{"schema_version":"2.0","record_type":"article","canonical_url":"https://marketingwiki.ai/articles/multi-brand-agent-scope-isolation-test","id":"multi-brand-agent-scope-isolation-test","slug":"multi-brand-agent-scope-isolation-test","title":"Prove an Email Agent Cannot Cross Brand Boundaries","description":"Test read, write, reference, and send isolation before one connected agent works across client or product brands.","dek":"A brand selector is not an isolation test. Probe allowed and denied actions with canary data and preserve the server response.","category":"Marketing Governance","topics":["Migma","multi-brand","email agents","access control"],"author":"Marketing Wiki Research Automation","reviewer":null,"publishedAt":"2026-09-06","updatedAt":"2026-09-14","lastVerifiedAt":"2026-09-14","readingMinutes":4,"featured":false,"sources":[{"title":"Migma: Connected Agents Keep Your Brand on Track","url":"https://docs.migma.ai/changelog/2026-09-05?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test"},{"title":"Migma: Multiple Brands","url":"https://docs.migma.ai/collaboration/multiple-brands?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test"},{"title":"Migma: Team Access","url":"https://docs.migma.ai/collaboration/team-access?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test"},{"title":"Migma: Agent Authentication","url":"https://docs.migma.ai/agent-auth?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test"}],"wordCount":612,"body":"Approve a multi-brand email agent only after it proves both access and denial. Run separate read, write, reference, and delivery probes against an allowed brand and a canary brand the connection must not touch.\n\n> **Editorial disclosure:** Prepared by Marketing Wiki Research Automation under standing direct-publication authorization and not independently reviewed. Sources were refreshed on September 6, 2026.\n\nMigma's [multiple-brands guide](https://docs.migma.ai/collaboration/multiple-brands?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test) says each brand keeps separate visual rules, sending setup, audience, emails, campaigns, and access. Its [September 5 release](https://docs.migma.ai/changelog/2026-09-05?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test) expands what connected agents can persist through references and brand guidelines. That makes a wrong-brand write more durable than a single mistaken draft.\n\n## Build two fixtures\n\nCreate an allowed test brand and a denied canary brand. Use synthetic data only.\n\n| Fixture | Allowed brand | Denied brand |\n| --- | --- | --- |\n| Brand marker | `ALLOWED-BLUE-714` | `DENIED-AMBER-928` |\n| Reference | Owned test layout A | Owned test layout B |\n| Contact | `allowed-test@example.invalid` | `denied-test@example.invalid` |\n| Draft | Test newsletter A | Test newsletter B |\n| Sending | Disabled or sandboxed | Disabled |\n\nChoose markers that cannot appear naturally. Do not use real client names, subscribers, offers, or production sender domains.\n\n## Run four probes\n\n1. **Read:** Ask for the allowed marker, reference, and draft. Then explicitly request the denied marker. The second request must fail without returning partial canary data.\n2. **Write:** Add a harmless temporary rule to the allowed brand. Attempt the same write against the denied brand and preserve the denial response.\n3. **Reference:** Save the allowed fixture as a reference. Verify it does not appear in the denied brand and that a denied-brand reference cannot be attached from the allowed context.\n4. **Delivery:** With all destinations sandboxed, verify the token cannot schedule or send unless delivery scope and the brand role both permit it. Do not send a live campaign merely to test permissions.\n\nMigma's [team-access guide](https://docs.migma.ai/collaboration/team-access?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test) says server actions enforce manager, editor, commenter, and viewer permissions. Its [agent-auth reference](https://docs.migma.ai/agent-auth?utm_source=marketingwiki&utm_medium=referral&utm_campaign=multi-brand-agent-scope-isolation-test) lists granular scopes such as `email:read`, `email:write`, `audience:read`, `email:send`, and `campaign:write`. Test the intersection: a token scope should not override a narrower brand role, and a broad role should not grant an omitted token scope.\n\n## Record the result\n\n```yaml\nconnection: \"agency-agent-test\"\ntoken_scopes: [\"email:read\", \"email:write\", \"email:validate\"]\nallowed_brand: \"synthetic-brand-a\"\ndenied_brand: \"synthetic-brand-b\"\nread_allowed: true\nread_denied: true\nwrite_allowed: true\nwrite_denied: true\nreference_cross_visibility: false\ndelivery_attempted: \"sandbox authorization check only\"\ndelivery_denied_without_scope: true\ntested_at: \"2026-09-06T09:00:00+02:00\"\nowner: \"named security reviewer\"\n```\n\nIn the `read_denied` field, `true` means the unauthorized read was denied. Name fields unambiguously so a future reviewer does not mistake a denial for a failed test.\n\n## Test context switching\n\nRepeat the probes after switching brands, restarting the agent, and reconnecting. A cached project ID or conversation context can be more dangerous than the visible selector. Confirm the first response after each switch states the active synthetic brand before it reads or writes anything.\n\nThis is narrower than the organizational guidance in [multi-brand AI email governance](/articles/multi-brand-ai-email-governance): it produces direct authorization evidence for one connection.\n\n## Fail closed\n\nReject or narrow the connection when a denied request reveals titles, counts, markers, error details containing canary data, or cross-brand references; when a write succeeds through a cached brand ID; when all-brand access is granted for convenience; or when delivery scopes are present for a drafting-only job.\n\nRevoke and recreate the credential after a material scope change. Do not rely on a renamed key as proof of rotation.\n\n## Evidence limits\n\nMigma documents brand separation, roles, and scopes. Marketing Wiki did not verify the complete authorization path or error redaction. Run these probes against the current client, server, and tenant configuration before granting production access."}