Every scope each application declares.
Permissions are declared in the application’s Forge manifest and are reviewed against the production manifest before release. An application requests only the permissions its documented functionality needs.
LaunchPad
27 Forge scopesForge manifest- storage:app
- read:jira-work
- write:jira-work
- read:jira-user
- manage:jira-project
- manage:jira-configuration
- read:servicedesk-request
- write:servicedesk-request
- read:requesttype:jira-service-management
- write:requesttype:jira-service-management
- read:servicedesk:jira-service-management
- read:issue-type-screen-scheme:jira
- read:screen-scheme:jira
- read:screen:jira
- read:screen-tab:jira
- read:cmdb-schema:jira
- write:cmdb-schema:jira
- read:cmdb-type:jira
- write:cmdb-type:jira
- read:cmdb-attribute:jira
- write:cmdb-attribute:jira
- read:cmdb-object:jira
- write:cmdb-object:jira
- read:cmdb-config:jira
- write:cmdb-config:jira
- read:cmdb-icon:jira
- import:import-configuration:cmdb
The configuration and project management scopes are required because LaunchPad builds Jira Service Management request forms and Assets schemas on the customer’s behalf.
External endpoints
- api.atlassian.com
Atlassian’s own API. No LT.Solutions endpoint and no third party service is permitted.
Second Chance
5 Forge scopesForge manifest- read:jira-work
- read:jira-user
- manage:jira-project
- read:knowledgebase:jira-service-management
- storage:app
manage:jira-project is required only to set the project property that gates the panels.
External endpoints
- None declared
No external fetch permissions exist in the manifest, so no backend request can leave Forge.
LT Census Connect
12 Forge scopesForge manifest- storage:app
- read:cmdb-schema:jira
- read:cmdb-type:jira
- read:cmdb-attribute:jira
- read:cmdb-object:jira
- read:cmdb-icon:jira
- read:servicedesk-request
- read:permission:jira
- write:cmdb-schema:jira
- write:cmdb-type:jira
- write:cmdb-attribute:jira
- write:cmdb-object:jira
No deletion scope is declared, in Assets or anywhere else.
External endpoints
- account.apple.com
- api-business.apple.com
- *.api.kandji.io
Your own source systems. No LT.Solutions endpoint appears in the list.
Asset Sync
Published before releaseNot yet publishedGoogle and Atlassian permissions are published from the deployed production configuration before release, in the same structure as the Forge applications above.
External endpoints
- Published before release
The LT.Solutions services in the path are named at publication, not summarised now.
LT Census Discovery
Published when verifiedNot yet publishedCloud permissions are published when the production architecture has been deployed and verified.
External endpoints
- Published when verified
Hosting model and storage locations are named at the same time.