ActovianOperating system
Local simulationExternal actions off
Production writes disabled
GOOGLE WORKSPACECONTROLLED CONNECTION

Connect carefully. Keep every external action accountable.

Gmail and Google Calendar are the first provider ecosystem. Actovian will not claim a connection or enable a write until OAuth, storage and webhook secrets are configured.

01Secure valuesRequired first
02Owner authorizationOAuth + PKCE
03Read-only syncGmail + Calendar
04Controlled writesApproval required
EMAIL ADAPTER

Gmail

Read threads, classify replies and create approval-bound drafts.

Not connected
  • Read-only incremental sync
  • Draft before send
  • Allowlisted recipients only
CALENDAR ADAPTER

Google Calendar

Inspect availability and book an approved meeting with evidence.

Not connected
  • Event-level access
  • Idempotent booking
  • Provider event ID required
SECURITY CONTRACT

Controls before connectivity

OAuth 2.0 + PKCE

Short-lived state, S256 challenge and offline refresh.

Encrypted tokens

Credentials stay server-side with key versioning.

Webhook replay guard

Channel token and message ID must both verify.

Recipient allowlist

Sending outside an approved address or domain is blocked.

Provider evidence

A real action requires the Google provider ID.

Disconnect cleanup

Tokens, channels and sync access are revoked together.

OPERATIONAL STATUS

No hidden connection state

Provider adapterVerified
Calendar intakePrepared
Webhook channelInactive
Incremental syncNot started
Persisted resources0
Provider accessNone
Automatic email sendUnavailable
Open pilot readiness
REQUESTED GOOGLE SCOPES5 minimal capabilities
PKCE S256State TTL 600sRefresh server-only