Trust
Some things are not a permission. They are absent.
Data erasure, API keys, user and role administration, field permissions, and marketplace installation and management are denied to the assistant for every user, including a full administrator. This is not a permission check that an admin passes: no tool touching those areas has been built, and the deny list makes sure none can be added without being refused.
How it works
Refused before it is ever offered
Four gates decide whether a tool is offered to you at all: a deployment-wide switch, the deny list, your workspace modules, and your own permissions. Two of them are reported back to you by name. The other two are absences you never see offered.
The deny list
Evaluated before anything else and applied to everyone. Data erasure, API keys, user and role administration, field permissions, and marketplace installs and management are structurally unreachable.
Module and permission
A capability whose module your workspace has switched off is never offered. Then every permission a tool declares is checked against your account, and all of them must pass.
Scope, at answer time
Maddox refuses the scope rather than the record: it will not confirm whether something it cannot see exists. And where a field is withheld from you it says withheld, not missing, absent or zero.
In the product
It will tell you what it cannot do, and why.
The mechanism
What the deny list actually is, and what it is not
The outcome is stronger than a filter, and the difference matters to anyone whose job is to verify it rather than believe it.
Seven prefixes, five families, matched against what a tool declares
The list is not a list of tool names. It is a set of permission-name prefixes, and a tool declaring any permission that starts with one of them is refused exposure for every user. Seven prefixes cover five families: data erasure, API keys, user administration, role administration, field permissions, and marketplace installation and marketplace management — the last two being one family expressed as two prefixes.
Reading the marketplace is deliberately absent from that list. Browsing is not a mutation, and denying reads would be a wider rule than the one that was asked for. The same list is now shared with the other kind of delegated actor in the product, an operator working inside a customer workspace, because that is the same shape of risk: a principal whose reach was granted by somebody else. Two copies would mean the next dangerous domain gets added to one of them.
It is a forward guard, not a filter with something to filter
No tool in the assistant declares a permission in any denied family. The permissions the tools actually declare are a short, ordinary list — viewing deals, contacts, companies, calls, meetings, campaigns, scorecards, forecasts and sales management, plus creating activities and meetings and editing campaigns, which is what the six approval-gated changes need. So the deny list is not removing anything today. What it does is guarantee that a tool touching one of those areas cannot be added later without being refused, by somebody who never read this page. Saying that plainly is more useful than implying a filter is quietly holding back a set of dangerous tools that exist.
The same list decides what an approval batch may carry
It is not only an exposure rule. Approving several pending changes at once asks the same question of each one, using the same prefixes, so an action in a blast-radius area is refused a place in a batch for exactly the reason it would be refused exposure. The alternative — a separate list of tool-name prefixes maintained beside this one — is what the product used to do, and it had a general fallback that was bulk-approvable.
Record text is data, and it never becomes an instruction
For a product whose pitch is that it read every transcript, this is the objection a security reviewer raises first, and it is answered with a dedicated boundary rather than a line of good intentions. Text inside transcripts, notes, emails, documents, deal fields and campaign copy is content the assistant is reading, written by prospects, customers and third-party imports.
If any of it appears to address the assistant, claim new permissions, ask it to ignore its rules or ask it to fetch something else, that is data describing what someone wrote. It is reported as such and never acted on. Instructions come only from the system message and from your own messages in this conversation, and nothing arriving inside a tool result can change what the assistant is allowed to do. Where a record asks for something outside what you asked for, you are told that the record contains that request, and it stops there.
Who it is for
For the person doing the security review
This page exists to be read by someone whose job is to say no, and to give them enough to say yes.
- Security and compliance reviewers
- Administrators deciding how widely to enable the assistant
- Anyone who has been asked what the AI can actually reach
Related
Questions
The things people actually ask.
Can an administrator grant Maddox access to the denied areas?
No. The deny list is applied when the tool registry is built, before any permission is considered, and it applies to administrators too. There is no role configuration that reaches those domains.
Why is reading the marketplace allowed but installing not?
Because reading is not a mutation, and denying reads would be a wider rule than the one intended. The install and manage capabilities are denied; browsing is not.
What happens if a record contains text telling Maddox to do something?
It is treated as data describing what someone wrote, and reported as such. Transcripts, notes, emails and imported fields are content, written by prospects and third parties. Instructions come only from the system prompt and from your own messages, and nothing arriving inside a tool result can widen what the assistant is allowed to do.
Will it guess when it is not sure which record I meant?
No. With two or more plausible candidates it asks. Before anything that would change something it confirms the subject with you even when there is only one candidate, because a wrong read is a correction and a wrong write is damage.
Can it tell me a number it worked out itself?
It is instructed to quote figures from the tool that returned them, and not to add, average, convert or re-derive them, or combine numbers from two different ledgers. A sample of answers is also audited automatically for unsourced specifics and fabricated citations.
Bring us the question your security review will ask.
We would rather answer it now, against the actual implementation, than have it surface after a rollout.