# GOOGLESUPER_ACL_PATCH

Updates an access control rule for a calendar using patch semantics (partial update). This allows modifying specific fields without affecting other properties. Note: Each patch request consumes three quota units. For domain-type ACL rules, if PATCH fails with 500 error, this action will automatically fallback to UPDATE method.

Agent View of the PolicyLayer registry record for `GOOGLESUPER_ACL_PATCH`. HTML page: https://policylayer.com/tools/googlesuper/googlesuper-acl-patch

## Facts

- Tool: `GOOGLESUPER_ACL_PATCH`
- Server: Google Super (`googlesuper`) — https://policylayer.com/tools/googlesuper.md
- Install: `npx -y googlesuper`
- Homepage: https://www.npmjs.com/package/googlesuper
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server rate-limited: no
- Parameters: 5
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `role` | string | no | The role assigned to the scope. Possible values are: "none" - Provides no access; "freeBusyReader" - Provides read access to free/busy information; "reader" - P |
| `scope` | object | no | The extent to which calendar access is granted by this ACL rule. Optional for patch operations. |
| `rule_id` | string | no | ACL rule identifier. This is typically in the format 'type:value', such as 'user:email@example.com' or 'group:group@example.com'. |
| `calendar_id` | string | no | Calendar identifier. To retrieve calendar IDs call the calendarList.list method. If you want to access the primary calendar of the currently logged in user, use |
| `send_notifications` | boolean | no | Whether to send notifications about the calendar sharing change. Note that there are no notifications on access removal. Optional. The default is True. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "GOOGLESUPER_ACL_PATCH",
    "arguments": {}
  }
}
```

## Why GOOGLESUPER_ACL_PATCH is rated Medium

This tool modifies calendar access permissions through PATCH semantics, which is a reversible write operation. It does not delete data (Destructive), execute arbitrary code (Execute), or move money (Financial).

From the tool's own definition: "Tool description states 'Updates an access control rule for a calendar' and explicitly mentions 'partial update' and 'modifying specific fields'. The ACL (Access Control List) patch operation modifies permissions and sharing settings."

## Use case

AI agents use GOOGLESUPER_ACL_PATCH to create or update resources in Google Super, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Google Super environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Google Super:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "GOOGLESUPER_ACL_PATCH": {
      "limits": [
        {
          "counter": "googlesuper_acl_patch_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Google Super (199)

- `GOOGLESUPER_BATCH_DELETE_MESSAGES` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-batch-delete-messages.md
- `GOOGLESUPER_CALENDARS_DELETE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-calendars-delete.md
- `GOOGLESUPER_CLEAR_BASIC_FILTER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-basic-filter.md
- `GOOGLESUPER_CLEAR_CALENDAR` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-calendar.md
- `GOOGLESUPER_CLEAR_TASKS` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-tasks.md
- `GOOGLESUPER_CLEAR_VALUES` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-clear-values.md
- `GOOGLESUPER_DELETE_COMMENT` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-comment.md
- `GOOGLESUPER_DELETE_CONTENT_RANGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-content-range.md
- `GOOGLESUPER_DELETE_DIMENSION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-dimension.md
- `GOOGLESUPER_DELETE_DRAFT` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-draft.md
- `GOOGLESUPER_DELETE_DRIVE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-drive.md
- `GOOGLESUPER_DELETE_EVENT` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-event.md
- `GOOGLESUPER_DELETE_FOOTER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-footer.md
- `GOOGLESUPER_DELETE_HEADER` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-header.md
- `GOOGLESUPER_DELETE_MESSAGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-message.md
- `GOOGLESUPER_DELETE_NAMED_RANGE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-named-range.md
- `GOOGLESUPER_DELETE_PERMISSION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-permission.md
- `GOOGLESUPER_DELETE_REPLY` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-reply.md
- `GOOGLESUPER_DELETE_SHEET` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-sheet.md
- `GOOGLESUPER_DELETE_TABLE` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table.md
- `GOOGLESUPER_DELETE_TABLE_COLUMN` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table-column.md
- `GOOGLESUPER_DELETE_TABLE_ROW` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-table-row.md
- `GOOGLESUPER_DELETE_TASK` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-task.md
- `GOOGLESUPER_DELETE_TASK_LIST` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-delete-task-list.md
- `GOOGLESUPER_EMPTY_TRASH` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-empty-trash.md
- `GOOGLESUPER_GOOGLE_DRIVE_DELETE_FOLDER_OR_FILE_ACTION` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-google-drive-delete-folder-or-file-action.md
- `GOOGLESUPER_MOVE_TO_TRASH` — Destructive — https://policylayer.com/tools/googlesuper/googlesuper-move-to-trash.md
- `GOOGLESUPER_EVENTS_WATCH` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-events-watch.md
- `GOOGLESUPER_EXECUTE_SQL` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-execute-sql.md
- `GOOGLESUPER_QUERY_TABLE` — Execute — https://policylayer.com/tools/googlesuper/googlesuper-query-table.md
- …and 169 more: https://policylayer.com/tools/googlesuper.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=googlesuper · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/googlesuper
