Tags

184 tags across the catalog. Find policies by what they do — access-control, dlp, pii, secrets, redaction — and by ingress or egress. Useful when the shape of the control matters more than the app.

Every policy declares its tags in its own frontmatter. App and bundle tags mirror the browse pages; the rest name the control family — the pattern a policy instantiates — and the risk it addresses.

Direction

Where the policy runs: before the call (ingress) or on the response (egress).

Apps

Every policy scoped to an MCP server carries its app as a tag.

Bundles

Framework and use-case bundles a policy belongs to.

Controls

What the control does — the policy family and the risk it addresses.

dlp 44 pii 39 access-control 36 redaction 30 redact-pii 23 freeze-destructive-ops 20 iso27001-nist 19 fence-sensitive-scopes 16 role-gate-writes 16 least-privilege 14 allowlist 13 cap-bulk-export 13 governance 13 default-deny-unknown-tools 12 email 12 record-integrity 9 data-minimisation 7 finserv-comms 7 guard-external-send 7 guard-warehouse-sql 7 secrets 7 data-minimization 6 data-protection 6 cardholder-data 5 exfiltration 5 mask-pan-egress 5 sql 5 constrain-aggregator 4 deny-escape-hatches 4 guard-share-links 4 readonly 4 sharing 4 deny-public-exposure 3 freeze-identity-plane 3 groups 3 identity 3 phi 3 rbac 3 require-human-approval 3 anti-exfil 2 bec 2 comments 2 confidentiality 2 consent 2 contacts 2 datasource 2 dax 2 deals 2 eu-ai-act 2 external-sharing 2 financial-pii 2 force-internal-comments 2 gate-money-movement 2 guard-mailbox-persistence 2 integrity 2 pan 2 privacy 2 protect-closed-periods 2 publication 2 read-only 2 recency 2 redact-pii-egress 2 rls 2 separation-of-duties 2 transform 2 acl 1 agentic-search 1 anti-bec 1 archive 1 articles 1 associations 1 audit-integrity 1 batch-mutation 1 block-secrets 1 bulk-export 1 calculation 1 calendar 1 change-management 1 compensation 1 contact-enumeration 1 contact-reads 1 cortex 1 default-deny 1 disputes 1 dm 1 drive 1 entra 1 esign 1 exclude-personal-drives 1 export 1 fence-hr-and-credit-scope 1 fence-restricted-folders 1 fence-sensitive-tables 1 filter-blocked-senders 1 filter-dormant-threads 1 filter-labeled-threads 1 finra 1 force-draft-envelopes 1 gate-memory-writes 1 guard-public-exposure 1 guard-transcripts 1 guard-vendor-banking 1 guard-warehouse-export 1 guard-webhook-persistence 1 help-center 1 human-approval 1 human-in-the-loop 1 jsm 1 label-filter 1 lifecycle 1 mask-pan 1 memory 1 modeling 1 observability 1 opportunity 1 org-allowlist 1 payroll 1 phishing 1 pipeline 1 prompt-injection 1 recent-search-only 1 redact-content 1 redact-secrets 1 revenue 1 roadmap 1 role-gate-schema-consent 1 scoping 1 segregation-of-duties 1 sender-blocklist 1 sensitive-scopes 1 service-management 1 service-principal 1 share-links 1 slack-connect 1 suiteql 1 tab-values 1 team-chat 1 unknown-tools 1 vendor-banking 1 vizql 1 webhook 1 work-notes 1

to navigate to open