Information should stay out of an add-on's connected scope when it is not needed for the task, when it is sensitive, or when the connection reaches a wider audience than intended. The relevant boundary is the data and audience actually exposed—not merely the permissions displayed. One cited guidance point says app permissions do not themselves grant an app new access; another warns that incorrect access settings, including access for “Everyone,” can lead to oversharing sensitive content.
What to keep out
A practical exclusion rule is to leave out:
- Sensitive information that the task does not require.
- Material intended for a restricted audience.
- Unrelated files, messages, and records.
- Information whose purpose in the connected workflow cannot be clearly identified.
This is not a universal classification of data. It is a way to test whether the proposed connection is narrower than the task and its intended audience require.
How to check the connection
- Identify the task. List the specific information needed to complete it. Treat everything else as outside the initial scope.
- Inspect the actual connection. Check which resources are connected instead of relying only on the permissions list. A permission statement does not itself create new access.
- Review access settings. Treat access for “Everyone” as a setting to investigate, not a default. The cited guidance identifies overly broad access as a route to oversharing sensitive content.
- Check the existing sharing context. Confirm that a connected file, conversation, or folder is not already visible to a wider audience.
- Recheck after changes. Review the connected resources and access settings again whenever the connection is changed.
What still needs confirmation
The cited statements do not establish which files, conversations, or records a particular add-on can access. They also do not specify retention, deletion, or downstream-sharing rules. Those details must be confirmed through the tool’s current documentation and the actual connection settings rather than inferred from the permissions display.
In particular, the reader should confirm:
- The exact resources connected to the add-on.
- The effective audience and access level for each resource.
- The actions the add-on can take with the connected information.
- Any retention, deletion, or sharing terms that apply.
- What happens to access after the connection is removed.
If those details are not documented, the connection is not yet sufficiently defined for sensitive content.