Connected apps · Reviewed July 28, 2026

Your external services, under your control.

Microsoft, Dropbox, and Slack connections are optional. Lumen requests only the permissions needed for the feature you connect, keeps authorization tokens server-side, and lets you disconnect at any time.

In context

You choose each connection

Outlook and OneDrive & SharePoint are separate Lumen connections even though both use Microsoft Graph.

Least privilege

Visible features map to scopes

The exact provider permissions and their product purpose are listed below.

Approval

Consequential actions stay gated

Sending mail, changing calendar data, or posting to Slack follows your connected-app approval setting.

Revocable

Disconnect whenever you choose

Disconnecting immediately deletes Lumen's stored token record for that connection.

1. Choose Connect

Start from the relevant Lumen feature.

2. Review consent

The provider shows the account and exact permissions.

3. Use the feature

Lumen accesses provider data only for the task you request.

4. Disconnect

The encrypted authorization record is deleted.

Permissions and why they are necessary

Service and OAuth scopeUser-facing use in Lumen Doc HubAccess boundary
Microsoft identity
openid
profile
email
offline_access
Identify the Microsoft account connected to Outlook or OneDrive & SharePoint, and keep the user-selected connection available without repeated sign-in.Identity and offline access do not themselves grant file, mail, calendar, or contact access.
OneDrive & SharePoint
Files.Read.All
Search spreadsheet files the user can already access in OneDrive or SharePoint, import a selected CSV, TSV, JSON, XLSX, or XLSM file, and refresh explicitly connected table data.Read-only. Lumen does not request Microsoft file creation, modification, or deletion permissions.
Outlook Mail
Mail.ReadWrite
Search and read requested messages and, when the user directs it, create or update mail content needed for the Outlook workflow.The product does not expose mailbox deletion or bulk background processing. Sending is separately authorized by Mail.Send.
Outlook Mail
Mail.Send
Send a new email or reply only after the user initiates or approves the action. Messages can be plain text or use a safe Markdown subset rendered to formatted HTML with a plain-text alternative.Used only for sending; formatting requires no additional permission. Arbitrary HTML, scripts, styles, event handlers, and unsafe link schemes are not accepted.
Outlook Calendar
Calendars.ReadWrite
List or search events and create, update, or respond to an event at the user's direction.Limited to calendar data. It does not grant access to Microsoft files or mail.
Outlook Contacts
Contacts.Read
Find a contact the user asks for when addressing an approved message or completing an Outlook task.Read-only; Lumen cannot create, change, or delete contacts.
Dropbox
files.metadata.read
files.content.read
Search files the user can access, import the spreadsheet or structured-data file they select, and refresh explicitly connected table data.Read-only. Lumen does not request file upload, edit, sharing, or deletion permissions.
Slack conversations
channels:read
channels:history
groups:read
groups:history
im:read
im:history
mpim:read
mpim:history
List and read only conversations where the installed Lumen bot is a member, and search recent messages locally within those joined conversations for a user-requested task.Lumen does not request workspace-wide search:read, user-token history, member-directory, administration, or deletion scopes.
Slack posting
chat:write
Post a message to a conversation where the Lumen app is permitted, only when the user initiates or approves it.No posting is performed merely because the app is installed or a conversation is read.

How connected-app data is handled

  • Access and use. Lumen accesses provider data only after the user connects that service and only to deliver the visible feature described above.
  • Storage and security. OAuth tokens are encrypted at rest in Lumen's server-side vault. Provider responses are not routinely retained as a separate server-side dataset. Content may remain in a local Lumen document or task history when the user chooses to use or save the result.
  • AI-assisted tasks. When a user explicitly asks Lumen Agent to summarize or transform connected content, the content needed for that request may be sent through Lumen's managed backend to the AI processor identified in our Privacy Policy. It is used to return that result, not for advertising or generalized model training.
  • Sharing. Lumen does not sell connected-app data, use it for targeted advertising, or disclose it to data brokers. Service providers receive data only as needed to deliver the user-requested feature, secure the service, or comply with law.
  • Human access. Lumen personnel do not read connected content unless the user gives explicit permission for specific support, access is necessary to investigate abuse or a security incident, or access is required by law.
  • Retention and deletion. Authorization remains until the user disconnects, revokes access at the provider, or deletes the Lumen account. Disconnecting deletes the stored connector token record. Locally saved results remain under the user's control.

Your controls

  1. Connect only the service you want from its relevant feature in Lumen Doc Hub.
  2. Review the provider consent screen before granting access.
  3. Set Act in connected apps to Ask if you want approval before every consequential action.
  4. Use Disconnect in Lumen to delete the stored token, or revoke access from your Microsoft, Dropbox, or Slack account controls.
  5. Request account and associated cloud-data deletion at privacy@lumenqube.com.

Google permissions are documented separately on our Google integrations page. For the complete legal disclosure, read our Privacy Policy. For connection help, contact support@lumenqube.com.