ActiveManage Docs ← Back to activemanage.co.uk

Deciding What Applications Can See

What a connected application may learn about a user is controlled by a set of permissions, each shown to the user in plain language when they are asked to approve it.

The permissions

  • Sign you in — "Verify your identity". Enabled by default.
  • Your basic profile — "View your name, username and profile picture". Enabled.
  • Your email address — "View your email address". Enabled.
  • Your phone number — "View your mobile number". Disabled by default.
  • Stay signed in — "Remain signed in without being asked again". Disabled.
  • Your security groups — "View which security groups you belong to". Disabled.

The three disabled by default release more than an application usually needs. Enable them deliberately, and per application.

Be careful with security groups

Releasing group membership tells an application a great deal about your internal structure and about the individual. Enable it only where the application genuinely makes decisions from it, and only for applications you control.

Consent

Consent is recorded per user, per application, and it is the thing that gets revoked when access is withdrawn — so it matters more than it looks.

It expires after a set period, one year by default, after which the user is asked again. An application asking for something beyond what the user already approved prompts them afresh, so an application cannot quietly widen its access.

The consent screen is your users' only defence

What they see is the application's name, logo and description together with those plain-language descriptions. That is the entire basis on which they decide. Keep the details honest, and do not mark third-party applications as trusted.