RedHub AIRedHub AI
Tool Gate · How it works

How the roll-up gate works

How the Agent Connector Access Auditor gate works

This tool grades a fleet of AI-agent connectors on least-privilege. It reads 7 connectors and rolls them into one verdict — the worst, never the average — then a gate that can only make it worse.

The 7 connectors

01C3 · CRM sync connectorfix firstrisk 65UNGOVERNED
02C2 · Support inbox drafterrisk 44OVER-SCOPED
03C5 · Billing export botrisk 65OVER-SCOPED
04C6 · Old Zapier hookrisk 68OVER-SCOPED
05C1 · Calendar read agentrisk 14LEAST-PRIVILEGE
06C7 · Docs read agentrisk 23LEAST-PRIVILEGE
07C4 · Analytics read-onlyrisk 0LEAST-PRIVILEGE
GOVERNED
every connector least-privilege
DRIFTING
worst is over-scoped
EXPOSED
any connector ungoverned
Ungoverned-connector · worsen-only

A connector that can WRITE regulated data with no named owner is UNGOVERNED however low its risk score — and one ungoverned connector makes the whole fleet EXPOSED, regardless of the score.

EXPOSED

Why: Three connectors are least-privilege and three are merely over-scoped — but the CRM sync can write regulated data with no owner, so it's UNGOVERNED. Fleet posture is the worst connector, never the average, so it reads EXPOSED. 1 of 7 ungoverned · worst-not-average · mean risk 40.

Fix firstC3, the CRM sync connector — assign an owner and scope it down; an unowned regulated-write connector is the whole fleet's exposure.

No single connector is the crisis — the clustering is. The roll-up takes the worst, the gate escalates when trouble compounds, and it names the one thing to fix first. Grades connector configuration, not people. Confirm data-handling rules with your security or compliance owner.