AI Addaiadd.org

What permissions should an add-on need for the intended workflow?

An add-on should need only the permissions tied to information the workflow must read and actions it must take. Connected-app permission settings determine when approval is requested before reading information or taking an action. They do not grant the add-on new access, so approval settings and existing access must be checked separately.

How to check the fit

Start with the workflow rather than the permission screen:

  1. List the required reads. Identify the exact information the add-on needs to retrieve for the task.
  2. List the required actions. Identify what the add-on must create, change, send, or otherwise do.
  3. Match every permission to a workflow step. A permission with no corresponding read or action should not be treated as necessary simply because it is available.
  4. Check approval timing. Determine when the connected-app settings will request approval before information is read or an action is taken.
  5. Check existing access. Permission settings do not create access. The add-on’s current access must therefore be evaluated independently.

A read-only workflow, for example, needs a clear justification for any action permission. A workflow that changes information needs the permitted change and its approval point to be explicit.

What still requires confirmation

The cited guidance does not provide a universal permission list for broad tasks such as reading, summarising, creating, or updating. Those labels can involve different operations and access requirements.

The exact minimum therefore cannot be verified without the specific workflow and add-on. The remaining checks are:

  • which permissions are currently enabled;
  • which data those permissions cover;
  • which actions they allow;
  • when approval is requested; and
  • what access the add-on already has.

If those details are unavailable or unclear, the required permission level remains unverified rather than automatically sufficient.

Sources