Effective app permissions (project)
Policy
Effective app permissions (project)
What the PUBLISHED policy actually allows for an app, per tool — a read-only reflection, not an editor. Replaces the retired /rules/permissions/{provider}, which returned stored permission rows; this resolves the rules instead, so a verdict set by any matching rule appears here.
Omit agentId for the all-agents baseline. variesByIdentity counts identity-scoped rules the baseline cannot show. An organization rule’s name is visible only to organization admins; other viewers receive redacted: true.
GET
Effective app permissions (project)
Authorizations
API key obtained from the dashboard or GET /user/api-key
Query Parameters
App provider, e.g. gmail.
Narrow to one agent's identity.