Google connector and write boundary
The standard path connects GSC, GA4 and GTM through exactly eight incrementally selected capability groups in the managed connector. After authorization, three read capabilities may return evidence and aggregated reports. The five write capabilities are never autonomous: a change may run only after an exact target and payload preview, a one-time approval and with at most one provider attempt. It requires an execution receipt, technical provider post-check, and rollback where supported or explicit recovery. Creating a GTM version does not publish it; GTM publish is a separate action with its own one-time approval. A changed preview needs a new approval. Google tokens stay server-side and never reach the browser, Local Agent, OpenClaw, Hermes or a model. General CMS, Bing and other writes stay closed without their own connector contract. Google data serves only the connected workspace; MarketingOS does not sell it, use it for advertising, transfer it to unrelated third parties or train general-purpose AI models with it.