The Artificial Organisation
Log inBook a discovery callBook a call
Back to home
Data and permissions

What each connection can see, and why.

TAO asks a system for access only when you or your administrator connects it, and only for the modules you can see inside the product. This page is the public record of what each connection is for, kept in step with the consent screens themselves.

How connections work

Nothing is connected until you or your administrator connects it. Each connection asks for the narrowest set of permissions that covers the module you can see, is listed inside TAO with those permissions, and can be revoked there or at the provider.

Google Workspace

  • How it connects: OAuth 2.0 through a reviewed Google project.
  • What it can see: Gmail, Google Calendar, Contacts and Drive data only where the connected module and the approved scope require it.
  • Your controls: Disconnect inside TAO or revoke from your Google Account at any time. TAO’s use and transfer of Google user data adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft 365

  • How it connects: Microsoft Entra ID sign-in and Microsoft Graph permissions.
  • What it can see: Outlook mail, calendar, profile and files only where you or your administrator grants the relevant permission.
  • Your controls: Administrators can require consent for higher-privilege permissions and revoke the app from Enterprise Applications.

Xero

  • How it connects: Xero OAuth 2.0 with granular scopes.
  • What it can see: Invoices, contacts, payments, account codes and reports, only for the accounting work a module does. The narrowest scopes that cover the live feature.
  • Your controls: Re-authorise when scopes change. Remove the connection from Xero or TAO at any time.

Current RMS and other job or rental systems

  • How it connects: The system’s own OAuth or API key, depending on what it offers.
  • What it can see: Jobs, opportunities, contacts, inventory and rental records where the implementation scope requires them.
  • Your controls: API keys are stored encrypted, rotated on a schedule and revoked when no longer needed.

Everything else

  • How it connects: The provider’s own official access, documented before it is switched on.
  • What it can see: Only what the visible module needs. No scope is requested until the feature that uses it exists and this page describes it.
  • Your controls: Every connection is listed inside TAO with its permissions, and can be revoked there.

What reviewers can check

The identifiers we use on every provider consent screen, so they can be matched against this page.

  • App nameTAO, The Artificial Organisation
  • Primary domaintheartificialorganisation.com
  • App subdomainapp.theartificialorganisation.com
  • API subdomainapi.theartificialorganisation.com
  • Privacytheartificialorganisation.com/privacy
  • Termstheartificialorganisation.com/terms
  • Supporttheartificialorganisation.com/support
  • Contactsupport@theartificialorganisation.com

One conversation about how your business works.

Half an hour with the people who would build it. Then a proposal for exactly what TAO should take off your plate.