| Microsoft identityopenidprofileemailoffline_access | Identify the Microsoft account connected to Outlook or OneDrive & SharePoint, and keep the user-selected connection available without repeated sign-in. | Identity and offline access do not themselves grant file, mail, calendar, or contact access. |
| OneDrive & SharePointFiles.Read.AllFiles.ReadWrite.All (incremental)Sites.ReadWrite.All (incremental) | Search and import files with read access. When the user chooses save-back and grants the additional scopes, create or update the selected file or site content for that action. | The connection starts read-only. Write scopes are requested incrementally for user-directed save-back; they are not part of the default read connection. |
| Outlook MailMail.ReadWrite | Search and read requested messages and, when the user directs it, create or update mail content needed for the Outlook workflow. | The product does not expose mailbox deletion or bulk background processing. Sending is separately authorized by Mail.Send. |
| Outlook MailMail.Send | Send a new email or reply only after the user initiates or approves the action. Messages can be plain text or use a safe Markdown subset rendered to formatted HTML with a plain-text alternative. | Used only for sending; formatting requires no additional permission. Arbitrary HTML, scripts, styles, event handlers, and unsafe link schemes are not accepted. |
| Outlook CalendarCalendars.ReadWrite | List or search events and create, update, or respond to an event at the user’s direction. | Limited to calendar data. It does not grant access to Microsoft files or mail. |
| Outlook ContactsContacts.Read | Find a contact the user asks for when addressing an approved message or completing an Outlook task. | Read-only; LumenQube cannot create, change, or delete contacts. |
| Dropboxfiles.metadata.readfiles.content.read | Search files the user can access, import the spreadsheet or structured-data file they select, and refresh explicitly connected table data. | Read-only. LumenQube does not request file upload, edit, sharing, or deletion permissions. |
| Slack conversationschannels:readchannels:historygroups:readgroups:historyim:readim:historympim:readmpim:history | List and read only conversations where the installed LumenQube bot is a member, and search recent messages locally within those joined conversations for a user-requested task. | LumenQube does not request workspace-wide search:read, user-token history, member-directory, administration, or deletion scopes. |
| Slack postingchat:write | Post a message to a conversation where the LumenQube app is permitted, only when the user initiates or approves it. | No posting is performed merely because the app is installed or a conversation is read. |