Agent-readable docs index: /llms.txt. Full docs in one file: /llms-full.txt. Download /docs.zip to grep all markdown files locally.

Identity & cloud access

Two per-customer capabilities can be enabled from the customer's detail view on Customers. They are separate controls, and neither automatically grants Stackyapper tools to customer users.
CapabilityWhat it governsWhere to enable it
Managed customer identityWho can enter the customer workspace: customer-owned SAML and SCIMCustomers → select the customer → Identity settings
Cloud permission packWhich Microsoft 365 or Google Workspace provider permissions the managing-account connection requestsCustomers → select the customer → Cloud access

Managed customer identity

Customer-owned SAML, SCIM, and automated identity lifecycle are included with every active managed customer workspace. There is no separate identity charge. Custom access domains are reserved for a future MSP package and are not included automatically. See Plan and billing.
Configure identity in the customer context:
  1. Select the customer on Customers and open Identity settings.
  2. Use the customer's verified domain and identity-provider metadata.
  3. If provisioning is required, generate a customer-scoped SCIM token and store it directly in the customer's identity provider.
  4. Test with a customer user and verify they reach the customer workspace.
Do not reuse MSP SAML metadata, a SCIM token, or a custom hostname across customers.

Cloud permission packs

Permission packs describe predefined Microsoft 365 or Google Workspace access. All packs are off by default, and each pack is a separate provider credential boundary. Five packs are read-only; one (Identity Containment) is write-capable.

Foundation Read

Read-only tenant basics through an org-level read app.
  • Covers: users and account status, domains, groups and membership, license inventory, service health (Microsoft 365) / org metadata (Google)
  • Excludes: group or license changes, mail and file contents, user suspension

Endpoint Posture

Read-only device posture through a separate endpoint read app (Intune / ChromeOS and mobile).
  • Covers: managed devices, compliance, OS and encryption status, stale-device reporting
  • Excludes: retire, wipe, lock, reset, policy changes

Security & Audit

Read-only security signals through a separate high-sensitivity read app; role-gated.
  • Covers: sign-ins and risky users, Defender incidents, audit activity, app grants (Microsoft 365) / login, admin, token, and Drive audit activity (Google)
  • Excludes: remediation, session revocation, account suspension

Configuration Posture

Read-only policy posture through a separate configuration read app.
  • Covers: Conditional Access, auth method posture, sharing posture, forwarding posture, policy summaries
  • Excludes: policy create, update, assign, or delete
Read-only content search through a resource-scoped content app with an explicit allowlist.
  • Covers: selected SharePoint sites, OneDrive locations, or Drive folders and files only
  • Excludes: tenant-wide content access, file writes, sharing changes, personal mail

Identity Containment

Write actions through a dedicated containment write app. Exact-argument confirmation and MSP approval are always required.
  • Covers: revoke sessions and tokens, disable or suspend a compromised account, remove an identified risky app grant or OAuth token
  • Excludes: create or delete users, password resets, role assignment, group or license management

Rules across all packs

  • A call runs only when provider consent, workspace policy, and action-time confirmation all allow it.
  • No pack exposes arbitrary Graph, Google API, PowerShell, or HTTP access.
  • Full revocation takes two steps — see the revocation note at the end of this page.
Pack documents are versioned and append-only; the current version (2026-07-18.1) is published at /docs/customer-cloud-permission-packs/2026-07-18.1 and shown in the portal. When the documentation version changes, review the current included and excluded capabilities before renewing the acknowledgement.

Before enabling a pack

  • Read the versioned permission documentation shown in the portal.
  • Confirm the provider tenant belongs to the selected customer, and that the pack is required for the intended workflow.
  • Acknowledge the documented access and approval requirements. If the pack is write-capable, have a managing-workspace owner enable it.
  • Complete customer administrator consent in the provider, then verify that the returned provider tenant or domain is the intended customer.
  • Grant Stackyapper tools separately through customer workspace policy.
Enabling a pack allows Stackyapper to request the documented provider permissions. It does not complete provider authorization or grant tools to customer users.
To revoke a pack, disable it in Stackyapper and revoke the corresponding enterprise application, OAuth grant, or domain-wide-delegation client in the customer's provider console.