Critical-risk tools in Attio
6 of the 57 tools in Attio are classified as critical risk. This page profiles those tools specifically, with recommended policy actions and the attack patterns that target them.
Every operation listed below is an action PolicyLayer recommends controlling at the transport layer. Open any tool to see the full profile, risk score, and YAML policy snippet.
Tools at critical risk
-
deletev2notesbynoteidDestructiveDelete a single note by ID. Required scopes: \
-
deletev2tasksbytaskidDestructiveDelete a task by ID. Required scopes: \
-
deletev2webhooksbywebhookidDestructiveDelete a webhook by ID. Required scopes: \
-
deletev2commentsbycommentidDestructiveDeletes a comment by ID. If deleting a comment at the head of a thread, all messages in the thread are also deleted. Required scopes: \
-
deletev2listsentriesbyentryidDestructiveDeletes a single list entry by its \
-
deletev2objectsrecordsbyrecordidDestructiveDeletes a single record (e.g. a company or person) by ID. Required scopes: \
Attacks that target this class
Critical-risk tools in any server share these documented attack patterns. Each links to the full case and the defensive policy.