Draft behaviour policy · not yours yet
An assistant connected to a personal mailbox
Derived from vendor documentation read on 12 September 2026, not from your account. We have assumed a conservative mandate. If the numbers below look wrong, they are — and telling us how is the next step.
Grant7
Mandate2
Excess5
Unbounded5
| Capability | | Barrier | Material | In the mandate |
| read.message.tenant | ◉ | expectation — a rule in prose | mixed | yes |
| read.record.history | ● | none | mixed | no |
| send.message.world | ◐ | setting — you can flip it back | organisation | yes |
| read.credential.host | ● | none | third_party | no |
| send.endpoint.world | ● | none | mixed | no |
| create.record.world | ◉ | expectation — a rule in prose | mixed | no |
| read.record.browsing | ◐ | setting — you can flip it back | mixed | no |
Five of seven capabilities are mixed or third_party. That is not a setting you have wrong. There is no supported way to say my inbox, except messages from outside the company — the unit of restriction is the connector, not the correspondence.
| Where the vendor's own pages disagree | Advertised | Granted |
| label mutation | label and unlabel mail threads | no scope in the grant authorises it · unresolved |
| calendar writes | create, update and delete events | the granted scope list is read-only · unresolved |
Provenance
7 of 7 capability rows derived from published documentation, 0 measured. Mandate assumed, not elicited. Delta computed from both, pinned to the versions shown. Valid for the deployment shape described, as at 12 September 2026 — if the risk changed, the deployment changed, not this document. No score appears anywhere in this document and none will.
This is wrong in places — let me correct it
Download as it stands