Sales Outreach Agent
ATC-AGT-0005502
91
critical risk
Identity
Who owns it, and what it is for
- Declared purpose
- Draft and send follow-up mail to inbound leads within one business day.
- Business owner
- Rowan Adeyemi · Revenue Operations
- Technical owner
- Priya Raman · Support Engineering
- Provider and model
- Google · gemini-2.5-pro
- Framework
- Custom
- Environment
- production
- Data classes reached
- Confidential, PII
- Last activity
- Contained 3 hours ago
Risk
Why the score is 91
Every point is accounted for. Remove a factor and the score moves by exactly that much.
- +25
Incident history
Open incident: attempted bulk export after a refusal
- +22
Behaviour
Read volume 48× its own baseline within four minutes
- +16
Data
Customer PII across the CRM
- +12
Action
Held send rights to external recipients
- +10
External exposure
Outbound mail leaves the tenant
- +6
Privilege
Requested an export grant it was never issued
- 91Total
Access
What it may do, action by action
Permissions are held at the level of the action, so reading a record and changing its banking details are separate grants that can be decided separately.
- read_contactSalesforceL0 ReadGranted
- create_contactSalesforceL2 Execute, low riskGranted
- export_contactsSalesforceL3 SensitiveWithheld
- send_emailEmailL2 Execute, low riskWithheld
Dependencies
MCP servers it is bound to
- pending
Email MCP
Internal · Messaging
send_email
Execution identity
What it authenticates as
An agent does not reach anything by itself. It runs as a machine identity, and that identity is what actually holds the credential — so the agent's permissions are only ever a subset of what this can do.
- Salesforce Integration Account66
ATC-MID-0003901 · Salesforce
Client secretShared with 1 other agent. An action taken through this credential cannot be attributed to one of them.
Supply chain
Bill of materials
What this agent is assembled from. It is also the answer to the blast-radius question when one of these is compromised.
Model
Framework
Tools
MCP servers
Databases
Packages
Runtime
Decisions taken on its behalf
Every governed action produces one of these, and each records the rule that decided it.
- 10:01:21read_contactsalesforce:248 recordsAllowed
rule: revenue.read.contacts
- 10:01:28send_emailmcp:emailHeld
rule: mcp.pending-approval
- 10:01:35export_contactssalesforce:bulkDenied
rule: data.egress.bulk-export
- 10:01:36export_contactsreporting-apiDenied
rule: data.egress.bulk-export
- 10:01:37sessionagentDenied
rule: containment.quarantine
Incident INC-2209
Bulk export attempted twice, then contained
The agent read 248 customer records inside a normal task, was refused an export, and immediately attempted the same export through a second endpoint. The second attempt is what moved this from an anomaly to an incident: one refusal is a policy working, two is an agent looking for a way around it.
- 10:01:14Agent authenticated against the CRM
- 10:01:18Salesforce queried
- 10:01:21248 customer records read — 48× the session baseline
- 10:01:28Email MCP called; server is pending approval
- 10:01:35Bulk export attempted and refused
- 10:01:36Same export attempted through a second endpoint
- 10:01:37Agent quarantined; tokens revoked, sessions closed, evidence preserved
Blast radius
- Systems reached
- Salesforce, Email MCP
- Records read
- 248 customer contacts
- Records modified
- None
- Data leaving the tenant
- None — both attempts refused
- Credentials used
- 1 brokered token, revoked
- Agents sharing that credential
- None