01
The grant is user-shaped, not data-shaped
Finding
When somebody connects an assistant to their mailbox or their drive, what do they actually grant it? We read four vendors' own documentation and the answer is consistent: the unit of restriction is the application, never the data. The narrowest mail scope that can read a message reads every message. The default file corpus is, in the publisher's own words, files owned by or shared to the user. And in four places a vendor's own marketing and their own scope list disagree with each other.
12 September 20264 sources, quoted verbatimNothing tested
02
What buying a behaviour policy would actually look like
Mockup
Twelve stages from the first question a stranger reads to a delivered, recomputing vault with a read key they can hand to an underwriter. Five of those stages are drawn here as interface mockups, including the one that matters most: what a draft policy looks like, and what correcting it feels like. None of this is built. The mockups exist so the flow can be argued with before it is written.
12 September 20265 screensNot built
03
Changes we are asking of the behaviour-policy site
Proposal
The model and its data live on a separate site, maintained by somebody else. This is our open request list against it: one new property for the capability grammar, four deployment shapes we would like published, and the provenance conventions we would need in order to render any of it. Published rather than emailed, so the reasoning is checkable and the answer can be public too.
12 September 20263 requestsAwaiting a reply