{
  "trust_level": "claimed",
  "official_brand_source": false,
  "verification_method": null,
  "verified_domain": null,
  "verified_at": null,
  "verification_last_checked_at": null,
  "verification_expires_at": null,
  "status": "active",
  "customer_handle": "monday-com-4ca31c9f",
  "certification_status": "not_certified",
  "registry_certified": false,
  "certification": null,
  "brand_name": "monday.com",
  "response_scope": "full_tree",
  "integrity": {
    "version": 2,
    "publication_id": "1de3ef44a92785600a202725729ebe4e972a280602a7059d219cd2b50d4dcff5",
    "revision_id": "81ff9c4b-cdd3-45a0-8d66-f48af61fea8b",
    "manifest_sha256": "fb291b0bce2943d02f6ba0f37fd5e0a1016e0387cc2d910335142531a292843c",
    "manifest_signature": "Mi9dowE+Fj/RDuDqkOHiphczlu+Q1GiEb5s5BLPtbfm7XouVbBjQZ4zvntFkUvQcSY4OnmD3JUIVv7M+tQXQDA==",
    "manifest_signature_kid": "v1"
  },
  "verified": null,
  "schema": "bcp-readable-package-v1",
  "integrity_scope": "publication_manifest",
  "representation": "Derived readable representation; verify signatures against the canonical source files.",
  "canonical_registry_url": "https://registry.brandcontextprotocol.dev/brands/monday-com-4ca31c9f",
  "html_url": "https://registry.encodedbrands.ai/brands/monday-com-4ca31c9f",
  "files": [
    {
      "path": "/.well-known/brand/boundaries.md",
      "content": "---\nbcp_version: \"0.8\"\nfile_type: boundaries\nparent: https://registry.brandcontextprotocol.dev/monday-com-4ca31c9f/.well-known/brand.md\nlast_updated: 2026-08-21\n---\n\n# Boundaries\n\nThis file is the primary reference for brand-safety agents, vendor platforms, and any party generating content or configuring agents on behalf of monday.com. It encodes monday.com's published and owner-confirmed rules for how agents may act, what requires human review, and what is never permitted.\n\n## Hard nos\n\nThese are absolute. No exceptions, no contextual allowances.\n\n```yaml\nhard_no:\n  - item: >\n      Agents must not perform actions outside their explicitly granted permissions.\n      Do not imply or depict agents acting beyond their configured scope.\n    tier: core\n    trigger: any content or configuration suggesting an agent can act on resources or channels it has not been explicitly permitted to access\n    allowed_alternative: describe agents as operating within a defined, human-configured permission boundary\n    source: \"support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com\"\n    evidence_quote: \"Remember that the agent cannot perform actions outside of what it is explicitly permitted to do.\"\n\n  - item: >\n      High-impact actions — deleting data, changing user permissions, accessing\n      confidential information — must not be executed by an agent without prior\n      human review and approval. Do not depict or instruct agents to perform these\n      autonomously.\n    tier: core\n    trigger: any content depicting an agent deleting data, changing permissions, or accessing confidential information without a human approval step\n    allowed_alternative: show the agent flagging the action and awaiting explicit human approval before proceeding\n    escalation: route to human reviewer before execution; do not proceed autonomously\n    source: \"monday.com/blog/ai-agents/ai-agent-security-protection/\"\n    evidence_quote: \"High risk: Approval required before execution. Examples: deleting data, changing user permissions,\"\n\n  - item: >\n      Do not depict or imply that legal or ethical accountability for agent\n      actions rests with the agent itself. Accountability always rests with the\n      human owner responsible for that agent's behavior and configuration.\n    tier: core\n    trigger: any framing that treats an agent as an independent legal or ethical actor\n    allowed_alternative: frame agents as tools operated by and accountable to named human owners\n    source: \"theaiinnovator.com/monday-com-rebuilds-its-platform-for-ai-agents-not-just-humans/\"\n    evidence_quote: \"Agents are tools in the hands of humans, and humans are responsible for their agents,\"\n    authority_note: >\n      This quote is from an independent publisher reporting co-CEO statements.\n      Owner-confirmed framing aligns: agents are tools; humans are responsible.\n```\n\n## Soft nos\n\nThese are judgment calls. Context determines appropriateness.\n\n```yaml\nsoft_no:\n  - item: >\n      Do not depict agents with broad, unscoped permissions. Default framing\n      should show each agent receiving only the permissions it needs for its\n      specific job, reviewed regularly.\n    tier: default\n    condition: >\n      Acceptable to describe expanded permissions only when context makes clear\n      those permissions were deliberately granted and reviewed by a human owner\n      for a specific, named purpose.\n    source: \"monday.com/blog/ai-agents/ai-agent-security-protection/\"\n    evidence_quote: >\n      \"Start with least privilege, not broad access: Give each agent only the\n      permissions it needs for its specific job, and review those permissions\n      regularly.\"\n\n  - item: >\n      Write tools (send, create, edit, delete) should not be depicted as active\n      by default in monday agents. Default state is inactive; a human must\n      explicitly review and activate each write tool before an agent may use it.\n    tier: default\n    condition: >\n      Acceptable to show write tools as active only after explicitly depicting\n      the human review and activation step.\n    source: \"support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com\"\n    evidence_quote: >\n      \"Write tools are added as inactive and the agent will prompt you to review\n      the setup. You can explicitly activate the tool when you're ready.\"\n\n  - item: >\n      Do not depict agents posting to any Slack channel or emailing any contact\n      without showing that those recipients and channels were explicitly\n      configured and restricted by a human operator.\n    tier: default\n    condition: >\n      Acceptable to show agent-initiated communications when the copy or visual\n      makes clear the agent is operating within administrator-defined guardrails\n      (specific channel allowlist, specific contact allowlist).\n    source: \"support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com\"\n    evidence_quote: >\n      \"you can restrict the agent to only post in a specific Slack channel, or\n      only email certain contacts\"\n\n  - item: >\n      Do not depict full agent autonomy as the starting point. The staged-autonomy\n      model — agent states intended action, human approves, greater independence\n      follows — should be the default narrative arc when showing agent capability.\n    tier: default\n    condition: >\n      Acceptable to show a more autonomous agent workflow only when context\n      makes clear that prior human approval and trust-building steps have\n      already been completed.\n    source: \"theaiinnovator.com/monday-com-rebuilds-its-platform-for-ai-agents-not-just-humans/\"\n    evidence_quote: >\n      \"The way we solve it is by first having agents tell you what they're going\n      to do, and then you approve,\"\n    authority_note: Independent publisher reporting co-CEO statements.\n```\n\n## Brand safety\n\nFor vendor platforms, brand-safety tools, and DSPs.\n\n```yaml\nbrand_safety:\n  adjacency_unsuitable:\n    - \"Content depicting AI systems operating without human oversight or accountability (GARM Floor)\"\n    - \"Content implying AI agents are autonomous legal actors independent of human responsibility\"\n    - \"Misinformation or disinformation content\"\n    - \"Content that promotes unauthorized data access or privacy violations\"\n    - \"Hate speech, harassment, or targeted abuse (GARM Floor)\"\n    - \"Violence or graphic content (GARM Floor)\"\n  adjacency_acceptable:\n    - \"Enterprise technology and SaaS\"\n    - \"Project management and productivity\"\n    - \"Business operations and workflow automation\"\n    - \"AI and machine learning — responsible-use framing\"\n    - \"HR, PMO, media operations, and professional services\"\n    - \"Business news and analysis\"\n  adjacency_contextual:\n    ai_autonomy_content:\n      rule: >\n        Adjacent content about AI autonomy is acceptable only when it discusses\n        human oversight, staged trust models, or responsible deployment.\n        Unsuitable when it celebrates ungoverned autonomy or treats human\n        oversight as an obstacle.\n    security_content:\n      rule: >\n        Adjacent content about cybersecurity is acceptable when focused on\n        enterprise protection. Unsuitable when sensationalizing breaches or\n        promoting offensive tooling.\n```\n\n## Regulatory constraints\n\n```yaml\nregulatory:\n  framework: \"SOC 2 Type II, ISO 27001, GDPR, HIPAA (monday.com holds relevant certifications; verify current scope at monday.com/l/security)\"\n  notes: >\n    monday.com is a publicly traded company (Nasdaq: MNDY). Any agent generating\n    content that references financial performance, revenue figures, customer counts,\n    or forward-looking guidance must use only claims recorded in claims.md with\n    proof_status: approved and must not introduce, extrapolate, or paraphrase\n    financial metrics beyond the approved_language for each claim.\n    Revenue and guidance figures are time-sensitive; always use the as-of date\n    bound to the specific claim entry in claims.md.\n  restricted_claims: >\n    Financial performance figures, customer counts, growth rates, and forward-\n    looking revenue guidance require Legal or Finance owner confirmation before\n    use in advertising, regulated communications, or comparative contexts.\n    Do not generate comparative financial claims against named competitors.\n```\n\n## Agent configuration guidance\n\nThe following rules apply to agents configured to act on behalf of monday.com or within monday.com's platform. They are operational extensions of the hard nos and soft nos above.\n\n```yaml\nagent_config:\n  named_owner_required:\n    rule: >\n      Every agent deployed on the monday.com platform must have a named human\n      owner accountable for its behavior and configuration. Do not deploy or\n      describe agents without a designated responsible human.\n    tier: core\n    source: \"monday.com/blog/ai-agents/ai-agent-security-protection/\"\n    evidence_quote: \"a named human owner who is accountable for its behavior and configuration\"\n\n  permission_review_cadence:\n    rule: >\n      Agent permissions must be reviewed regularly, not set once and forgotten.\n      Content and documentation should reflect ongoing human oversight as the\n      default, not a one-time setup.\n    tier: default\n    source: \"monday.com/blog/ai-agents/ai-agent-security-protection/\"\n\n  external_comms_guardrails:\n    rule: >\n      Agents initiating external communications (email, Slack, other channels)\n      must operate within administrator-configured recipient and channel\n      restrictions. No agent may send to unrestricted recipients by default.\n    tier: core\n    trigger: any agent workflow involving outbound email or messaging\n    escalation: require human operator to define and activate the allowed recipient or channel list before the agent may send\n    source: \"support.monday.com/hc/en-us/articles/33347027353746-AI-Agents-on-monday-com\"\n```\n",
      "signature": "gUmgWN3uB+pN2AzZPl7pCYr7mTGcDlT8qd66CvveQOmZkJPBSH/0UtLLmHOg0nz2w44973h0HHDyXWbYLFPGCQ==",
      "sha256": "d178d9a2b6800c7429969dd7a16ea46837a059194f23992afc64afdd449d8ee9",
      "kid": "v1",
      "content_type": "text/markdown; charset=utf-8",
      "html_url": "https://registry.encodedbrands.ai/brands/monday-com-4ca31c9f/files/boundaries",
      "json_url": "https://registry.encodedbrands.ai/brands/monday-com-4ca31c9f/files/boundaries/data.json",
      "source_url": "https://registry.encodedbrands.ai/brands/monday-com-4ca31c9f/source/boundaries.md",
      "canonical_source_url": "https://registry.brandcontextprotocol.dev/monday-com-4ca31c9f/.well-known/brand/boundaries.md"
    }
  ]
}
