Skip to content

Email Security docs: warning banners, mailbox events and privacy - #462

Merged
maximelb merged 10 commits into
masterfrom
fbF/mailsec-fixes
Oct 2, 2026
Merged

maximelb merged 10 commits into
masterfrom
fbF/mailsec-fixes

Conversation

@maximelb

@maximelb maximelb commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Email Security documentation now describes configurable warning banners, mailbox identities, access auditing and data flows as implemented.

  • Warning banners: title, fixed colour palette, logo, per-verdict overrides, plain action wording, server preview, and Gmail plain-text rendering. API, policy, automation and remediation pages agree on the contract.
  • Hunting: Body contains searches retained authored/HTML/plain text, and pre-run estimates make billed or unknown-cost execution explicit.
  • Mailbox events: each protected mailbox has its own sensor, with stable id/address and UPN when known; connection-wide events retain a connection sensor. The automation examples show per-mailbox and per-reporter counters using global suppression.
  • Quarantine: Microsoft uses a hidden folder; Gmail uses a visible label, so users can still find the message.
  • Reports: CLI examples and the API outcome table use the currently accepted malicious/spam/graymail/benign/simulation values.
  • Access/privacy: content-read audit fields, repeat-read suppression, best-effort events versus fail-closed raw downloads, and a new data-residency/encryption/data-flow page.

Documentation only. Preview and action examples require the matching released CLI/backend support. No runtime behavior or infrastructure changes.

Validation: rendered-doc build, link/Markdown checks, Go/Python snippet compilation and 215 documentation tests pass. The new counter rules were validated and exercised with the LimaCharlie CLI. The mailbox sensor overview was checked against the current event contract.

🤖 Generated with Claude Code

maximelb and others added 2 commits September 30, 2026 22:48
…nt-read audit event

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@maximelb

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Sep 30, 2026
lcbill
lcbill previously approved these changes Oct 1, 2026
@limacharlie-refractionpoint

limacharlie-refractionpoint Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

LimaCharlie Cloud Security — code scan

No new code findings were introduced by this pull request.

This check reports and never fails: no gating.fail_on is set on the code_scanning policy.

Scanned refractionPOINT/documentation b3ab604…e0a3c65 — only findings new in the head commit are listed; anything already on the base branch is the repository's own finding set, on the Cloud Security Code page.

This comment is updated in place on every push to this pull request.

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb maximelb changed the title Email Security docs: Gmail quarantine label, per-user counters, content-read audit event, data residency Email Security docs: warning banners, mailbox events and privacy Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

lcbill
lcbill previously approved these changes Oct 1, 2026
@maximelb

maximelb commented Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

/lc-review

@maximelb
maximelb merged commit 23120ff into master Oct 2, 2026
7 checks passed
@maximelb
maximelb deleted the fbF/mailsec-fixes branch October 2, 2026 00:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants