sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · riskmandate.ai

Reading room / riskmandate.ai · raw text · live ↗

From riskmandate.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

A Gmail-connector vault built from a measured run, and the purchase workflow mapped for one customer

A sixteenth shape, and the first built with the deployer in the room. Claude's Gmail connector: Claude in the browser, the Gmail connector on, Calendar and Drive off. It was read from Anthropic's help article and from Google's own reference for the server behind it, and then the project lead connected it on an account they run and did the things: signed in through Google's three screens, read the inbox, sent one message to an address they named, asked for the settings, trashed the message, and asked for it to be deleted for good. Every screen is transcribed in the vault's evidence/ folder with the address redacted, and four of its six rows stand at measured. The vault is built and checked in the repository; it is listed on which Agent Behaviour Policy next?↗ as built and awaiting a push, and it gets its page when the lead pushes it and its key lands in the catalogue.

What the run found, that the pages did not say. The connector is Google's, not Anthropic's: MADE BY Google, a Developer Preview server, with Anthropic's footer disclaiming control of the tool list. Google's reference for that server names ten tools and none that sends; the listing in Claude names reply and forward, the prompt on the screen names Send email message, and the consent asks for two scopes that send. The approval prompt is the textbook setting: three buttons, and Always allow is one click by the account holder. Filters are listed on the page and denied by the agent. The message as sent carries nothing that names the client, only a Received line saying the Gmail API sent it. And permanent deletion is refused, because the scope the connector asks for excludes it — the one boundary in the shape that nobody had to set.

The purchase workflow, run once. A brief in docs/briefs/, linked from Admin↗, maps what happens after a call with a customer who wants exactly this policy: nine steps from the call to the review trigger, the vault mapped to what the customer does with each file, the settings with where each lives and who can undo it, and the block of prose the customer gives Claude. The customer's draft instance exists — anonymised, status draft, a question on every line of the mandate — built with the same generator outside the deployed tree, which needed one line in the build script.

Also. The register gains its sixth informal item, the lead's instruction of 16 September, with what it produced and what it still lacks. The asked-for row for Google Workspace now names what is left of it: Calendar and Drive.

Not done. The two pushes, which need the lead's write keys: the template to a public vault, the instance to a private one with no public key. The eleven screenshots as redacted image files: they arrived inline, and only the sent message's headers arrived as a file. The customer's answers to the draft mandate, and the signed licence. Nothing in any other vault changed.