From abp.sgit.ai, the page as fetched on 2026-09-25 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.
{
"type": "abp/mandate/v1",
"id": "read-and-draft-never-send",
"label": "Find things in the inbox, draft replies, never send",
"surface": [
"web"
],
"applies_to": [
"anthropic/gmail-connector/default",
"anthropic/gmail-connector/measured-2026-09-19"
],
"status": "starting-point",
"authored": "2026-09-16",
"authored_by": "the site, as a starting point — not measured, not surveyed; the first thing to argue with",
"description": "We connected Gmail to Claude so it could find things in the inbox, answer questions about it, and draft replies for a person to send themselves. Reading is what was wanted. Nobody asked it to send mail as them — Google's own consent screen already permits it, and only the per-action approval prompt stands between the two.",
"want": [
"read.message.tenant"
],
"do_not_want": [
"send.message.world",
"read.credential.host",
"create.schedule.tenant"
],
"unstated": [
"authenticate-as.credential.signing",
"authenticate-as.credential.tenant",
"create.record.world",
"create.schedule.host",
"delete.file.host",
"execute.process.host",
"execute.process.self",
"grant.credential.self",
"read.file.host",
"read.file.project",
"read.record.browsing",
"read.record.history",
"send.endpoint.allowed",
"send.endpoint.world",
"write.budget.tenant",
"write.file.host",
"write.file.project",
"write.repository.project",
"write.repository.tenant"
],
"notes": {
"send.message.world": "refused; bounded today only by the approval prompt, which is a setting and not a boundary — an org owner can remove it",
"read.message.tenant": "wanted — and reads every message the account can already read, which is more than most people picture when they say \"read my mail\"",
"create.schedule.tenant": "refused; a filter is a rule that keeps acting on mail after the chat ends, and nobody asked for one"
},
"provenance": {
"source": "https://riskmandate.ai/vaults/claude-gmail-connector/data/mandate.json",
"source_page": "https://riskmandate.ai/abp-vault-claude-gmail-connector.html",
"retrieved": "2026-09-20T17:23:43Z",
"pack_version": null,
"content_hash": "sha256:cf7e3c1e8af38979099b193e9c98a502924e8d4f11cc6079c8c1d9573b2534b3",
"verbatim_bytes": "contributed/riskmandate/claude-gmail-connector/mandate.json",
"contributed_by": "riskmandate.ai",
"contributed_manifest": "contributed/riskmandate/manifest.json",
"note": "Contributed by riskmandate.ai, promoted from claude-gmail-connector/mandate.json. `unstated` is recomputed here. A mandate is elicited, not measured: this is the contributor's first draft, written to be argued with.",
"licence": "CC BY 4.0"
},
"applies_to_extended": {
"to": "anthropic/gmail-connector/measured-2026-09-19",
"note": "Extended at v0.11.0 to the measured variant of the same shape, so that the site's own starting mandate and the agent's inferred one can be read against one grant. The contributed bytes are unchanged; the extension is the site's."
}
}