Governance boundary
Access planning uses official provider IDs, OS9 Mission Contract gates, and public-safe scope/IAM summaries. The flow never returns Google tokens or starts OAuth.
The operator surface binds official Google-managed MCP inventory to Mission Contracts, approval gates, and receipts. It creates access plans and approval evidence only; Google runtime stays behind MCP Warehouse policy.
This shell inherits authenticated page-route posture and is not exposed as a public marketing surface.
Runner registration and connector mutation stay blocked; signed Mission approval issuing, sandbox eval summaries, cost visibility, and operator sandbox interrupts are live.
Published /api/v2/os9 fleets, runners, approvals, and mission contracts use route-level auth and explicit OpenAPI registration; broader OS9 APIs remain closed.
Verified from Google source updated 2026-06-01.
Registered slices expose L0/L1 tools only.
Official servers still blocked from runtime.
google_mcp_provider_access gates are compiled.
Read, sensitive read, candidate, side effect, privileged.
Maestro and Prometheus do not receive Google credentials.
Access planning uses official provider IDs, OS9 Mission Contract gates, and public-safe scope/IAM summaries. The flow never returns Google tokens or starts OAuth.
Public-safe evidence digest for official Google MCP providers that are not runtime-enabled. It exposes evidence IDs and counts only.
Actionable evidence checklist for catalog-only providers. Each row points to existing OS9 evidence lanes or package gates and grants no runtime authority.
Live read-only snapshot of the evidence ledgers for one catalog-only provider. Evidence states are observability; they do not authorize runtime promotion.
Workspace MCP is visible for planning, but Gmail, Drive, Calendar, Chat, and People stay blocked until user OAuth subject binding and credential-boundary receipts are attached to an OS9 contract.
Google Cloud MCP runtime requires hash-only project and principal evidence before credentials can load.
These candidates remain non-executable until the Workspace OAuth subject contract and provider-specific runtime tests are complete.
Select official Google MCP servers and request a bounded OS9 risk tier.
Provider options come from the verified Google MCP catalog.
No OAuth URL, approval token, credential, or Google tool result is produced here.
{
"provider_ids": [
"google.developer.developer_knowledge"
],
"risk_tier": "read_only",
"mission_contract_id": "mission_contract_d1b1006685640fcfb675",
"reason": "Review Google MCP access through OS9."
}Signed approval evidence can be issued only after OS9 validates the contract, gate, and capability.
Hash-only subject, revocation, runtime-readiness, and promotion-review receipts for Workspace MCP.
Accepted hash-only credential-boundary receipts available for Google Cloud MCP runtime attachment.
Governed read-only Google MCP attempts with receipt hashes and sanitizer evidence.