01
Credentials stay local
Provider sign-in details stay on the enrolled Mac.
EmailOS prepares eligible inbox work on the Mac that owns the account. Approved team context follows a separate, scoped path with bounded evidence.
The EmailOS app prepares eligible drafts on the account Mac. The approved provider connection stays on its designated host Mac; SwarmOS returns only scoped, cited context after actor, device, grant, purpose, and revocation checks. The portal holds administration metadata, not private work.
01
Provider sign-in details stay on the enrolled Mac.
02
A review should show where the connection lives, what the request may use, and what happens when policy changes.
The host Mac owns the provider interaction. A teammate does not receive its credential or unrestricted provider access.
Define one source, purpose, role, approved Mac, and expiry. Check the cited result, then revoke the source and confirm the next request is withheld.
Encryption, OAuth scopes, app updates, support evidence, and incident handling each have their own owner and current scope. A source file, control surface, or activity record is not a formal attestation; match each item to the exact product version and environment under review.
Start with one approved Mac, one source, and one purpose. Verify what may return, how access ends, and which evidence applies before expanding scope.
The selected account, purpose, and approved permissions are checked.
03
The reply receives only the approved details needed for that task.
An allowed request receives only the context needed for its purpose. A gap stays visible instead of becoming an invented answer.
Role, source, device, expiry, or membership changes are checked before disclosure. An out-of-scope result is denied or withheld.