Home / Cases / beta-001

One person, two assistants, six deployments, one shared account

An early beta user: a business user whose day runs in a mail, calendar and files suite, with two chat assistants connected to different parts of it and a third, out of scope here, handling text messages. Two assistants, six deployments, and one Google account that four of them share. Everything below was elicited from one interview on 2026-09-21; nothing was measured.

Where the words on this page came from. One interview, elicited by riskmandate.ai on 21 September 2026 and transcribed automatically. The transcript is not published; every quoted fragment was checked against it. Nothing here is measured. No grant was probed, no tool list was captured, and every delta is provisional against a published shape that is not this deployment. The deployer has not yet corrected the draft, and the correction is the mandate.

The estate

One person, two assistants, six deployments, one shared accounteach deployment is an ABP; the account is where four of their grants unionOne persona business user, elicited on 21 SeptemberChatGPTallow all: the per action approval is offClaudeapproval mode not statedGmailmailCalendareventsDrivefilesNote takermeetingsSlackchannelsInbox scoutthe same grant, nobody presentOne Google accountmail, calendar, drive and the scout: the union of four grantsA third assistanttext messages: connected to neither, not mappedSix ABPs one level down, each over the grammar. One level up, one mandate in the person's words against the union of every grant they hold.
The estate as elicited. The dashed scout holds the Gmail grant with no person in front of it, which makes it a deployment of its own; the account underneath is the junction where four separately consented grants meet.
DeploymentConsentNearest published shapeThe mandateProvisional delta
ChatGPT with the Gmail connector, allow allallow allanthropic/gmail-connector/default1 wanted, 3 refused, 19 unstated5 excess, 4 unbounded
ChatGPT with the Google Calendar connector, allow allallow allnone published0 wanted, 2 refused, 21 unstatedno shape to compute against
ChatGPT with the Google Drive connector, allow allallow allgoogle/drive/readonly-connector1 wanted, 3 refused, 19 unstated2 excess, 1 unbounded
ChatGPT with a meeting note taker connectedallow allnone published1 wanted, 2 refused, 20 unstatedno shape to compute against
The inbox scout: the same Gmail grant, running with nobody presentallow allgeneric/scheduled-job/service-account1 wanted, 6 refused, 16 unstated7 excess, 7 unbounded
Claude with the Slack connectornot statednone published1 wanted, 1 refused, 21 unstatedno shape to compute against

Allow all is on for every ChatGPT connector. Asked whether they were authorising each action, the deployer said they had done the allow all. That is the third barrier kind switched to off: the one setting the product puts in front of an action is not there, so on every row of the four ChatGPT deployments the barrier is whatever Google's scopes leave and nothing above it.

The account is the junction

Four deployments run over one Google account: mail, calendar, drive and the unattended scout. Each holds its own grant, each was consented to separately, and the account's exposure is the union of the four, which no single deployment's ABP can see. A connector attaches to the account rather than to a conversation, so each of these grants holds in every session that has it attached, and the account's exposure is the union of all four. A scheduled task holds the same grant with nobody in front of it.

This is the fractal claim made concrete rather than argued. One level down, each deployment is four objects over the grammar. One level up, the person is four objects again: one mandate, in their words, against the union of every grant they hold. Same shape, different ontology, and the account is the node where the levels meet.

What they told us about how they work

The calendar has no backup, and the mailbox is the only trail

The thing the deployer values most is the thing with no backup. Asked, the answer was that as far as they know a deleted event is gone. But some of a calendar arrives as mail: invitations, updates, declines and cancellations all land in the inbox, and from that trail some events could be rebuilt. Which ones is a map nobody has drawn, and it decides what a deletion would actually cost.

Which events a deletion would actually costthere is no backup; the mailbox is the only trail, and it only holds what was sentArrived as an invitationfrom somebody else, or a group meeting with an agendathe invitation, its updates and anycancellation are in the mailboxRebuildable from your own mailYou created it, with guestsa one to one you set upyour sent mail and the guests' inboxeshold the invitationRebuildable from somebody's mailbox,perhaps not yoursYou created it, no guestsa block of time, a reminder, a note to yourselfnothing ever left the calendarNot rebuildable: a deletion is theend of itThe proportion between the three is unknown for this estate. It is the number that says what one deletion costs, and the deployer can produce it with one prompt.
Three kinds of event, sorted by what could put them back. The clause on the calendar page asks the assistant to say which kind an event is before it touches it.

Open questions the deployer can answer

Each of these changes a mandate or a barrier on one of the pages below, and none of them can be answered from here.

  1. What produces the P0 and P1 marking? If it is a Gmail feature or a filter, it is a setting in the account. If it is the assistant, it is the scout below acting on mail rather than only reading it, which changes that deployment's mandate.
  2. How is the inbox scout implemented? A scheduled task inside the assistant, a recurring prompt the person runs, or a third party with its own grant. Each is a different shape and only the first is covered by the nearest shape named below.
  3. Which scopes did the calendar and drive consents ask for? The consent screens were not captured. Read only and full access are different grants and the same allow all click sits in front of both.
  4. What is the approval mode on the Slack connector? Not asked. Per action or allow all decides the barrier on every row.
  5. What does the meeting note taker's connector expose? Transcripts of other people's speech, summaries, or both, and whether the connector can write back. Not documented anywhere this site has read.
  6. Which calendar events could be rebuilt from mail? Events that arrived as invitations leave a trail in the mailbox; events the person created with no guests leave none. The proportion is unknown and it decides how much of the calendar a deletion would actually cost.

The first prompt, for both assistants

Before any of the six pages, one prompt to paste into each assistant separately. Two answers, one account, and the comparison is the point.

Prompt AThe connectors, from the insideRun it in ChatGPT and in Claude. The two lists together are the estate.
List every connector and every external tool you have on my account, by name. For each
one say:

  - whether each action needs my approval, or whether I have allowed all
  - what you have already done through it in our conversations, as far as you can see,
    and say plainly if you cannot see earlier sessions
  - whether it can only read, or can also change or send something
  - whether anything runs through it on a schedule, when I am not here

Then tell me which of these connectors share one underlying account, because a grant on
one of them is a grant on the account.

The six deployments

ChatGPT with the Gmail connector, allow all

a different client on the same platform: the measured profile for a chat assistant with a Gmail connector, 4 of 6 rows seen on the thing itself. The Google scopes are the same layer; the tool list is not this product's.

1 said, 3 inferred, 19 unstated

ChatGPT with the Google Calendar connector, allow all

no published shape. A calendar connector for a chat assistant is on riskmandate.ai's list of shapes asked for and not yet published, and the grammar this site is written in has no word for a calendar event at all, which is the finding on this page.

0 said, 2 inferred, 21 unstated

ChatGPT with the Google Drive connector, allow all

the read only shape, derived and not measured. This deployment's consent was not captured and may be the full drive scope, in which case the nearest shape understates the grant by every write and delete row.

1 said, 3 inferred, 19 unstated

ChatGPT with a meeting note taker connected

no published shape, and nothing this site has read documents what the connector exposes: transcripts, summaries, or both, and whether it can write. Everything in it is other people's speech.

1 said, 2 inferred, 20 unstated

The inbox scout: the same Gmail grant, running with nobody present

the derived shape for a job that runs when nobody is watching. It is not a mail connector, so the primitives differ; what it shares with this deployment is the one property that matters: no person's judgement stands in front of any action.

1 said, 6 inferred, 16 unstated

Claude with the Slack connector

no published shape. A Slack connector for a chat assistant is on riskmandate.ai's list of shapes asked for and not yet published, with the note that channels are mostly other people's writing.

1 said, 1 inferred, 21 unstated

Out of scope

Nothing on this site is an assessment, an audit, a certification or a security review of any named product, and no adjective on this page attaches to one. A case describes one person's deployments in their own words and against published shapes with their sources and dates.

The case as JSON · The walkthrough the discovery prompts come from · The estate universe