Skip to main content
Guardrails

You gave it Gmail access. What else did you just give it?

The scariest part of giving an agent access to your tools isn't what it might do on purpose. It's what it might do by accident. Civic defaults to the safest possible scope and requires explicit grants to expand.

Gmailagent connected
gmail:readRead emails
gmail:sendSend as you
denied
gmail:deleteDelete threads
denied
gmail:forwardAuto-forward
denied
gmail:manage_filtersCreate filters
denied
gmail:manage_labelsModify labels
denied

One click. Six permissions you didn't ask for.

Most platforms grant full access the moment you connect a tool. You wanted to read emails. You got the keys to the entire account.

gmail:read

Read emails

you wanted this

gmail:send

Send as you

silently granted

gmail:delete

Delete threads

silently granted

gmail:forward

Auto-forward

silently granted

gmail:manage_filters

Create filters

silently granted

gmail:manage_labels

Modify labels

silently granted

You connected one tool. You got six permissions. Five of them can cause damage you won't notice until it's too late.

Default deny. Explicit grant.

Civic Chat
1[you] Restrict Gmail to read-only. Block
2 sending, deleting, forwarding,
3 and creating filters.
4 
5[nexus] Configured. Gmail guardrails set:
6 ✓ gmail:read — allowed
7 ✗ gmail:send — blocked
8 ✗ gmail:delete — blocked
9 ✗ gmail:forward — blocked
10 ✗ gmail:manage_* — blocked

Safe by default. Powerful when you need it.

Set up guardrails in minutes. Sleep better tonight.