Skip to Content
ConceptsADM Register scope mapping

ADM Register scope mapping

Mapping version 2026-10-01.1. “None” means the scope was reviewed and reaches no personal information about the people affected. A scope not listed here shows in the register as “Unclassified, needs review”. MCP server tools are always unclassified, because a tool’s name is not evidence of what it reaches. The sign-in scopes openid, profile, email and offline_access identify only the person who connected the account and are treated as None on every platform.

Airtable (airtable)

ScopePersonal information it can reach
data.records:readBusiness database records
data.records:writeBusiness database records
schema.bases:deleteNone
schema.bases:readNone
schema.bases:writeNone

Microsoft Azure (azure)

Infrastructure management only.

ScopePersonal information it can reach
azure:resources.readNone
azure:subscriptions.readNone
azure:vm.deleteNone
azure:vm.powerNone
azure:vm.readNone
azure:vm.writeNone

Azure DevOps (azure-devops)

ScopePersonal information it can reach
azure-devops:build.executeNone
azure-devops:build.readNone
azure-devops:code.readNone
azure-devops:code.writeNone
azure-devops:pipelines.readNone
azure-devops:pipelines.runNone
azure-devops:workitems.deleteWorkplace records that name people
azure-devops:workitems.readWorkplace records that name people
azure-devops:workitems.writeWorkplace records that name people

Buffer (buffer)

ScopePersonal information it can reach
posts:deleteSocial media posts and profiles
posts:readSocial media posts and profiles
posts:writeSocial media posts and profiles

Clerk (clerk)

User and session records of the people who sign in to your product.

ScopePersonal information it can reach
organizations:readContact details
organizations:writeContact details
sessions:readOnline identifiers and account information, Location information
users:readContact details, Online identifiers and account information
users:writeContact details, Online identifiers and account information

Cloudflare (cloudflare)

Infrastructure management, except object storage (R2), which can hold any file.

ScopePersonal information it can reach
cloudflare:cache.purgeNone
cloudflare:dns.readNone
cloudflare:dns.writeNone
cloudflare:pages.readNone
cloudflare:pages.writeNone
cloudflare:r2.readFiles and documents
cloudflare:r2.writeFiles and documents
cloudflare:workers.readNone
cloudflare:workers.writeNone
cloudflare:zones.readNone

Confluence (confluence)

ScopePersonal information it can reach
read:confluence-content.allWorkplace records that name people
read:confluence-space.summaryNone
read:confluence-userContact details
write:confluence-contentWorkplace records that name people

Fireflies (fireflies)

Meeting transcripts and recordings, and the people who attended.

ScopePersonal information it can reach
deleteCall and meeting recordings or transcripts
readCall and meeting recordings or transcripts, Email and message content, Contact details, Calendar and scheduling information
writeCall and meeting recordings or transcripts

GitHub (github)

Source code is treated as not personal information. Issues and pull requests name the people involved.

ScopePersonal information it can reach
delete_repoNone
github:actions.readNone
github:actions.runNone
github:contents.readNone
github:contents.writeNone
github:issues.readWorkplace records that name people
github:issues.writeWorkplace records that name people
github:pulls.readWorkplace records that name people
github:pulls.writeWorkplace records that name people
github:repo.createNone
github:repo.readNone
github:user.readContact details, Online identifiers and account information
read:userContact details, Online identifiers and account information
repoWorkplace records that name people
user:emailContact details
workflowNone

Gmail (gmail)

Mailbox access reaches email content and the contact details of everyone in it.

ScopePersonal information it can reach
gmail.labelsNone
https://www.googleapis.com/auth/gmail.labelsNone
https://www.googleapis.com/auth/gmail.settings.basicNone
https://www.googleapis.com/auth/gmail.settings.sharingContact details
labels.readNone
labels.writeNone
messages.deleteEmail and message content, Contact details
messages.modifyEmail and message content, Contact details
messages.readEmail and message content, Contact details
messages.sendEmail and message content, Contact details
Any scope matching `gmail.(readonlymodify

Google Calendar (google-calendar)

ScopePersonal information it can reach
Any scope matching calendar(\.events)?(\.readonly)?$Calendar and scheduling information, Contact details

Google Docs (google-docs)

ScopePersonal information it can reach
https://www.googleapis.com/auth/documentsFiles and documents

Google Drive (google-drive)

drive.file is limited to files the app created or was given, but those files can still hold personal information.

ScopePersonal information it can reach
https://www.googleapis.com/auth/driveFiles and documents
https://www.googleapis.com/auth/drive.fileFiles and documents

Google Sheets (google-sheets)

ScopePersonal information it can reach
https://www.googleapis.com/auth/spreadsheetsBusiness database records

HubSpot (hubspot)

CRM objects are customer records about people. Schema scopes describe fields only.

ScopePersonal information it can reach
companies:readCustomer and sales records
companies:writeCustomer and sales records
contacts:readContact details, Customer and sales records
contacts:writeContact details, Customer and sales records
crm.objects.companies.readCustomer and sales records
crm.objects.companies.writeCustomer and sales records
crm.objects.contacts.readContact details, Customer and sales records
crm.objects.contacts.writeContact details, Customer and sales records
crm.objects.deals.readCustomer and sales records, Financial and transaction information
crm.objects.deals.writeCustomer and sales records, Financial and transaction information
crm.schemas.companies.readNone
crm.schemas.contacts.readNone
crm.schemas.deals.readNone
deals:readCustomer and sales records, Financial and transaction information
deals:writeCustomer and sales records, Financial and transaction information
emails:readEmail and message content, Contact details
emails:writeEmail and message content, Contact details
oauthNone
tickets:readCustomer and sales records, Email and message content
tickets:writeCustomer and sales records, Email and message content

Jira (jira)

ScopePersonal information it can reach
read:jira-userContact details
read:jira-workWorkplace records that name people
write:jira-workWorkplace records that name people

Linear (linear)

ScopePersonal information it can reach
adminWorkplace records that name people, Contact details
comments:createWorkplace records that name people
issues:createWorkplace records that name people
readWorkplace records that name people
writeWorkplace records that name people

Metabase (metabase)

Running queries and reading saved questions reaches whatever the connected databases hold.

ScopePersonal information it can reach
metabase:admin.permissionsNone
metabase:admin.settingsNone
metabase:card.readBusiness database records
metabase:card.writeNone
metabase:collection.readNone
metabase:collection.writeNone
metabase:dashboard.readBusiness database records
metabase:dashboard.writeNone
metabase:database.readNone
metabase:query.runBusiness database records
metabase:user.readContact details, Online identifiers and account information
Any scope matching `^(custom.api.query.run.)`

Microsoft Outlook (microsoft-outlook)

Mail, calendar and contacts access reaches message content and the people in it. User.Read covers only the signed-in account.

ScopePersonal information it can reach
Calendars.ReadCalendar and scheduling information, Contact details
Calendars.ReadWriteCalendar and scheduling information, Contact details
Contacts.ReadContact details
Contacts.ReadWriteContact details
Files.ReadFiles and documents
Files.ReadWriteFiles and documents
Mail.ReadEmail and message content, Contact details
Mail.ReadWriteEmail and message content, Contact details
Mail.SendEmail and message content, Contact details
Tasks.ReadWorkplace records that name people
Tasks.ReadWriteWorkplace records that name people
User.ReadNone
User.ReadBasic.AllContact details

Microsoft Teams (microsoft-teams)

ScopePersonal information it can reach
ChannelMessage.Read.AllEmail and message content, Contact details
Chat.ReadEmail and message content, Contact details
Chat.ReadWriteEmail and message content, Contact details
Mail.ReadEmail and message content, Contact details
Mail.ReadWriteEmail and message content, Contact details
Mail.SendEmail and message content, Contact details
channels:readContact details
channels:writeContact details
chat:readEmail and message content, Contact details
chat:writeEmail and message content, Contact details
messages:readEmail and message content, Contact details
messages:writeEmail and message content, Contact details
teams:readContact details
teams:writeContact details

Microsoft (tenant) (microsoft-tenant-specific)

Agent registry access only. User.Read covers only the signed-in account.

ScopePersonal information it can reach
AgentCard.ReadWrite.AllNone
AgentRegistration.Read.AllNone
AgentRegistration.ReadWrite.AllNone
User.ReadNone

Notion (notion)

ScopePersonal information it can reach
deleteWorkplace records that name people, Files and documents
readWorkplace records that name people, Files and documents
writeWorkplace records that name people, Files and documents

Slack (slack)

History scopes reach message content. Channel listing and reactions do not.

ScopePersonal information it can reach
channels:historyEmail and message content, Contact details
channels:joinNone
channels:manageNone
channels:readNone
channels:writeNone
chat:writeEmail and message content
chat:write.publicEmail and message content
files:readFiles and documents
files:writeFiles and documents
groups:historyEmail and message content, Contact details
groups:readNone
im:historyEmail and message content, Contact details
im:readNone
im:writeEmail and message content
incoming-webhookEmail and message content
messages:writeEmail and message content
mpim:historyEmail and message content, Contact details
mpim:readNone
pins:writeNone
reactions:readNone
reactions:writeNone
users:readContact details, Online identifiers and account information
users:read.emailContact details

Stripe (stripe)

Customer, charge, invoice and subscription access reaches people’s payment and contact details. Product, price and coupon access does not.

ScopePersonal information it can reach
stripe:balance.readNone
stripe:charges.readFinancial and transaction information, Payment card details, Contact details
stripe:checkout.readFinancial and transaction information, Contact details
stripe:checkout.writeFinancial and transaction information, Contact details
stripe:coupons.deleteNone
stripe:coupons.readNone
stripe:coupons.writeNone
stripe:customers.deleteContact details, Customer and sales records, Financial and transaction information
stripe:customers.readContact details, Customer and sales records, Financial and transaction information
stripe:customers.writeContact details, Customer and sales records, Financial and transaction information
stripe:events.readFinancial and transaction information, Customer and sales records, Contact details
stripe:invoices.deleteFinancial and transaction information, Customer and sales records
stripe:invoices.readFinancial and transaction information, Customer and sales records, Contact details
stripe:invoices.writeFinancial and transaction information, Customer and sales records, Contact details
stripe:payment_intents.readFinancial and transaction information, Payment card details
stripe:payment_intents.writeFinancial and transaction information, Payment card details
stripe:prices.readNone
stripe:prices.writeNone
stripe:products.deleteNone
stripe:products.readNone
stripe:products.writeNone
stripe:refunds.readFinancial and transaction information
stripe:refunds.writeFinancial and transaction information
stripe:subscriptions.cancelFinancial and transaction information, Customer and sales records
stripe:subscriptions.readFinancial and transaction information, Customer and sales records
stripe:subscriptions.writeFinancial and transaction information, Customer and sales records
stripe:webhooks.readNone
stripe:webhooks.writeNone

Stripe (stripe-live)

Customer, charge, invoice and subscription access reaches people’s payment and contact details. Product, price and coupon access does not.

ScopePersonal information it can reach
stripe:balance.readNone
stripe:charges.readFinancial and transaction information, Payment card details, Contact details
stripe:checkout.readFinancial and transaction information, Contact details
stripe:checkout.writeFinancial and transaction information, Contact details
stripe:coupons.deleteNone
stripe:coupons.readNone
stripe:coupons.writeNone
stripe:customers.deleteContact details, Customer and sales records, Financial and transaction information
stripe:customers.readContact details, Customer and sales records, Financial and transaction information
stripe:customers.writeContact details, Customer and sales records, Financial and transaction information
stripe:events.readFinancial and transaction information, Customer and sales records, Contact details
stripe:invoices.deleteFinancial and transaction information, Customer and sales records
stripe:invoices.readFinancial and transaction information, Customer and sales records, Contact details
stripe:invoices.writeFinancial and transaction information, Customer and sales records, Contact details
stripe:payment_intents.readFinancial and transaction information, Payment card details
stripe:payment_intents.writeFinancial and transaction information, Payment card details
stripe:prices.readNone
stripe:prices.writeNone
stripe:products.deleteNone
stripe:products.readNone
stripe:products.writeNone
stripe:refunds.readFinancial and transaction information
stripe:refunds.writeFinancial and transaction information
stripe:subscriptions.cancelFinancial and transaction information, Customer and sales records
stripe:subscriptions.readFinancial and transaction information, Customer and sales records
stripe:subscriptions.writeFinancial and transaction information, Customer and sales records
stripe:webhooks.readNone
stripe:webhooks.writeNone

Supabase (supabase)

A general database connection reaches whatever the database holds.

ScopePersonal information it can reach
auth:readContact details, Online identifiers and account information
database:readBusiness database records
database:writeBusiness database records
edge-functions:invokeNone
edge_functions:readNone
organizations:readNone
projects:readNone
secrets:readNone
secrets:writeNone
storage:readFiles and documents
storage:writeFiles and documents

Xero (xero)

Contacts, invoices and transactions identify customers and suppliers. Payroll scopes reach employee and tax information.

ScopePersonal information it can reach
accounting.budgets.readNone
accounting.contactsContact details, Customer and sales records, Financial and transaction information
accounting.contacts.readContact details, Customer and sales records, Financial and transaction information
accounting.invoicesFinancial and transaction information, Customer and sales records
accounting.invoices.readFinancial and transaction information, Customer and sales records
accounting.paymentsFinancial and transaction information
accounting.payments.readFinancial and transaction information
accounting.reports.readFinancial and transaction information, Customer and sales records
accounting.settingsNone
accounting.settings.readNone
accounting.transactionsFinancial and transaction information, Customer and sales records
accounting.transactions.readFinancial and transaction information, Customer and sales records
assets.readNone
files.readFiles and documents
Any scope matching ^payroll\.Employment and HR information, Financial and transaction information, Government identifiers, Contact details
Last updated on