What we can see
Every connector uses minimal, read-only OAuth scopes: we can look, we can never touch. You can revoke access at any time from the tool itself or from Stackleaks. Below is exactly what each connector reads — this list is generated from the connector code itself, so it can't drift from reality.
Google Workspace LIVE
admin.directory.user.readonly— your user directory: names, emails, suspended/archived status and each user's last sign-in — the roster we check seats against, the leaver signal, and the activity signal in one read.apps.licensing— which Workspace license SKU each user holds, so findings carry the seat's real list price. Google offers no read-only variant of this scope — we only ever read with it.
Signing in with Google (the login button) uses only email and profile — the admin scopes above are requested separately, and only when a Workspace admin connects the scanner.
Microsoft 365 LIVE
User.Read.All (application)— your directory roster: names, emails, enabled/disabled status — the leaver signal.Reports.Read.All (application)— per-product usage reports, to know when an account was last active.Organization.Read.All (application)— your tenant's subscribed licenses — purchased vs assigned seats, and which SKU each user holds.
Granted once by a tenant admin via Microsoft's admin-consent screen, revocable in Entra at any time. The admin first signs in with Microsoft (openid profile email) so we can verify which tenant the consent belongs to — that sign-in grants us nothing else and nothing from it is stored. We store no passwords or refresh tokens — only your tenant id.
Slack LIVE
users:read + users:read.email (bot)— your member list with emails and deactivated status — the roster we cross-check.team.billing:read (bot, optional opt-in)— your workspace's plan, so findings carry Slack's real per-seat price — asked for separately because Slack labels it "Administer your workspace" even though it only reads the plan name; skipping it just means list-price estimates.admin (installing admin's user token, optional opt-in)— team.accessLogs — when each member last signed in (finds dormant seats); Slack only exposes this to admins on paid plans, and only if you take the optional activity upgrade.
Slack is not an identity source: its accounts only link to the roster your directory provides — a Slack seat can never mark anyone active or inactive in your directory.
Atlassian — Jira + Confluence LIVE
read:directories:admin— your Atlassian directory: names, emails, account status, which products (Jira/Confluence) each person can use, and when each product was last used (Atlassian delays activity by ~24h).read:workspaces:admin— each site's plan tier (Free/Standard/Premium) per product, so free products honestly cost €0 in your report and paid ones use their real tier's list price.
No OAuth app here: you create the API key yourself in admin.atlassian.com (walkthrough with the exact scopes) and can revoke it there at any time. Atlassian expires these keys within a year — we remind you before yours does. Disconnecting deletes the key from our side immediately.
GitHub Copilot LIVE
Members (read)— your organization's member and outside-collaborator list, plus verified-domain email addresses for matching seats to your roster.GitHub Copilot Business (read)— who holds a Copilot seat, which plan it is on, and when each seat was last active (IDE telemetry — can be unknown).Administration (read)— your organization's plan name and seat counts — a Free org's members honestly cost €0, and unused purchased seats surface as waste.
OpenAI LIVE
Admin API key (read-only use)— your OpenAI organization's member list: names, emails, roles, and when each member was added.audit log (login events only)— when each member last signed in — the dormant-seat signal; we read login.succeeded events and nothing else.
Anthropic Claude LIVE
Claude Enterprise: Analytics API key (read:analytics)— every claude.ai seat holder and whether they were active each day — full ghost and dormant detection.Claude Team: your exported members CSV (no API access — Anthropic doesn't offer one for Team)— seat list with tiers, so Standard and Premium price correctly; ghost detection via your roster, activity honestly unknown.
ClickUp LIVE
ClickUp has no OAuth scopes — the token acts as the authorizing user (their design, not ours)— we only ever read the workspace member list (names, emails, roles, last-active) and the plan name. Authorize with an admin account rather than the owner to keep the blast radius small.
HubSpot LIVE
settings.users.read— your HubSpot user list: emails, roles, seat assignments.crm.objects.owners.read— mapping users to CRM owners, so a ghost's pipeline ownership is visible.account-info.security.read— the login-activity log — when each user last signed in, the dormant-seat signal.
Pipedrive LIVE
users:read (base scope)— your Pipedrive user list: names, emails, admin flag, active/deactivated state, and each user's last login — everything the ghost and dormant checks need, from one endpoint.
Zoom LIVE
user:read:list_users:admin— your Zoom user list: emails, Basic vs Licensed seat type, and each user's last sign-in — the whole ghost/dormant check in one read.user:read:user:admin— reading a single user's details when the list needs disambiguating.
Miro LIVE
team:read— your Miro team's member list with each person's role and join date — who actually holds a seat.identity:read— each member's email address, so Miro seats match your roster — the ex-employee still in your Miro is exactly what this catches. Miro exposes no license or activity data outside Enterprise, so seats price at your plan's list rate and dormancy stays honestly unknown.alternatively: your users CSV or a pasted members page (zero access)— same member list without granting anything; the Enterprise export adds license + last activity, which the API withholds.organizations:read (dormant)— Miro grants this only to apps owned by Enterprise accounts; once our Enterprise API access is approved it adds license types and real activity in one read.
Figma LIVE
your exported members CSV (no API access — Figma offers no org-members API)— each member's seat type and last-active date: Full, Dev and Collab seats price correctly at your plan's rate, and the €90/month Full seat nobody opened since spring is a real finding, not a guess.
Zendesk LIVE
users:read— your agent and admin list with suspension state, light-agent flag and each agent's last sign-in — billable seats and activity in one read; ticket contents stay unreadable.
Dropbox Business LIVE
members.read— your team's member list with each seat's status (active, invited, suspended) — file contents stay unreadable.team_info.read— licenses bought vs seats filled — the licenses you pay for but never handed out.
monday.com LIVE
users:read— your member list with each seat's kind (admin, member, guest, viewer), status and last activity — billable seats and dormancy in one read.account:read— your plan tier and purchased seat count, so findings carry monday's real per-seat price and the seats you bought but never handed out show up.
Intercom LIVE
Read admins (Developer Hub scope — Intercom sets scopes on the app, not per consent)— your teammate list with each seat's paid-vs-Lite flag — the billable inbox seats. Intercom exposes no last-seen for teammates, so activity stays honestly unknown; conversations and customer data stay unreadable.
GitLab LIVE
read_api— your top-level group's billable members: usernames, names, the email GitLab shows group owners, each member's last activity and last sign-in, and how they hold the seat (direct, via a project, via an invited group) — read-only; code, issues and merge requests are never fetched.
Asana LIVE
users:read— the members of the Asana workspace you pick: each seat's name and sign-in email — read-only; tasks, projects and messages are never fetched.workspaces:read— the names of the workspaces the connecting account belongs to, only so you can pick the one we scan.
Notion LIVE
Read user information incl. email (connection capability)— the members of your Notion workspace: each seat's name and sign-in email — read-only; guests aren't even listed, bots are skipped.Read content (forced on by Notion — never used)— Notion requires every public connection to hold a content capability, so its consent screen asks you to share pages. Pick any page and continue: we never call a content endpoint — pages, databases and comments are never fetched.
Linear LIVE
read— your Linear workspace's members: names, emails, roles (owner, admin, member, guest), when each was last seen and when they joined — plus the workspace name and plan so seats price themselves. Read-only, and the smallest scope Linear offers: issues, projects, comments and documents are never fetched.
CSV / Excel upload NO ACCESS AT ALL
The no-OAuth path: you export your users list yourself (CSV or .xlsx) and upload it. We read nothing from your systems — the report covers exactly what's in the file.
What we can never do
- Create, modify, suspend, or delete users or licenses — the scopes don't allow it.
- Read message or document contents. We see who has a seat and when it was last used, not what anyone wrote.
- Share your data across tenants — every record is scoped to your organization.
Responsible disclosure
Found a vulnerability? Mail [email protected] — we acknowledge within 2 business days and keep you posted until it's fixed. We will not take legal action against good-faith security research; we don't run a paid bounty program, but we credit reporters who want it. Machine-readable: /.well-known/security.txt.
Disconnecting cuts access — deleting is your call
Disconnecting any connector deletes its tokens immediately (we also revoke them at the provider where an API for that exists), so we can read nothing from that moment on. Your scan history — seats, findings, recovered money — stays, because connections are sometimes quirky and reconnecting should never cost you your history. Want the data gone too? Deleting your account removes everything, and deletion requests by mail work at any granularity: [email protected], acknowledged within 2 business days, executed within 7. Backups roll off within 30 days. Two cases where deletion happens without a mail: removing a disconnected tool from your stack deletes that tool's seats and findings (that is the explicit "we don't use this" step — the card, the seats and the findings leave together), and removing the Zoom app from your Zoom account wipes everything we read from Zoom, as Zoom's marketplace terms require.
How tokens are handled
OAuth tokens are encrypted at rest (Active Record encryption), never written to logs, and never serialized into background jobs. Hosting is EU-only. Adding any new scope to a connector requires updating this page in the same change.
More connectors (Salesforce, DocuSign, Okta) will be listed here, scope by scope, as they ship.