<!-- Generated from abp-vault-google-workspace-mcp.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# RiskMandate — the behaviour-policy vault for Google Workspace MCP servers

The template Agent Behaviour Policy vault for Google Workspace MCP servers (google/workspace-mcp/default), rendered live from vault pq7ct02p: the card, the mandate, the grant with a barrier per row, the delta, the Licence to Operate, the vault’s own app in a sandboxed frame, the file list and the public read key.

Source: https://riskmandate.ai/abp-vault-google-workspace-mcp.html

---

# The Google Workspace MCP servers.

Google's own MCP servers, one per Workspace product, used from an MCP client such as an IDE or an agent. Each server "inherits the same permissions and data governance controls as the user": it acts as the person who consented, over everything that person can reach. This is the template vault for that shape: the grant read from the vendor's own pages on 2026-09-15 and quoted, with 4 open questions it could not settle, the starting mandate written here to be argued with, and everything else derived. Every number on this page is decrypted from the vault as you read it.

## Six it can do. Two you asked for. One nothing bounds.

Four counts and no score. The bar splits the excess by what stands in the way of each row: nothing, a rule in prose, a setting the agent's own account can flip, or a boundary enforced above it. Only the last is a control. 0 of 6 rows were measured; every row was read from a vendor page on a date, and the open questions are the rows a page could not settle.

## What you asked it to do, and what you did not.

Elicited, and the only authored file in the vault. This is the draft asserting a conservative mandate so that the correction goes upward: most people authorised less than they think, and never mentioned the rest.

## Everything the agent can do, irreversible rows first.

Measured from the shape, not from your account and not by you. Each row says how it is known (✓ marks a row observed on the thing itself), what stands in the way, and whether the effect can be undone. What host, tenant and world mean in this shape is stated on the vault's Grant view, because for an agent in a vendor's container the host is the container and not your machine.

## What it can do that nobody asked for.

Derived from the grant and the mandate, never authored, stored with both inputs pinned. Split three ways: the part you refused, the part you never mentioned, and the part with no boundary in the way — which is the only list a real control shortens.

## The organisation authorises the agent, for an interval, on conditions.

The organisation is the authority, the behaviour policy is the instrument, the agent is the licensee. A template is unsigned and unissued; a corrected vault carries a name, a date and an interval — and each condition sits next to what enforces it, so the person signing knows what they are accepting with their eyes open.

## The vault's own interface, running here from the vault.

The vault carries a single self-contained page that renders itself from the files beside it, and opens on Start here: what this is, where the pieces go, what we want the agent to do beside what we do not, and three ways to hand it over. Below it is booted inside a sandboxed frame with an opaque origin and served its reads by this page over a message channel — the app never sees a key, and this page never runs the app's code in its own origin.

On a phone, open it in its own window: the frame below is the same app, sandboxed, and small. The vault browser is the whole product — files, history and the app — and the button carries the public read key, so it opens read-only without a paste. The copy this site serves at [vaults/google-workspace-mcp/index.html](vaults/google-workspace-mcp/index.html) says in its top bar which route it loaded the app by.

## The bytes themselves, listed from the live tree.

Markdown for people, JSON for machines, the pinned vocabulary, the history, and the two files you hand the agent — `AGENTS.md` for a CLAUDE.md, a ROLE.md or a skill, and `SKILL.md` in the portable skill format. The list is the vault's; each link opens the copy this site serves.

## Published on purpose. Read, and nothing else.

Derived one-way from the vault's write key, which is not published and never will be. With the key below anyone can clone this vault, open it in the vault browser, or read it from their own page — and check every number above against the bytes it came from. That is what makes a template free: the library is the argument, and it is public. A buyer's corrected vault has no public key.

sgit prints the same key with a prefix that declares its intent; the public form is the one shown. This page reads the vault at `dev.send.sgraph.ai` over plain cross-origin GETs and decrypts in your browser; the site never proxies it and holds no credential beyond the key you can see.

## Run this? Correct the mandate.

Open the app above, move the rows that are wrong, and send us the export. Your vault is this one with the mandate corrected, a name on the licence, and no public key — and it recomputes when the grant moves.
