Connect your Gmail to grant TokenForm read and send access. Your OAuth token stays secure โ agents only get a constrained PAT.
Define what the agent is allowed to do. These constraints are enforced by TokenForm.
These rules are enforced by the proxy. The agent CANNOT bypass them.
Instructions sent to the agent. Compliance depends on agent architecture.
Simulate what an agent would try to do. TokenForm will allow or block based on the PAT constraints.