Integrations

Scopes

A connection can do only what its scopes allow. This is what each one allows, who can give it, and what no scope allows.

This page is for the developer deciding what a connection needs to reach, and for the manager in your organisation who gives it that access.

It lists every scope, who can give each one, and what a connection cannot do whatever scopes it holds.

The scopes

ScopeAllows
conversations:readlist conversations, and read one, its transcript and its facts
summaries:readread a conversation's summary
cases:readlist cases and read one
cases:writecreate a case, and start a conversation in one
documents:writesend a document in a case to be translated
documents:readread a sent document and its translation
users:readlist people and invitations, and read one
users:writeadd, change and remove people, withdraw an invitation, and set a person's group
groups:readlist groups and the permissions they hold
groups:writeadd, change and delete groups, and set their permissions
webhooks:manageadd, change and remove the connection's webhooks

GET /me needs no particular scope. Any other call that needs a scope the connection does not hold answers 403 scope_missing.

A write scope does not include its read scope. A connection that creates cases and reads them back needs both cases:write and cases:read.

Who can give a scope

Scopes are chosen on the Integrations page when a connection is made, and you can change them there later. The person choosing must hold Manage integrations, and for each scope the permission it reads or writes:

ScopePermission the person must hold
conversations:read, summaries:readRead conversations
cases:read, cases:write, documents:write, documents:readaccess to cases
users:read, users:writeManage users
groups:read, groups:writeManage groups
webhooks:manageManage integrations only

If somebody without a scope's permission saves the connection, a scope it already holds stays. They cannot add it.

A change of scopes applies from the next call, to every key of the connection.

What no scope allows

  1. Starting a conversation without a person. cases:write answers an address, and a signed-in member of your organisation opens it to start the conversation.
  2. Sending a password reset, removing an authenticator, or removing passkeys.
  3. Erasing a person. users:write removes a person from your organisation, and their account remains.
  4. Giving away the management permissions. A connection cannot give a group Manage users, Manage billing, Manage integrations or Manage groups, or put a person in a group that holds one of them. These answer 403 permission_not_grantable.
  5. Reaching another organisation. Nothing of another organisation can be read or changed. These answer 404 not_found.

Choosing scopes

Give a connection only the scopes its job needs. These are the usual sets:

UseScopes
Copy summaries into a case management systemconversations:read, summaries:read, webhooks:manage
Open a case from another system and start a conversation in itcases:read, cases:write
Send letters to be translatedcases:read, documents:write, documents:read, webhooks:manage
Provision accounts from an identity providerusers:read, users:write, groups:read, groups:write