06 · In a behaviour policy
Calendar rows, with recovery beside each one. Draft
From the Calendar behaviour policies in draft, for an agent holding the scope that reads and edits events on all calendars. The reach is what the scope allows. The mandate is an example of what a person might authorise. The barrier column says what actually stands in the way, and a sentence in the agent’s instructions is not a barrier: it is hope.
CapabilityUndo in the productMandate, for exampleWhat stands in the way
Read eventsnot neededyesnothing, and nothing needed
Create an eventdelete it; trash 30 daysyes, on my calendar, up to ten a daynothing enforces the ten; stated as an expectation
Edit an eventnone documentedonly events it created, one at a time, never ones with outside guestsnothing in the scope; the deployment would have to save the event’s prior state somewhere the agent cannot write, before each edit
Change the guest listprevious list discardednever without menothing in the scope
Delete one eventtrash, 30 days, from a computeronly events it creatednothing in the scope; recoverable by me
Delete “this and following”nonenevernothing in the scope
Many edits in one runnonenever more than five without askingnothing in the scope; a limit the deployment would have to count
Read down the last column and the answer is the uncomfortable one: for most rows, nothing stands in the way except the agent’s instructions. A behaviour policy does not grade that; it writes it down, row by row, so that whoever authorises the agent sees it before the first mistake rather than after. Where a barrier is wanted, the facts above say which: a before-image of every event the agent edits, kept where the agent cannot reach, because Google does not keep one for the user.