Credential-isolating Microsoft 365 proxies for a two-VM OpenShell/OpenClaw deployment. The read and write trust boundaries are implemented as independent Rust crates.
OpenClaw VM Integration VM
m365 CLI / approval tool
│ opaque OpenShell placeholder
▼
agent forwarder ── inter-VM capability ─► integration forwarder
│
▼
Rust policy proxy
│ Graph placeholder
▼
OpenShell gateway
│ real OAuth token
▼
Microsoft Graph
| Directory | Purpose | Allowed Graph operations |
|---|---|---|
read-proxy |
Read-only Outlook and calendar access for the Microsoft 365 CLI | Governed GET, HEAD, and OPTIONS requests below /v1.0/me for the explicit mail/calendar allowlist |
write-proxy |
Explicitly approved Outlook draft creation and sending | POST /v1.0/me/messages and POST /v1.0/me/messages/{draft-id}/send only |
The write workflow requires separate, non-replayable approvals to create and send. Approval to create a draft never authorizes sending it. Direct /sendMail, attachments, updates, deletes, arbitrary Graph writes, and non-empty send bodies are denied.
Each component is independently buildable and contains its own Rust crate, tests, container definition, OpenShell policy/provider examples, two-VM forwarders, and deployment assets. The write component additionally owns the OpenClaw approval tool and skill.
Run validation independently in each directory:
cd read-proxy
cargo fmt --check
cargo test
cargo clippy --all-targets -- -D warnings
cd ../write-proxy
cargo fmt --check
cargo test
cargo clippy --all-targets -- -D warningsNo OAuth token, refresh token, client ID, tenant ID, or inter-VM capability belongs in this repository. Render the provider and OpenShift examples for the target environment at deployment time.