Skip to main content
Glama

Server Configuration

Describes the environment variables required to run the server.

NameRequiredDescriptionDefault

No arguments

Instructions

Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.

This server publishes no instructions, or was last inspected before Glama recorded them.

Capabilities

Features and capabilities supported by this server

Protocol revision2025-11-25

CapabilityDetails
tools
{
  "listChanged": false
}
experimental
{}

Tools

Functions exposed to the LLM to take actions

NameDescription
apps_script_list_projectsA

List standalone Google Apps Script projects visible to the user (id, name, last-modified time). Container-bound scripts attached to a Sheet/Doc/Form are not returned. Auto-approved.

apps_script_get_contentA

Fetch the full source of a Google Apps Script project -- every file (.gs/.html) plus the appsscript.json manifest. Requires user approval.

apps_script_write_contentA

Write new source to a Google Apps Script project. Replaces the project's entire file set -- there is no single-file/partial update, so always pass every file the project should have afterward, not just the ones you changed (fetch the current set with apps_script_get_content first if you need to preserve files you aren't touching). This only writes source -- PrivacyFence never runs the script; the user runs it themselves in the Apps Script editor once this write is approved. Requires user approval.

apps_script_get_execution_logA

Read the result of the most recent run(s) of a script that the user triggered themselves outside PrivacyFence (status, duration, which function ran) -- not a live console.log transcript. Requires user approval.

calendar_list_calendarsB

List all Google Calendars for the authenticated user. Auto-approved.

calendar_list_eventsB

List events from a calendar (id, title, start_time, end_time, all_day, status). No attendees, description, or links returned. Auto-approved.

calendar_get_free_busyA

Query colleagues' schedules for a time range. For each email, tries to fetch full event details (title, time, status) when the authenticated user has calendar access; falls back to free/busy slots only when access is unavailable. Use this for meeting scheduling. Auto-approved.

calendar_get_event_detailsA

Fetch full details of a calendar event including attendees, description, conferencing links, and file attachments (e.g. the "Notes by Gemini" and transcript docs Google Meet attaches after a meeting ends). Each attachment's file_id can be passed to drive_get_file_content to read its content. Requires user approval.

calendar_get_event_visibilityA

Get a calendar event's visibility setting (default, public, private, or confidential) without fetching its full details (attendees, description, etc.) the way calendar_get_event_details does. Auto-approved.

calendar_set_event_visibilityA

Set a calendar event's visibility. 'default' follows the calendar's own sharing settings; 'public' makes it visible to anyone who can see the calendar; 'private' hides its details from viewers who aren't invited; 'confidential' is a legacy synonym the Calendar API still accepts for 'private'. Only visibility changes — no other fields are affected. Requires user approval.

calendar_list_roomsA

List meeting rooms and resource calendars from the organization's room directory. This is a locally-cached list IT refreshes with scripts/sync_room_directory.py, not a live Workspace lookup — it may come back empty if IT hasn't synced one yet. Returns room name, email, building, floor, and capacity. To check whether a room is actually free before booking, call calendar_get_free_busy with its resource_email. Use the room email with calendar_create_event or calendar_update_event to book. Auto-approved.

calendar_list_colorsA

List Calendar's fixed event color palette: each color's id, name (e.g. "Tomato", "Sage"), and hex background/foreground. Use a color's id or name as the color argument to calendar_create_event, calendar_update_event, or calendar_set_event_color instead of guessing a numeric id. Auto-approved.

calendar_create_eventC

Create a new calendar event. Requires user approval.

calendar_update_eventA

Update an existing calendar event. For a recurring event, 'scope' controls which occurrences this touches: 'this' (default) affects only the given event_id; 'following' splits the series so this instance and every later one get the changes, leaving earlier ones untouched; 'all' updates the entire series. Requires user approval.

calendar_delete_eventA

Delete a calendar event. For a recurring event, 'scope' controls what's deleted: 'this' (default) deletes only the given event_id; 'following' ends the series just before this instance, deleting it and every later occurrence but keeping earlier ones; 'all' deletes the entire series. Requires user approval.

calendar_set_event_colorA

Set a calendar event's color. Only the color changes — no other fields are affected. Accepts a color id (1-11) or name, e.g. "Tomato" -- see calendar_list_colors. Requires user approval.

calendar_create_out_of_officeA

Create an out-of-office event on the primary calendar. Always auto-declines new conflicting meeting invitations that arrive while it's in effect — existing invitations already on the calendar are left alone. Requires user approval.

calendar_set_working_locationA

Set your working-location presence (office or home) for a single day on the primary calendar — the same picker Google Calendar's web UI exposes. Requires user approval.

confluence_list_spacesA

List Confluence spaces the user has access to (key, name, type, description). Auto-approved.

confluence_searchB

Full-text search across Confluence content. Returns matching pages/blog posts with excerpts. Auto-approved.

confluence_cql_searchB

Search Confluence using CQL (Confluence Query Language). Auto-approved.

confluence_list_pagesC

List pages in a Confluence space (title, id, version). Auto-approved.

confluence_list_attachmentsA

List attachment names, media types, and sizes for a Confluence page. Auto-approved -- metadata only, no attachment content is returned. Use confluence_download_attachment to fetch the actual file.

confluence_download_attachmentA

Download a Confluence page attachment's content. Identify the attachment by the name returned from confluence_list_attachments. On a local install: saved to destination_dir, and the saved file path is returned -- destination_dir is required, there is no default, so choose deliberately: pass ~/Downloads (or another path the user asked for) when this attachment is a deliverable the user should find afterward, or your own working/scratch directory when you're only downloading it to read or process it yourself. On an organization-managed install: destination_dir is ignored (there is no local filesystem you and the human share) -- a small attachment's bytes come back directly in this tool's result so you can read or hand it to the human yourself; a larger one comes back as a one-time link the human opens in their own signed-in browser tab instead. Requires user approval.

confluence_get_pageA

Fetch the full content of a Confluence page by page ID. Returns the page body as HTML storage format. Requires user approval.

confluence_get_page_by_titleA

Fetch a Confluence page by space key and exact title. Requires user approval.

confluence_create_pageA

Create a new Confluence page in the given space. Body is HTML storage format. Requires user approval.

confluence_update_pageA

Update the title and/or body of an existing Confluence page. Body is HTML storage format. Requires user approval.

contacts_listA

List contacts from the user's Google address book. Google blends personally-saved contacts together with Workspace directory profiles (colleagues) by default; use 'source' to split them apart. Returns display name, emails, phones, organization, job title, and a 'source' field ('personal', 'directory', or 'both' if the same person is both a saved contact and a colleague). Auto-approved.

contacts_searchA

Search contacts by name or email address. Use 'source' to search only personally-saved contacts, only Workspace directory contacts, or both (default). Note: 'directory' search only finds directory profiles you already have some contact history with; there is no full company-directory search under this app's permissions. Auto-approved.

contacts_getA

Fetch a single contact by resource name (e.g. 'people/c12345'). 'source' asserts the expected kind of contact ('personal', 'directory', or 'both'/default); the call fails if the resource doesn't match. Auto-approved.

contacts_updateA

Update a contact's fields. Provide only the fields you want to change. Requires user approval. emails and phones are JSON strings, e.g. '[{"value": "a@b.com", "type": "work"}]'.

contacts_createA

Create a new contact in the user's Google address book. Requires user approval. emails and phones are JSON strings, e.g. '[{"value": "a@b.com", "type": "work"}]'. Contact deletion is not supported.

contacts_add_labelA

Add a label to a contact, creating the label if it doesn't already exist. Requires user approval.

contacts_remove_labelB

Remove a label from a contact. Requires user approval.

drive_list_filesB

Search Google Drive and return matching file metadata (id, name, mime_type, owners, sharing status). Auto-approved.

drive_get_file_metadataA

Fetch metadata for a single Drive file by id (name, owners, times, sharing status). Auto-approved.

drive_list_folderB

List the direct children of a Drive folder by id. Auto-approved.

drive_create_blank_fileB

Create a new blank Drive file. Auto-approved.

drive_get_file_contentA

Fetch the content of a Drive file by id. A Google Doc comes back as Markdown (headings, bold, italic, strikethrough, underline, code, link, ==highlight==, '---' dividers, nested bullet/numbered lists with a 2-space indent per level, GFM pipe tables with alignment), the syntax drive_write_doc_content accepts, so it round-trips into it or drive_docs_edit_content. An exact highlight or text color Markdown can't carry comes back in 'highlights'/'text_colors' ({text, hex} lists). A Sheet comes back as CSV, Slides as plain text. A PDF, .docx, .pptx or .xlsx comes back as its extracted text (a scanned PDF has none), with 'truncated': true when cut to fit; a .zip as its list of entries. Other files, such as images, only get a placeholder: use drive_download_file for those. Requires user approval.

drive_write_file_contentB

Write content to an existing Drive file. Requires user approval.

drive_upload_fileA

Upload any file (e.g. a PDF or image) to Drive as a new file — use this instead of drive_write_file_content for any binary file, since that tool only writes UTF-8 text. Provide exactly one of local_path (a path on the user's computer — where Claude Desktop runs: absolute, or starting with ~/. Claude's own working or outputs directory is fine), content_base64 (base64-encoded file bytes, decoded by PrivacyFence itself — use this when you only have the file's bytes and not a local path; 'name' is then required), or upload_id (the id privacyfence_create_upload_slot returned after you PUT the file's bytes to its upload_url — use this if local_path fails with an error about PrivacyFence being unable to read files in your home folder directly, e.g. no PrivacyFence extension is installed). On an organization-managed install, local_path is read from wherever PrivacyFence's own server runs, not the user's machine — prefer content_base64 or upload_id there. Requires user approval.

drive_move_fileA

Move a Drive file to a different folder. Requires user approval.

drive_add_commentB

Add a comment to a Drive file. Requires user approval.

drive_list_shared_drivesB

List all Google Workspace Shared Drives the user can access (returns id and name for each). Auto-approved.

drive_write_doc_contentA

Write Markdown content to a Google Doc with rich formatting: headings (# through ######), bold, italic, bold-italic, strikethrough, underline, code, ==highlight== (these five nest freely with each other, e.g. ==bold and highlighted==), link (escape a literal '[' or ']' in the link text as '['/']'), bullet/numbered lists (indent a sub-list 2 spaces per nesting level), GFM pipe tables (a '| --- |' separator row under the header; ':---'/'---:'/':---:' for left/right/center column alignment), and '---'/'***'/'___' on their own line as a horizontal-rule divider. Clears the existing document content before writing — use drive_docs_edit_content or drive_docs_format_content instead for a change that shouldn't touch the rest of the document. Use this instead of drive_write_file_content when the target is a Google Doc and you want formatted output. Requires user approval.

drive_docs_edit_contentA

Replace one occurrence of existing text in a Google Doc with new Markdown, without touching the rest of the document. find_text must match exactly one location in the document's plain, unformatted text — the words as typed, with no Markdown syntax in them at all (this is not the same as drive_get_file_content's output for a Doc, which now renders formatting as Markdown; strip any '**'/'#'/etc. markers back out of find_text first) — include enough surrounding context to make it unique, the same way a unique-match text editor requires; set replace_all=true to replace every occurrence instead. replace_markdown supports the same Markdown syntax as drive_write_doc_content, including GFM pipe tables. Requires user approval.

drive_docs_format_contentA

Apply formatting (bold, italic, highlight, text color) to existing text in a Google Doc, located the same way as drive_docs_edit_content, without changing the text itself. Every formatting parameter is opt-in — its default means 'leave that aspect unchanged', so a call that only sets highlight_color never touches bold/italic already on the matched text. Requires user approval.

drive_download_fileA

Download a Drive file. Google Workspace documents are exported as text/CSV. On a local install: saved to destination_dir, and the saved file path is returned -- destination_dir is required, there is no default, so choose deliberately: pass ~/Downloads (or another path the user asked for) when this file is a deliverable the user should find afterward, or your own working/scratch directory when you're only downloading it to read or process it yourself. On an organization-managed install: destination_dir is ignored (there is no local filesystem you and the human share) -- a small file's bytes come back directly in this tool's result so you can read or hand it to the human yourself; a larger file comes back as a one-time link the human opens in their own signed-in browser tab instead. Requires user approval.

drive_sheets_createB

Create a new Google Sheets spreadsheet, optionally with named tabs. Auto-approved.

drive_sheets_get_metadataB

List the tabs in a spreadsheet (id, title, index, row/column count). Auto-approved.

drive_sheets_get_valuesA

Read a range of cells from a spreadsheet: display values by default, or the underlying values, or formulas instead of computed results, and optionally cell formatting alongside them. Requires user approval.

drive_sheets_write_rangeA

Write values and/or formulas into a range of an existing spreadsheet. A cell string starting with '=' is evaluated as a formula, exactly as if typed into the Sheets UI — there is no separate tool for formulas. Writing an empty row/column clears those cells. Requires user approval.

drive_sheets_add_sheetC

Add a new tab to an existing spreadsheet. Requires user approval.

drive_sheets_rename_sheetA

Rename an existing tab in a spreadsheet. There is no delete-sheet tool — to mark a tab for removal, rename it (e.g. to 'TO BE DELETED - ') and the user can delete it by hand in the Sheets UI. Requires user approval.

drive_sheets_format_rangeA

Apply formatting to a range in a spreadsheet: bold/italic, colors, number format, horizontal/vertical alignment, text wrap, column width, frozen rows/columns, and merged cells. Every parameter is opt-in — its default means 'leave that aspect unchanged', so a call that only sets a background color never touches unrelated formatting already on the range. Requires user approval.

drive_sheets_insert_dimensionsA

Insert blank rows or columns into a sheet tab, shifting existing content after the insertion point. Values/formulas are untouched, only their position shifts; formulas referencing shifted cells are adjusted automatically. Requires user approval.

drive_sheets_delete_dimensionsA

Delete rows or columns from a sheet tab, including any values, formulas, and formatting they contain. This is destructive — deleted cell content is not recoverable through PrivacyFence. Remaining rows/columns shift to close the gap. Requires user approval.

gmail_list_messagesA

Search Gmail and return matching message summaries (id, thread_id, subject, sender, date). Auto-approved — no body content is returned.

gmail_list_threadsA

Search Gmail and return matching thread summaries (id, snippet). Auto-approved — snippet is a short excerpt of the last message's body, subject to the same 'body' privacy category as gmail_get_message.

gmail_get_messageA

Fetch a single Gmail message by id, including body, metadata, and attachment list. Requires user approval.

gmail_get_threadB

Fetch a full Gmail thread by id, including all messages. Requires user approval.

gmail_list_message_attachmentsA

List attachment names, MIME types, and sizes for a Gmail message. Auto-approved — metadata only, no attachment content is returned. Use gmail_download_attachment to fetch the actual file.

gmail_download_attachmentA

Download a Gmail attachment's content. Identify the attachment by the name returned from gmail_list_message_attachments. On a local install: saved to destination_dir, and the saved file path is returned -- destination_dir is required, there is no default, so choose deliberately: pass ~/Downloads (or another path the user asked for) when this attachment is a deliverable the user should find afterward, or your own working/scratch directory when you're only downloading it to read or process it yourself. On an organization-managed install: destination_dir is ignored (there is no local filesystem you and the human share) -- a small attachment's bytes come back directly in this tool's result so you can read or hand it to the human yourself; a larger one comes back as a one-time link the human opens in their own signed-in browser tab instead. Requires user approval.

gmail_create_draftC

Create a Gmail draft. Requires user approval.

gmail_reply_draftA

Create a Gmail draft replying to a single message, staying in the same thread (sets threadId plus In-Reply-To/References so it actually threads, unlike gmail_create_draft). Addressed only to the original sender. Requires user approval.

gmail_reply_all_draftA

Create a Gmail draft replying to all participants of a message (original sender plus To/Cc recipients, excluding yourself), staying in the same thread. Requires user approval.

gmail_create_draft_with_attachmentsA

Create a Gmail draft with one or more local-file attachments. Parallel to gmail_create_draft -- use this variant only when there is something to attach; use gmail_create_draft when there isn't, so a draft doesn't need this tool's extra attachments argument for nothing. Requires user approval.

gmail_reply_draft_with_attachmentsA

Create a Gmail draft replying to a single message, staying in the same thread, with one or more local-file attachments. Parallel to gmail_reply_draft -- use this variant only when there is something to attach. Addressed only to the original sender. Requires user approval.

gmail_reply_all_draft_with_attachmentsA

Create a Gmail draft replying to all participants of a message (original sender plus To/Cc recipients, excluding yourself), staying in the same thread, with one or more local-file attachments. Parallel to gmail_reply_all_draft -- use this variant only when there is something to attach. Requires user approval.

gmail_add_labelB

Add a label to a Gmail message. Requires user approval.

gmail_remove_labelB

Remove a label from a Gmail message. Requires user approval.

gmail_archive_messageA

Archive a Gmail message by removing it from the Inbox. The message is not deleted and remains searchable. Requires user approval.

gmail_list_filtersA

List all Gmail filters with their criteria and actions. Auto-approved -- filter rules only, no message content is returned.

gmail_list_labelsA

List all Gmail labels (system and user-created). Nested labels have a '/' in their name (e.g. 'Work/Projects'). Auto-approved -- label metadata only.

gmail_create_filterA

Create a Gmail filter. Provide at least one criteria field (from_address, to_address, subject, query, has_attachment) and at least one action (add_label_names, archive, mark_as_read, star, forward_to). Requires user approval.

gmail_update_filterA

Replace an existing Gmail filter's criteria and actions, identified by filter_id (from gmail_list_filters). Gmail's API has no native filter update, so this deletes the filter and creates a new one with the given fields, which gets a new id. Requires user approval.

gmail_create_labelA

Create a Gmail label. Use '/' to create nested labels (e.g. 'Work/Projects' creates 'Projects' nested under 'Work', creating 'Work' first if it doesn't already exist). Fails if the exact label name already exists. Requires user approval.

jira_list_projectsB

List Jira projects accessible to the user (key, name, type, lead). Auto-approved.

jira_search_issuesB

Search Jira issues using JQL. Returns summary info for matching issues. Auto-approved.

jira_get_issueA

Fetch full details of a Jira issue by key (e.g. PROJ-123), including description and comments. Requires user approval.

jira_get_transitionsA

List the status transitions available for a Jira issue right now (name and target status), given its current workflow state. Use before jira_transition_issue to see what transition names are valid. Auto-approved.

jira_create_issueC

Create a new Jira issue. Requires user approval.

jira_add_commentA

Add a comment to an existing Jira issue. Requires user approval.

jira_update_issueA

Update fields on an existing Jira issue (summary, description, priority, and/or custom fields). Requires user approval.

jira_transition_issueA

Move a Jira issue to a new status by transition name (e.g. "Done", "In Progress") — call jira_get_transitions first to see what's valid from the issue's current status. Requires user approval.

salesforce_list_reportsB

List Salesforce reports accessible to the user. Auto-approved.

salesforce_get_recordA

Fetch a Salesforce record by object type and id. Requires user approval.

salesforce_run_reportB

Run a Salesforce report by id and return the results. Requires user approval.

salesforce_searchA

Search Salesforce by name or id across one or more object types — the same mechanism as the search bar at the top of the Salesforce UI. Returns lightweight Id/Name matches per object type; call salesforce_get_record for full field details on a match. Requires user approval.

slack_list_channelsA

List Slack channels visible to the user (id, name, privacy, topic, purpose, member count). Optionally filter to channels a specific participant belongs to. Auto-approved.

slack_list_dmsA

List 1:1 direct-message conversations visible to the user (id, other participant). Optionally filter to the DM with a specific participant (user id, handle, or display name). Auto-approved.

slack_list_group_chatsA

List group-DM conversations visible to the user (id, name, participants). Optionally filter to group chats containing a specific participant (user id, handle, or display name). Auto-approved.

slack_resolve_permalinkA

Parse a Slack message permalink (from a message's "Copy link") into the channel id, timestamp, and (if the link points at a threaded reply) thread root timestamp needed by slack_get_channel_history/slack_get_thread_replies. Reads no message content -- just decodes the link. Auto-approved.

slack_refresh_user_cacheA

Force an immediate refresh of PrivacyFence's local cache of Slack workspace member names/emails, used to resolve message authors in channel history, thread replies, and search results without a per-message users.info call. Refreshes automatically about once a week; call this when a teammate who joined recently isn't resolving correctly yet. Auto-approved -- refreshes name/email lookups only, reads no message content.

slack_refresh_channel_cacheA

Force an immediate refresh of PrivacyFence's local cache of Slack channel/DM/group-DM names, used to resolve which conversation a message belongs to in search results and history/thread reads without a per-message conversations.info call. Refreshes automatically about once a week; call this after a new channel is created so it resolves by name right away. On a workspace with a lot of channels, one call may not finish the whole sync -- check the result's has_more flag and, if true, call this tool again (same args) to continue from where it left off. Auto-approved -- refreshes name lookups only, reads no message content.

slack_get_channel_historyA

Fetch recent messages in a Slack channel. Returns {messages: [...], has_more: bool}, plus a note when has_more is true -- more messages exist than were returned (a small/inactive channel, or a Slack-imposed cap; see docs/slack-setup.md) -- call again with a larger limit, or narrow the time range, to see the rest instead of assuming this is everything. Requires user approval.

slack_get_thread_repliesA

Fetch all replies in a Slack thread. Returns {messages: [...], has_more: bool}, plus a note when has_more is true -- more replies exist than were returned (see slack_get_channel_history's own note on why). Requires user approval.

slack_search_messagesA

Search Slack messages matching a query, a participant, or both. Prefer participant (a user id, handle, or display name) over a text-only query when looking for messages from or with someone -- e.g. 'Bob wrote me' is participant='Bob'; 'Bob in a chat with Jane' is participant='Bob,Jane' -- it reads the matching DM/group-chat conversation(s) directly instead of relying on Slack's search index, which is more reliable for participant-based lookups. Combine with query to also filter those conversations' text. Defaults to the last 90 days (about 3 months) so results on a workspace with long history aren't dominated by old, no-longer-relevant matches; widen or disable via days. Requires user approval.

slack_create_group_chatA

Create (or reopen the existing) group-DM conversation with the given participants and return its channel id, ready for slack_send_message. Participants must already have a Slack user id (from slack_list_dms, slack_list_group_chats, or a message's user_id) -- this does not resolve email addresses or handles. Requires user approval.

slack_send_messageA

Send a message to a Slack channel or DM. Requires user approval. Set mark_unread=true to leave the message unread after sending (useful when sending a DM to yourself as a note; requires the im:write scope on the user token for DMs).

tasks_list_task_listsB

List all Google Task lists. Auto-approved.

tasks_list_tasksC

List tasks in a task list. Auto-approved.

tasks_get_taskB

Fetch a single task by id. Auto-approved.

tasks_create_taskC

Create a new task. Requires user approval.

tasks_update_taskB

Update a task's title, notes, or due date. Requires user approval.

tasks_complete_taskA

Mark a task as completed. Requires user approval.

tasks_uncomplete_taskB

Mark a task as not completed. Requires user approval.

tasks_move_taskC

Move a task from one list to another. Requires user approval.

telegram_list_chatsB

List Telegram chats (id, name, type, unread count). Auto-approved.

telegram_get_messagesC

Fetch recent messages from a Telegram chat by chat id. Requires user approval.

telegram_search_messagesB

Search messages across Telegram chats by keyword. Requires user approval.

telegram_refresh_chat_cacheA

Force an immediate refresh of PrivacyFence's local cache of Telegram chat/group/channel names, used to resolve which chat a message belongs to in search results and chat history without a per-message lookup. Refreshes automatically about once a week; call this after a new chat starts so it resolves by name right away. Auto-approved -- refreshes name lookups only, reads no message content.

telegram_send_messageB

Send a message to a Telegram chat or user by chat id. Requires user approval.

privacyfence_check_policyA

Before calling a gated tool, ask whether that exact call would auto-accept or need a human. Pass the connector, tool and args you're about to call. Returns {gate, verdict, matched_rule, matched_rule_id, reason, pii_gate_may_apply}. verdict is 'auto_accept' (the real call will pass through identically), 'requires_review' (no configured rule can match these args), or 'unknown' (it depends on fetched content this can't see in advance). matched_rule_id is set only for 'auto_accept': the privacyfence_list_policy rule id that lets this call through, usable as privacyfence_propose_policy_change's rule_id. For 'review'-gated (read) tools pii_gate_may_apply is always true: the PII gate scans real content and can force a popup even when a rule matches, which can't be predicted. No external API call, no popup, no side effects -- call it freely while planning, especially before and during an unattended run. reason: one sentence on why you're checking now (logged, self-reported, unverified).

privacyfence_list_policyA

List every configured auto-accept rule, plus the scope catalogue privacyfence_propose_policy_change accepts. Returns {rules, scope_groups}. Each rule has: id (pass as privacyfence_propose_policy_change's rule_id to update or remove it), sentence (human-readable), connector, scope_type, value, operations (internal keys, informational), verbs ({verb, family} pairs; family is 'read', 'write', 'send' or 'destructive'), conditions, and covered_tools (every tool name the rule can auto-accept). Each scope_groups entry has an id (pass as group), the verbs that scope can govern (pass a subset as verbs; any other verb is rejected before a popup), and whether it needs a value. Call this before proposing a change: an id or group only matches something real if you listed it rather than guessed. Read-only, no popup. reason: one sentence on why you're listing the policy now (logged, self-reported; this discloses the full rule set).

privacyfence_propose_policy_changeA

Propose adding, updating or removing an auto-accept rule (a scope plus allowed verbs). ALWAYS blocks on a dialog a human must approve. If declined, or in an unattended session, it errors -- check the result, never assume success. Call privacyfence_list_policy first: group, verbs and rule_id must be listed, not guessed; a verb not in that group's scope_groups entry is rejected before any popup.

operation='add'/'update' need group (a scope_groups id, e.g. 'drive.folder'), value (resource ids/names the scope matches, e.g. a Drive folder id; omit when the group's needs_value is false) and verbs (a non-empty subset of the group's verbs, e.g. ['read', 'update']). 'update' also takes rule_id (that rule is removed, then re-added). 'remove' needs only rule_id.

Returns {confirmed, changed, description, rule_ids}: changed is false when confirmed but nothing differed; rule_ids names the rules affected.

reason: one sentence on why you're proposing this (logged, unverified).

privacyfence_begin_unattended_sessionA

Tell PrivacyFence this conversation is an unattended/scheduled Cowork run (e.g. a Routine firing on a schedule) with no human necessarily watching, for the rest of this connection. From then on, any gated tool call that isn't already covered by a configured auto-accept rule is denied immediately with a clear error, instead of PrivacyFence opening a native approval dialog that nobody will answer. Call this once at the start of a scheduled run, and pair it with privacyfence_check_policy to plan which steps are safe to attempt. Never changes what auto-accepts, only what happens when nothing does. Errors if an administrator hasn't enabled unattended sessions for this install. Do not call this during a normal interactive conversation -- it makes denials immediate instead of prompting. reason: one sentence on why this session is unattended (e.g. the Routine/schedule that triggered it) -- logged in the audit entry for this session change, since no popup is shown for it to appear in.

privacyfence_end_unattended_sessionA

Clear the unattended-session flag set by privacyfence_begin_unattended_session for this connection, restoring normal interactive approval behavior. Call this when a scheduled run finishes. Not strictly required -- the flag also clears automatically when the connection closes -- but call it if this connection might be reused afterward for something interactive. reason: one sentence on why the unattended session is ending now -- logged the same way as privacyfence_begin_unattended_session's.

privacyfence_await_approvalA

Long-poll pending approvals from gated calls' {status: 'approval_pending', approval_id, ...} results; status only, never content. Before the first call for an approval, relay that result's message and url (binder_url if several) to the user -- never wait silently. If pending_count > 1, first issue your other ready gated calls, then pass all approval_ids in one call (one human pass). Keep timeout_seconds under your client's tool-call timeout. Returns {approval_id: status}: 'pending' (schedule a follow-up if you can, else call again), 'approved' (re-issue the ORIGINAL call with identical arguments -- the only way to get the data), 'denied' (a human said no -- re-issuing will not change that; don't retry, ask the user how to proceed unless denial_feedback says otherwise), 'expired' (re-issuing starts a fresh approval) or 'unknown' (no such id here). denial_feedback holds the user's instruction for a denial: follow it. Returns on any change or at the timeout. Prefer this over re-issuing the original call to poll.

privacyfence_statusA

Check whether THIS PrivacyFence install is set up: call it before the first PrivacyFence-governed action in a conversation, or when asked why a connector (gmail_*, ...) is missing. An empty or partial tool list means connectors aren't authenticated yet, NOT that PrivacyFence is irrelevant -- this is the one tool guaranteed to exist even when every other tool is missing. Returns {mode ('local'/'org'), setup_complete (any connector authenticated), connectors [{name, enabled, authenticated, blocked_by: null, 'no_org_config', 'not_authenticated' or a reason}], next_step, message, sign_in_url (always null)}. If setup isn't complete, relay message to the human as-is. next_step 'open_privacyfence_companion' (local): the human opens PrivacyFence's companion app (menu-bar/tray icon; Linux: applications menu) and chooses Open Settings; you can't, and have no link. 'contact_your_administrator' (org): sign-in is via the org's IdP. Only side effect: an audit entry. reason: one sentence on why you're checking now (logged).

privacyfence_create_upload_slotA

Get a one-time URL to upload a local file to PrivacyFence, for a client without the PrivacyFence extension (e.g. Claude Code) -- use it when a tool's local_path/attachments parameter says PrivacyFence can't read your files directly. Returns {upload_id, upload_url, method: 'PUT', max_bytes, expires_at, example}: PUT the raw bytes to upload_url (e.g. the curl -T example); no Authorization header -- the URL is the credential. Then pass upload_id to the tool that needs the file (its upload_id parameter, e.g. drive_upload_file, or an 'upload:' attachments entry, e.g. gmail_*_with_attachments). Never fetch upload_url yourself or pass it as local_path. Single-use, expires in 10 minutes, claimable only by your next tool call in this conversation. This uploads, gates and approves nothing: that happens when the destination tool runs. reason: one sentence on why this file is needed now (logged, self-reported, unverified).

Prompts

Interactive templates invoked by user choice

NameDescription

No prompts

Resources

Contextual data attached and managed by the client

NameDescription

No resources

TDQS

B3.4/5.0

Scored across 122 tools

Disambiguation4/5

Tools are namespaced per service (gmail_, drive_, slack_, calendar_, etc.) and the descriptions go out of their way to distinguish near-neighbors (e.g. drive_get_file_content vs drive_download_file, calendar_get_event_details vs calendar_get_event_visibility, drive_write_doc_content vs drive_docs_edit_content vs drive_docs_format_content). The main confusion risk is the combinatorial Gmail draft family (create/reply/reply_all each duplicated with a _with_attachments twin), where selection hinges on a single parameter rather than a distinct purpose.

Naming Consistency4/5

Nearly everything is snake_case verb_noun with a stable service prefix, which makes the set predictable to scan. Minor deviations exist in prefix depth (drive_ vs drive_sheets_ vs apps_script_) and a few noun-first names (calendar_get_free_busy, slack_resolve_permalink), but nothing approaches mixed conventions.

Tool Count2/5

122 tools is far past any comfortable surface for one server and bloats agent context, with clear combinatorial duplication (six Gmail draft variants, three sheets dimension tools) rather than genuinely distinct operations. It is partly excused by spanning ~12 services, but the total is still excessive relative to the scope.

Completeness4/5

Coverage across the domains is broad and deliberately gated: read/write/create/update exist for Calendar, Drive, Docs, Sheets, Gmail, Slack, Jira, Tasks, Contacts, Confluence, and Salesforce, with intentional read-only or draft-only surfaces (Gmail drafts instead of send). Known holes are explicitly documented (no contact deletion, no Sheets tab deletion, Salesforce read-only), which agents can work around.

Maintenance

ActivityActive
ResponsivenessResponsive