## Five connector vaults, read from the vendors' own pages, with their open questions written to be handed on

The directory of behaviour-policy vaults grows from nine to fourteen, and the five new ones are the
shapes [Lab 01](lab-connector-grants.html) found and [Lab 03](lab-abp-requests.html) asked the
model site for: an assistant on a **personal Gmail mailbox**, on a **personal Google Drive**,
**Claude's Microsoft 365 connector** (a work mailbox and a corporate file estate in one consent),
**Google's own Workspace MCP servers**, and the **official Dropbox MCP server**. None is published at
abp.sgit.ai yet, so each was read from the vendor's own pages on 15 September 2026, quoted rather
than paraphrased, and stands at the *documented* evidence tier. Nothing was tested.

**A documented grant carries three things a measured one does not**, and the generator now writes
them for any vault whose grant has them. *Open questions* — what the pages could not settle — go to
a `RESEARCH-NEEDED.md` in the vault, one row each with how to settle it and where to look, counted
on the directory tile, the card and the app's first screen, and written to be handed to a separate
agent (the brief for that agent is in `docs/briefs/`). *Where the vendor's own pages disagree* is
the section Lab 03 said every connector shape needs: advertised in one place, permitted in another,
published unresolved on purpose. And *granted, and not in the grammar* records what a consent
screen permits that none of the 23 primitives names — trash a mail thread, read a calendar — so
the grant is never silently narrower than the consent.

**Whose material.** Every connector row carries the property Lab 01 said the grammar lacks — `own`,
`organisation`, `third_party` or `mixed` — as a column on the grant, in the markdown and in the
app. Almost every row is `mixed`, and no setting these vendors offer makes it `own`.

**What the pages said.** Google's Workspace MCP setup page advertises *create draft emails* and
*schedule meetings*; the scopes it asks for send mail (`gmail.compose`) and cannot touch a
calendar (three read-only scopes). Anthropic's Microsoft 365 guide, which Lab 01 read as read-only
on 12 September, lists ten write tools on 15 September, including *send an email as the user*; both
readings are in the vault. Dropbox's page says files *aren't deleted permanently* and that
*recovery depends on your plan's recovery window* in the same tool description. Gmail's narrowest
scope that returns a message body returns every body, and Drive's default corpus is *files owned by
or shared to the user*. The queue below the directory now names the next five connectors as *not
yet researched*, which is what they are.

The renderer is at v4 in the app vault; all fourteen application vaults were re-pushed to name it.
