A Gmail-connector vault built from a measured run, and the purchase workflow mapped for one customer
A sixteenth shape, and the first built with the deployer in the room. Claude's Gmail
connector: Claude in the browser, the Gmail connector on, Calendar and Drive off. It was read from
Anthropic's help article and from Google's own reference for the server behind it, and then the
project lead connected it on an account they run and did the things: signed in through Google's
three screens, read the inbox, sent one message to an address they named, asked for the settings,
trashed the message, and asked for it to be deleted for good. Every screen is transcribed in the
vault's evidence/ folder with the address redacted, and four of its six rows stand at
measured. The vault is built and checked in the repository; it is listed on
which Agent Behaviour Policy next?↗ as built and awaiting a
push, and it gets its page when the lead pushes it and its key lands in the catalogue.
What the run found, that the pages did not say. The connector is Google's, not Anthropic's:
MADE BY Google, a Developer Preview server, with Anthropic's footer disclaiming control of the
tool list. Google's reference for that server names ten tools and none that sends; the listing
in Claude names reply and forward, the prompt on the screen names Send email message, and
the consent asks for two scopes that send. The approval prompt is the textbook setting: three
buttons, and Always allow is one click by the account holder. Filters are listed on the page and
denied by the agent. The message as sent carries nothing that names the client, only a Received
line saying the Gmail API sent it. And permanent deletion is refused, because the scope the
connector asks for excludes it — the one boundary in the shape that nobody had to set.
The purchase workflow, run once. A brief in docs/briefs/, linked from Admin↗,
maps what happens after a call with a customer who wants exactly this policy: nine steps from the
call to the review trigger, the vault mapped to what the customer does with each file, the
settings with where each lives and who can undo it, and the block of prose the customer gives
Claude. The customer's draft instance exists — anonymised, status draft, a question on every
line of the mandate — built with the same generator outside the deployed tree, which needed one
line in the build script.
Also. The register gains its sixth informal item, the lead's instruction of 16 September, with what it produced and what it still lacks. The asked-for row for Google Workspace now names what is left of it: Calendar and Drive.
Not done. The two pushes, which need the lead's write keys: the template to a public vault, the instance to a private one with no public key. The eleven screenshots as redacted image files: they arrived inline, and only the sent message's headers arrived as a file. The customer's answers to the draft mandate, and the signed licence. Nothing in any other vault changed.