Trust · Permissions

Every scope each application declares.

Permissions are declared in the application’s Forge manifest and are reviewed against the production manifest before release. An application requests only the permissions its documented functionality needs.

LaunchPad

27 Forge scopesForge manifest
Application storage
  • storage:app
Jira and Jira Service Management
  • read:jira-work
  • write:jira-work
  • read:jira-user
  • manage:jira-project
  • manage:jira-configuration
  • read:servicedesk-request
  • write:servicedesk-request
  • read:requesttype:jira-service-management
  • write:requesttype:jira-service-management
  • read:servicedesk:jira-service-management
  • read:issue-type-screen-scheme:jira
  • read:screen-scheme:jira
  • read:screen:jira
  • read:screen-tab:jira
Assets
  • read:cmdb-schema:jira
  • write:cmdb-schema:jira
  • read:cmdb-type:jira
  • write:cmdb-type:jira
  • read:cmdb-attribute:jira
  • write:cmdb-attribute:jira
  • read:cmdb-object:jira
  • write:cmdb-object:jira
  • read:cmdb-config:jira
  • write:cmdb-config:jira
  • read:cmdb-icon:jira
  • import:import-configuration:cmdb

The configuration and project management scopes are required because LaunchPad builds Jira Service Management request forms and Assets schemas on the customer’s behalf.

External endpoints

  • api.atlassian.com

Atlassian’s own API. No LT.Solutions endpoint and no third party service is permitted.

Second Chance

5 Forge scopesForge manifest
All declared scopes
  • read:jira-work
  • read:jira-user
  • manage:jira-project
  • read:knowledgebase:jira-service-management
  • storage:app

manage:jira-project is required only to set the project property that gates the panels.

External endpoints

  • None declared

No external fetch permissions exist in the manifest, so no backend request can leave Forge.

LT Census Connect

12 Forge scopesForge manifest
Application storage
  • storage:app
Read
  • read:cmdb-schema:jira
  • read:cmdb-type:jira
  • read:cmdb-attribute:jira
  • read:cmdb-object:jira
  • read:cmdb-icon:jira
  • read:servicedesk-request
  • read:permission:jira
Write
  • write:cmdb-schema:jira
  • write:cmdb-type:jira
  • write:cmdb-attribute:jira
  • write:cmdb-object:jira

No deletion scope is declared, in Assets or anywhere else.

External endpoints

  • account.apple.com
  • api-business.apple.com
  • *.api.kandji.io

Your own source systems. No LT.Solutions endpoint appears in the list.

Asset Sync

Published before releaseNot yet published

Google and Atlassian permissions are published from the deployed production configuration before release, in the same structure as the Forge applications above.

External endpoints

  • Published before release

The LT.Solutions services in the path are named at publication, not summarised now.

LT Census Discovery

Published when verifiedNot yet published

Cloud permissions are published when the production architecture has been deployed and verified.

External endpoints

  • Published when verified

Hosting model and storage locations are named at the same time.

We use analytics cookies to understand how the site is used, only if you accept. Read our privacy policy.