The vaults
Every behaviour-policy vault on riskmandate.ai with its id, shape, measured rows and open questions, read off the catalogue and each vault's data. Source: https://riskmandate.ai/admin/vaults/↗ · noindex · written by scripts/site/build-admin.mjs
16vaults built and pushed*public read key, printed on purpose*
4measured on the thing itself*at least one row run by us*
28open research questions*across every grant*
8asked for, not built*5 connectors · 3 functions*
Read off the catalogue↗ and each vault's vault.json and data/grant.json. Measured counts rows run on a system we are entitled to run; everything else is documented from the vendor's pages, dated and quoted. No row here is a score: the number of open questions is how much the grant still does not know about itself.
Coding agents
| Vault | Shape | Rows | Measured | Open | As at | Id |
|---|
| Claude Code on the web↗
Claude Code on the web, with one repository attached | anthropic/claude-code-remote/ccr-container | 15 | 13 of 15 | none | 2026-09-15 | ruj286tr | host ↗ ↗ |
| Claude Code on your machine↗
Claude Code on your own machine, confirmations on | anthropic/claude-code/local-default | 16 | documented | none | 2026-09-15 | amicdz0h | host ↗ ↗ |
| Claude Code, confirmations off↗
Claude Code on your own machine, confirmations off | anthropic/claude-code/local-confirmations-off | 16 | documented | none | 2026-09-15 | ahly2cho | host ↗ ↗ |
Chat assistants
| Vault | Shape | Rows | Measured | Open | As at | Id |
|---|
| Claude Desktop↗
Claude Desktop, with local tools switched on | anthropic/claude-desktop/default | 10 | documented | none | 2026-09-15 | ty3axtmo | host ↗ ↗ |
| Claude in the browser, connectors on↗
Claude in the browser, with connectors switched on | anthropic/claude-web/connectors-on | 5 | documented | none | 2026-09-15 | wkm5owfl | host ↗ ↗ |
| ChatGPT in the browser↗
ChatGPT in the browser, nothing connected | openai/chatgpt-web/default | 1 | documented | none | 2026-09-15 | dd1teu9n | host ↗ ↗ |
| A browser extension↗
A browser extension with broad host permissions | generic/browser-extension/broad-host-permissions | 3 | documented | none | 2026-09-15 | exsaxrfr | host ↗ ↗ |
Automation & CI
| Vault | Shape | Rows | Measured | Open | As at | Id |
|---|
| GitHub Actions↗
A GitHub Actions runner, a hosted CI job | github/actions-runner/ci | 8 | 8 of 8 | none | 2026-09-15 | 0hpdpj80 | host ↗ ↗ |
| A scheduled job↗
A scheduled job running as a service account | generic/scheduled-job/service-account | 7 | documented | none | 2026-09-15 | kd7zeimj | host ↗ ↗ |
| n8n, owner API key↗
A self-hosted n8n instance, owner API key | n8n/self-hosted/owner-api-key | 8 | 7 of 8 | 4 open 2 contradictions | 2026-09-15 | l8opgcug | host ↗ ↗ |
Mail & files connectors
| Vault | Shape | Rows | Measured | Open | As at | Id |
|---|
| Google Workspace MCP servers↗
The Google Workspace MCP servers | google/workspace-mcp/default | 6 | documented | 4 open 3 contradictions | 2026-09-15 | pq7ct02p | host ↗ ↗ |
| Claude's Gmail connector↗
Claude, with the Gmail connector on one inbox | anthropic/gmail-connector/default | 6 | 4 of 6 | 6 open 5 contradictions | 2026-09-16 | oc433z3m | host ↗ ↗ |
| Gmail, read-only scope↗
An assistant on a personal Gmail mailbox | google/gmail/readonly-connector | 4 | documented | 3 open 1 contradiction | 2026-09-15 | l2zlv3ng | host ↗ ↗ |
| Google Drive, read-only scope↗
An assistant on a personal Google Drive | google/drive/readonly-connector | 3 | documented | 3 open 1 contradiction | 2026-09-15 | vz03p8it | host ↗ ↗ |
| Microsoft 365 connector (Claude)↗
Claude's Microsoft 365 connector | anthropic/microsoft-365-connector/default | 5 | documented | 4 open 3 contradictions | 2026-09-15 | dgx3nvu4 | host ↗ ↗ |
| Dropbox MCP server↗
The official Dropbox MCP server | dropbox/mcp-server/default | 5 | documented | 4 open 2 contradictions | 2026-09-15 | 9eqa7e4p | host ↗ ↗ |
Asked for, not built
Claude's Calendar & Drive connectors
Google Calendar and Google Drive, the two Google Workspace connectors not yet in the directory — Gmail's own is.not yet researched
An assistant connected to Slack
Channels are mostly other people's writing, and a bot token reaches every channel it is in.not yet researched
An assistant connected to GitHub
A fine-grained token can be scoped to a repository; an OAuth app cannot, and most connectors are OAuth apps.not yet researched
An assistant connected to Notion
An integration is added page by page, which is the one connector model with a floor. Whether the assistant's connector uses it is the question.not yet researched
An assistant connected to Salesforce
A CRM is entirely third-party material by construction.not yet researched
Access to the CRM
Customer records are third-party material by construction. Salesforce, HubSpot, Dynamics.asked for
The customer-service desk
Tickets, and the conversations inside them. Zendesk, Intercom, Freshdesk.asked for
Finance data
Spreadsheets, ledgers and the exports beside them. Sheets, Excel, NetSuite.asked for
The public page for these is what is next↗, with a vote and a suggestion form.