---
bcp_version: "0.8"
file_type: boundaries
parent: https://registry.brandcontextprotocol.dev/monday-com-4ca31c9f/.well-known/brand.md
last_updated: 2026-08-21
---

# Boundaries

This file is the primary reference for brand-safety agents, vendor platforms, and any party generating content or configuring agents on behalf of monday.com. It encodes monday.com's published and owner-confirmed rules for how agents may act, what requires human review, and what is never permitted.

## Hard nos

These are absolute. No exceptions, no contextual allowances.

```yaml
hard_no:
  - item: >
      Agents must not perform actions outside their explicitly granted permissions.
      Do not imply or depict agents acting beyond their configured scope.
    tier: core
    trigger: any content or configuration suggesting an agent can act on resources or channels it has not been explicitly permitted to access
    allowed_alternative: describe agents as operating within a defined, human-configured permission boundary
    source: "support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com"
    evidence_quote: "Remember that the agent cannot perform actions outside of what it is explicitly permitted to do."

  - item: >
      High-impact actions — deleting data, changing user permissions, accessing
      confidential information — must not be executed by an agent without prior
      human review and approval. Do not depict or instruct agents to perform these
      autonomously.
    tier: core
    trigger: any content depicting an agent deleting data, changing permissions, or accessing confidential information without a human approval step
    allowed_alternative: show the agent flagging the action and awaiting explicit human approval before proceeding
    escalation: route to human reviewer before execution; do not proceed autonomously
    source: "monday.com/blog/ai-agents/ai-agent-security-protection/"
    evidence_quote: "High risk: Approval required before execution. Examples: deleting data, changing user permissions,"

  - item: >
      Do not depict or imply that legal or ethical accountability for agent
      actions rests with the agent itself. Accountability always rests with the
      human owner responsible for that agent's behavior and configuration.
    tier: core
    trigger: any framing that treats an agent as an independent legal or ethical actor
    allowed_alternative: frame agents as tools operated by and accountable to named human owners
    source: "theaiinnovator.com/monday-com-rebuilds-its-platform-for-ai-agents-not-just-humans/"
    evidence_quote: "Agents are tools in the hands of humans, and humans are responsible for their agents,"
    authority_note: >
      This quote is from an independent publisher reporting co-CEO statements.
      Owner-confirmed framing aligns: agents are tools; humans are responsible.
```

## Soft nos

These are judgment calls. Context determines appropriateness.

```yaml
soft_no:
  - item: >
      Do not depict agents with broad, unscoped permissions. Default framing
      should show each agent receiving only the permissions it needs for its
      specific job, reviewed regularly.
    tier: default
    condition: >
      Acceptable to describe expanded permissions only when context makes clear
      those permissions were deliberately granted and reviewed by a human owner
      for a specific, named purpose.
    source: "monday.com/blog/ai-agents/ai-agent-security-protection/"
    evidence_quote: >
      "Start with least privilege, not broad access: Give each agent only the
      permissions it needs for its specific job, and review those permissions
      regularly."

  - item: >
      Write tools (send, create, edit, delete) should not be depicted as active
      by default in monday agents. Default state is inactive; a human must
      explicitly review and activate each write tool before an agent may use it.
    tier: default
    condition: >
      Acceptable to show write tools as active only after explicitly depicting
      the human review and activation step.
    source: "support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com"
    evidence_quote: >
      "Write tools are added as inactive and the agent will prompt you to review
      the setup. You can explicitly activate the tool when you're ready."

  - item: >
      Do not depict agents posting to any Slack channel or emailing any contact
      without showing that those recipients and channels were explicitly
      configured and restricted by a human operator.
    tier: default
    condition: >
      Acceptable to show agent-initiated communications when the copy or visual
      makes clear the agent is operating within administrator-defined guardrails
      (specific channel allowlist, specific contact allowlist).
    source: "support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com"
    evidence_quote: >
      "you can restrict the agent to only post in a specific Slack channel, or
      only email certain contacts"

  - item: >
      Do not depict full agent autonomy as the starting point. The staged-autonomy
      model — agent states intended action, human approves, greater independence
      follows — should be the default narrative arc when showing agent capability.
    tier: default
    condition: >
      Acceptable to show a more autonomous agent workflow only when context
      makes clear that prior human approval and trust-building steps have
      already been completed.
    source: "theaiinnovator.com/monday-com-rebuilds-its-platform-for-ai-agents-not-just-humans/"
    evidence_quote: >
      "The way we solve it is by first having agents tell you what they're going
      to do, and then you approve,"
    authority_note: Independent publisher reporting co-CEO statements.
```

## Brand safety

For vendor platforms, brand-safety tools, and DSPs.

```yaml
brand_safety:
  adjacency_unsuitable:
    - "Content depicting AI systems operating without human oversight or accountability (GARM Floor)"
    - "Content implying AI agents are autonomous legal actors independent of human responsibility"
    - "Misinformation or disinformation content"
    - "Content that promotes unauthorized data access or privacy violations"
    - "Hate speech, harassment, or targeted abuse (GARM Floor)"
    - "Violence or graphic content (GARM Floor)"
  adjacency_acceptable:
    - "Enterprise technology and SaaS"
    - "Project management and productivity"
    - "Business operations and workflow automation"
    - "AI and machine learning — responsible-use framing"
    - "HR, PMO, media operations, and professional services"
    - "Business news and analysis"
  adjacency_contextual:
    ai_autonomy_content:
      rule: >
        Adjacent content about AI autonomy is acceptable only when it discusses
        human oversight, staged trust models, or responsible deployment.
        Unsuitable when it celebrates ungoverned autonomy or treats human
        oversight as an obstacle.
    security_content:
      rule: >
        Adjacent content about cybersecurity is acceptable when focused on
        enterprise protection. Unsuitable when sensationalizing breaches or
        promoting offensive tooling.
```

## Regulatory constraints

```yaml
regulatory:
  framework: "SOC 2 Type II, ISO 27001, GDPR, HIPAA (monday.com holds relevant certifications; verify current scope at monday.com/l/security)"
  notes: >
    monday.com is a publicly traded company (Nasdaq: MNDY). Any agent generating
    content that references financial performance, revenue figures, customer counts,
    or forward-looking guidance must use only claims recorded in claims.md with
    proof_status: approved and must not introduce, extrapolate, or paraphrase
    financial metrics beyond the approved_language for each claim.
    Revenue and guidance figures are time-sensitive; always use the as-of date
    bound to the specific claim entry in claims.md.
  restricted_claims: >
    Financial performance figures, customer counts, growth rates, and forward-
    looking revenue guidance require Legal or Finance owner confirmation before
    use in advertising, regulated communications, or comparative contexts.
    Do not generate comparative financial claims against named competitors.
```

## Agent configuration guidance

The following rules apply to agents configured to act on behalf of monday.com or within monday.com's platform. They are operational extensions of the hard nos and soft nos above.

```yaml
agent_config:
  named_owner_required:
    rule: >
      Every agent deployed on the monday.com platform must have a named human
      owner accountable for its behavior and configuration. Do not deploy or
      describe agents without a designated responsible human.
    tier: core
    source: "monday.com/blog/ai-agents/ai-agent-security-protection/"
    evidence_quote: "a named human owner who is accountable for its behavior and configuration"

  permission_review_cadence:
    rule: >
      Agent permissions must be reviewed regularly, not set once and forgotten.
      Content and documentation should reflect ongoing human oversight as the
      default, not a one-time setup.
    tier: default
    source: "monday.com/blog/ai-agents/ai-agent-security-protection/"

  external_comms_guardrails:
    rule: >
      Agents initiating external communications (email, Slack, other channels)
      must operate within administrator-configured recipient and channel
      restrictions. No agent may send to unrestricted recipients by default.
    tier: core
    trigger: any agent workflow involving outbound email or messaging
    escalation: require human operator to define and activate the allowed recipient or channel list before the agent may send
    source: "support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com"
```
