Effective app permissions (project)
What the enforced policy actually allows for an app, per tool — a read-only reflection of the compiled grants plus organization rules, not an editor. Project-level access is written through the Grants endpoints; organization guardrails through /org/policy/*.
Omit agentId for the all-agents baseline. Pass connectionId to reflect one specific account when several accounts of the app are connected. variesByIdentity counts identity-scoped rules the baseline cannot show. Each tool’s orgCeiling reports what the organization level alone would decide — the value a project grant can never exceed. An organization rule’s name is visible only to organization admins; other viewers receive redacted: true.
Authorizations
API key obtained from the dashboard or GET /user/api-key
Query Parameters
App provider, e.g. gmail.
Narrow to one agent's identity.
Reflect one specific account (connection) of the app.