AW-046

Type: Risk acceptance

Subject: R-01

Decision requested: Accept the residual risk recorded for R-01 - Indirect prompt injection via externally-authored calendar content

Inherent / residual: High / Moderate

Control owner: InfoSec (tool permissions) + Google Workspace Admin (invitation settings)

Context: Treatment: Reduce - residual remains permanently. What we can commit to: We can stop an instruction hidden in a meeting invitation from causing Claude to send, change or delete anything by itself. Every such action stops for a person to approve. What remains: We cannot stop the hidden instruction being read, and we cannot stop it shaping what Claude tells you. If it produces a misleading summary, nothing detects that. Anyone able to send your staff a meeting invitation can attempt it - no account and no prior access required. Basis for acceptance: Yes - accept that answers drawn from externally-authored content may be influenced, and that staff must not treat agent output as authoritative.

No verification items specific to this connector.

Ruling:

Amendment or condition: