ADM Register scope mapping
Mapping version 2026-10-01.1. “None” means the scope was reviewed and reaches no personal information about the people affected. A scope not listed here shows in the register as “Unclassified, needs review”. MCP server tools are always unclassified, because a tool’s name is not evidence of what it reaches. The sign-in scopes openid, profile, email and offline_access identify only the person who connected the account and are treated as None on every platform.
Airtable (airtable)
| Scope | Personal information it can reach |
|---|---|
data.records:read | Business database records |
data.records:write | Business database records |
schema.bases:delete | None |
schema.bases:read | None |
schema.bases:write | None |
Microsoft Azure (azure)
Infrastructure management only.
| Scope | Personal information it can reach |
|---|---|
azure:resources.read | None |
azure:subscriptions.read | None |
azure:vm.delete | None |
azure:vm.power | None |
azure:vm.read | None |
azure:vm.write | None |
Azure DevOps (azure-devops)
| Scope | Personal information it can reach |
|---|---|
azure-devops:build.execute | None |
azure-devops:build.read | None |
azure-devops:code.read | None |
azure-devops:code.write | None |
azure-devops:pipelines.read | None |
azure-devops:pipelines.run | None |
azure-devops:workitems.delete | Workplace records that name people |
azure-devops:workitems.read | Workplace records that name people |
azure-devops:workitems.write | Workplace records that name people |
Buffer (buffer)
| Scope | Personal information it can reach |
|---|---|
posts:delete | Social media posts and profiles |
posts:read | Social media posts and profiles |
posts:write | Social media posts and profiles |
Clerk (clerk)
User and session records of the people who sign in to your product.
| Scope | Personal information it can reach |
|---|---|
organizations:read | Contact details |
organizations:write | Contact details |
sessions:read | Online identifiers and account information, Location information |
users:read | Contact details, Online identifiers and account information |
users:write | Contact details, Online identifiers and account information |
Cloudflare (cloudflare)
Infrastructure management, except object storage (R2), which can hold any file.
| Scope | Personal information it can reach |
|---|---|
cloudflare:cache.purge | None |
cloudflare:dns.read | None |
cloudflare:dns.write | None |
cloudflare:pages.read | None |
cloudflare:pages.write | None |
cloudflare:r2.read | Files and documents |
cloudflare:r2.write | Files and documents |
cloudflare:workers.read | None |
cloudflare:workers.write | None |
cloudflare:zones.read | None |
Confluence (confluence)
| Scope | Personal information it can reach |
|---|---|
read:confluence-content.all | Workplace records that name people |
read:confluence-space.summary | None |
read:confluence-user | Contact details |
write:confluence-content | Workplace records that name people |
Fireflies (fireflies)
Meeting transcripts and recordings, and the people who attended.
| Scope | Personal information it can reach |
|---|---|
delete | Call and meeting recordings or transcripts |
read | Call and meeting recordings or transcripts, Email and message content, Contact details, Calendar and scheduling information |
write | Call and meeting recordings or transcripts |
GitHub (github)
Source code is treated as not personal information. Issues and pull requests name the people involved.
| Scope | Personal information it can reach |
|---|---|
delete_repo | None |
github:actions.read | None |
github:actions.run | None |
github:contents.read | None |
github:contents.write | None |
github:issues.read | Workplace records that name people |
github:issues.write | Workplace records that name people |
github:pulls.read | Workplace records that name people |
github:pulls.write | Workplace records that name people |
github:repo.create | None |
github:repo.read | None |
github:user.read | Contact details, Online identifiers and account information |
read:user | Contact details, Online identifiers and account information |
repo | Workplace records that name people |
user:email | Contact details |
workflow | None |
Gmail (gmail)
Mailbox access reaches email content and the contact details of everyone in it.
| Scope | Personal information it can reach |
|---|---|
gmail.labels | None |
https://www.googleapis.com/auth/gmail.labels | None |
https://www.googleapis.com/auth/gmail.settings.basic | None |
https://www.googleapis.com/auth/gmail.settings.sharing | Contact details |
labels.read | None |
labels.write | None |
messages.delete | Email and message content, Contact details |
messages.modify | Email and message content, Contact details |
messages.read | Email and message content, Contact details |
messages.send | Email and message content, Contact details |
| Any scope matching `gmail.(readonly | modify |
Google Calendar (google-calendar)
| Scope | Personal information it can reach |
|---|---|
Any scope matching calendar(\.events)?(\.readonly)?$ | Calendar and scheduling information, Contact details |
Google Docs (google-docs)
| Scope | Personal information it can reach |
|---|---|
https://www.googleapis.com/auth/documents | Files and documents |
Google Drive (google-drive)
drive.file is limited to files the app created or was given, but those files can still hold personal information.
| Scope | Personal information it can reach |
|---|---|
https://www.googleapis.com/auth/drive | Files and documents |
https://www.googleapis.com/auth/drive.file | Files and documents |
Google Sheets (google-sheets)
| Scope | Personal information it can reach |
|---|---|
https://www.googleapis.com/auth/spreadsheets | Business database records |
HubSpot (hubspot)
CRM objects are customer records about people. Schema scopes describe fields only.
| Scope | Personal information it can reach |
|---|---|
companies:read | Customer and sales records |
companies:write | Customer and sales records |
contacts:read | Contact details, Customer and sales records |
contacts:write | Contact details, Customer and sales records |
crm.objects.companies.read | Customer and sales records |
crm.objects.companies.write | Customer and sales records |
crm.objects.contacts.read | Contact details, Customer and sales records |
crm.objects.contacts.write | Contact details, Customer and sales records |
crm.objects.deals.read | Customer and sales records, Financial and transaction information |
crm.objects.deals.write | Customer and sales records, Financial and transaction information |
crm.schemas.companies.read | None |
crm.schemas.contacts.read | None |
crm.schemas.deals.read | None |
deals:read | Customer and sales records, Financial and transaction information |
deals:write | Customer and sales records, Financial and transaction information |
emails:read | Email and message content, Contact details |
emails:write | Email and message content, Contact details |
oauth | None |
tickets:read | Customer and sales records, Email and message content |
tickets:write | Customer and sales records, Email and message content |
Jira (jira)
| Scope | Personal information it can reach |
|---|---|
read:jira-user | Contact details |
read:jira-work | Workplace records that name people |
write:jira-work | Workplace records that name people |
Linear (linear)
| Scope | Personal information it can reach |
|---|---|
admin | Workplace records that name people, Contact details |
comments:create | Workplace records that name people |
issues:create | Workplace records that name people |
read | Workplace records that name people |
write | Workplace records that name people |
Metabase (metabase)
Running queries and reading saved questions reaches whatever the connected databases hold.
| Scope | Personal information it can reach |
|---|---|
metabase:admin.permissions | None |
metabase:admin.settings | None |
metabase:card.read | Business database records |
metabase:card.write | None |
metabase:collection.read | None |
metabase:collection.write | None |
metabase:dashboard.read | Business database records |
metabase:dashboard.write | None |
metabase:database.read | None |
metabase:query.run | Business database records |
metabase:user.read | Contact details, Online identifiers and account information |
| Any scope matching `^(custom.api. | query.run.)` |
Microsoft Outlook (microsoft-outlook)
Mail, calendar and contacts access reaches message content and the people in it. User.Read covers only the signed-in account.
| Scope | Personal information it can reach |
|---|---|
Calendars.Read | Calendar and scheduling information, Contact details |
Calendars.ReadWrite | Calendar and scheduling information, Contact details |
Contacts.Read | Contact details |
Contacts.ReadWrite | Contact details |
Files.Read | Files and documents |
Files.ReadWrite | Files and documents |
Mail.Read | Email and message content, Contact details |
Mail.ReadWrite | Email and message content, Contact details |
Mail.Send | Email and message content, Contact details |
Tasks.Read | Workplace records that name people |
Tasks.ReadWrite | Workplace records that name people |
User.Read | None |
User.ReadBasic.All | Contact details |
Microsoft Teams (microsoft-teams)
| Scope | Personal information it can reach |
|---|---|
ChannelMessage.Read.All | Email and message content, Contact details |
Chat.Read | Email and message content, Contact details |
Chat.ReadWrite | Email and message content, Contact details |
Mail.Read | Email and message content, Contact details |
Mail.ReadWrite | Email and message content, Contact details |
Mail.Send | Email and message content, Contact details |
channels:read | Contact details |
channels:write | Contact details |
chat:read | Email and message content, Contact details |
chat:write | Email and message content, Contact details |
messages:read | Email and message content, Contact details |
messages:write | Email and message content, Contact details |
teams:read | Contact details |
teams:write | Contact details |
Microsoft (tenant) (microsoft-tenant-specific)
Agent registry access only. User.Read covers only the signed-in account.
| Scope | Personal information it can reach |
|---|---|
AgentCard.ReadWrite.All | None |
AgentRegistration.Read.All | None |
AgentRegistration.ReadWrite.All | None |
User.Read | None |
Notion (notion)
| Scope | Personal information it can reach |
|---|---|
delete | Workplace records that name people, Files and documents |
read | Workplace records that name people, Files and documents |
write | Workplace records that name people, Files and documents |
Slack (slack)
History scopes reach message content. Channel listing and reactions do not.
| Scope | Personal information it can reach |
|---|---|
channels:history | Email and message content, Contact details |
channels:join | None |
channels:manage | None |
channels:read | None |
channels:write | None |
chat:write | Email and message content |
chat:write.public | Email and message content |
files:read | Files and documents |
files:write | Files and documents |
groups:history | Email and message content, Contact details |
groups:read | None |
im:history | Email and message content, Contact details |
im:read | None |
im:write | Email and message content |
incoming-webhook | Email and message content |
messages:write | Email and message content |
mpim:history | Email and message content, Contact details |
mpim:read | None |
pins:write | None |
reactions:read | None |
reactions:write | None |
users:read | Contact details, Online identifiers and account information |
users:read.email | Contact details |
Stripe (stripe)
Customer, charge, invoice and subscription access reaches people’s payment and contact details. Product, price and coupon access does not.
| Scope | Personal information it can reach |
|---|---|
stripe:balance.read | None |
stripe:charges.read | Financial and transaction information, Payment card details, Contact details |
stripe:checkout.read | Financial and transaction information, Contact details |
stripe:checkout.write | Financial and transaction information, Contact details |
stripe:coupons.delete | None |
stripe:coupons.read | None |
stripe:coupons.write | None |
stripe:customers.delete | Contact details, Customer and sales records, Financial and transaction information |
stripe:customers.read | Contact details, Customer and sales records, Financial and transaction information |
stripe:customers.write | Contact details, Customer and sales records, Financial and transaction information |
stripe:events.read | Financial and transaction information, Customer and sales records, Contact details |
stripe:invoices.delete | Financial and transaction information, Customer and sales records |
stripe:invoices.read | Financial and transaction information, Customer and sales records, Contact details |
stripe:invoices.write | Financial and transaction information, Customer and sales records, Contact details |
stripe:payment_intents.read | Financial and transaction information, Payment card details |
stripe:payment_intents.write | Financial and transaction information, Payment card details |
stripe:prices.read | None |
stripe:prices.write | None |
stripe:products.delete | None |
stripe:products.read | None |
stripe:products.write | None |
stripe:refunds.read | Financial and transaction information |
stripe:refunds.write | Financial and transaction information |
stripe:subscriptions.cancel | Financial and transaction information, Customer and sales records |
stripe:subscriptions.read | Financial and transaction information, Customer and sales records |
stripe:subscriptions.write | Financial and transaction information, Customer and sales records |
stripe:webhooks.read | None |
stripe:webhooks.write | None |
Stripe (stripe-live)
Customer, charge, invoice and subscription access reaches people’s payment and contact details. Product, price and coupon access does not.
| Scope | Personal information it can reach |
|---|---|
stripe:balance.read | None |
stripe:charges.read | Financial and transaction information, Payment card details, Contact details |
stripe:checkout.read | Financial and transaction information, Contact details |
stripe:checkout.write | Financial and transaction information, Contact details |
stripe:coupons.delete | None |
stripe:coupons.read | None |
stripe:coupons.write | None |
stripe:customers.delete | Contact details, Customer and sales records, Financial and transaction information |
stripe:customers.read | Contact details, Customer and sales records, Financial and transaction information |
stripe:customers.write | Contact details, Customer and sales records, Financial and transaction information |
stripe:events.read | Financial and transaction information, Customer and sales records, Contact details |
stripe:invoices.delete | Financial and transaction information, Customer and sales records |
stripe:invoices.read | Financial and transaction information, Customer and sales records, Contact details |
stripe:invoices.write | Financial and transaction information, Customer and sales records, Contact details |
stripe:payment_intents.read | Financial and transaction information, Payment card details |
stripe:payment_intents.write | Financial and transaction information, Payment card details |
stripe:prices.read | None |
stripe:prices.write | None |
stripe:products.delete | None |
stripe:products.read | None |
stripe:products.write | None |
stripe:refunds.read | Financial and transaction information |
stripe:refunds.write | Financial and transaction information |
stripe:subscriptions.cancel | Financial and transaction information, Customer and sales records |
stripe:subscriptions.read | Financial and transaction information, Customer and sales records |
stripe:subscriptions.write | Financial and transaction information, Customer and sales records |
stripe:webhooks.read | None |
stripe:webhooks.write | None |
Supabase (supabase)
A general database connection reaches whatever the database holds.
| Scope | Personal information it can reach |
|---|---|
auth:read | Contact details, Online identifiers and account information |
database:read | Business database records |
database:write | Business database records |
edge-functions:invoke | None |
edge_functions:read | None |
organizations:read | None |
projects:read | None |
secrets:read | None |
secrets:write | None |
storage:read | Files and documents |
storage:write | Files and documents |
Xero (xero)
Contacts, invoices and transactions identify customers and suppliers. Payroll scopes reach employee and tax information.
| Scope | Personal information it can reach |
|---|---|
accounting.budgets.read | None |
accounting.contacts | Contact details, Customer and sales records, Financial and transaction information |
accounting.contacts.read | Contact details, Customer and sales records, Financial and transaction information |
accounting.invoices | Financial and transaction information, Customer and sales records |
accounting.invoices.read | Financial and transaction information, Customer and sales records |
accounting.payments | Financial and transaction information |
accounting.payments.read | Financial and transaction information |
accounting.reports.read | Financial and transaction information, Customer and sales records |
accounting.settings | None |
accounting.settings.read | None |
accounting.transactions | Financial and transaction information, Customer and sales records |
accounting.transactions.read | Financial and transaction information, Customer and sales records |
assets.read | None |
files.read | Files and documents |
Any scope matching ^payroll\. | Employment and HR information, Financial and transaction information, Government identifiers, Contact details |