Skip to content

Sign-in and permissions

What you approve when you connect an app, and what each permission allows.

When you connect an AI app, Tahoe’s sign-in page asks what the app may do in your workspace. You choose a preset or single permissions, and the app can then only do what you allowed. This page lists the presets, how the page groups permissions, and all 18 permissions.

Each permission has a short technical name, its scope, such as jobs:read. You see it in small print on the sign-in page, and some apps ask for scopes when an admin sets them up.

The presets

PresetWhat it includes
Read-onlyThe four View permissions, plus See contact details, résumés and phone screens, and View ATS & CRM. The app can look, but never changes anything: if it tries to change, spend or send something, Tahoe refuses with a clear message and nothing changes.
Recruiter (recommended)Everything in Read-only, plus Organize candidates, Manage jobs and pipelines, Draft and manage outreach, Run searches and Reveal contacts.
Full accessAll 18 permissions, as far as your Tahoe role allows.

Recruiter is selected when the sign-in page opens. It leaves out the four actions that reach outside Tahoe (sending email, publishing jobs, exporting to your ATS and posting on LinkedIn) and the three admin permissions.

The first time you ask the app for one of those outside actions, it opens Tahoe once to ask for that one permission. After you approve, Tahoe remembers it. If your app cannot open that page, disconnect it and connect again with Full access.

How the sign-in page groups permissions

Group on the pageWhat it covers
Read your workspaceLooking at your workspace, candidates, jobs and outreach.
Personal data about candidatesContact details, résumés, phone screens and ATS data.
Make changesChanges that stay inside Tahoe: lists, jobs, pipelines and outreach drafts.
Spend creditsSearches and contact reveals.
Act outside Tahoe (email, publish, export)Actions other people can see: email, job postings, your ATS and LinkedIn.
Administer the workspaceTeam, billing and compliance. Owners and admins only.

Permissions that include others

Some permissions need another one to make sense, so they include it. The sign-in page marks the included permission Included. For example:

  • Send email from your mailbox includes Draft and manage outreach, which includes View outreach.
  • Reveal contacts includes See contact details, résumés and phone screens.
  • Run searches and Organize candidates include View candidates and lists.
  • Manage jobs and pipelines includes View jobs and applicants, and Export to your ATS includes View ATS & CRM.
  • Administer the workspace includes View your workspace.

Labels next to a permission

LabelWhat it means
RequestedThe app asked for this permission.
IncludedAnother permission you ticked already includes it.
Needs a higher roleYour role in this workspace cannot grant it.
Turned off by your adminYour workspace admins have turned this off for AI apps.
Temporarily unavailableTahoe cannot offer it right now. Try again later.

All 18 permissions

Read your workspace

PermissionWhat it allowsScope
View your workspaceThe overview, notifications, credits and credit history, analytics, the team list, and settings (view only).workspace:read
View candidates and listsSaved profiles, lists, contacts without their emails or phone numbers, search history and GitHub results.candidates:read
View jobs and applicantsJobs, application forms, pipelines and applications (including the applicant’s email and phone, as in the dashboard), notes, scorecards and hiring analytics.jobs:read
View outreachMailboxes, campaigns, recipients and templates.outreach:read

Personal data about candidates

PermissionWhat it allowsScope
See contact details, résumés and phone screensEmails and phone numbers you have revealed, résumés, and phone pre-screen transcripts and recordings.contacts:read
View ATS & CRMATS and CRM connections, imported roles, sync activity and export history.integrations:read

Make changes

PermissionWhat it allowsScope
Organize candidatesSave people to lists, edit and import contacts, and manage saved searches and stages.candidates:write
Manage jobs and pipelinesCreate and edit jobs, application forms and the career page; move, reject and score applicants; add notes.jobs:write
Draft and manage outreachDraft campaigns and templates, pause or stop campaigns, mark replies and set mailbox limits.outreach:write

Spend credits

PermissionWhat it allowsScope
Run searchesCandidate searches and new result pages, X-ray searches, concierge requests and GitHub searches. Spends credits.search:run
Reveal contactsFind emails and phone numbers, unlock résumés and export GitHub results to CSV. Spends credits.contacts:reveal

Paid actions cost the same credits as in the dashboard, and the app states the price before it runs one. Credits and limits

Act outside Tahoe

PermissionWhat it allowsScope
Send email from your mailboxLaunch and resume campaigns, send test emails and email applicants.outreach:send
Publish jobsPublish, schedule, unpublish, close and reopen job postings.jobs:publish
Export to your ATSExport people to your ATS or CRM, sync, import again and change integration settings.integrations:write
Post to LinkedInDraft and publish posts on your own LinkedIn feed.linkedin:post

Sending email, GitHub search, LinkedIn posting and ATS export also need a one-time setup in the Tahoe dashboard. Connect your AI app lists where.

Administer the workspace

PermissionWhat it allowsScope
Administer the workspaceInvite teammates, change roles, and change company, compliance and notification settings.team:admin
Manage billingGet payment links, and cancel or resume the plan.billing:manage
Compliance actionsGDPR erasure, the EEO report and the security log.compliance:admin

Your role is the limit

An AI app can never do more than your own Tahoe role allows, whatever you tick. Full access means everything your role can do.

Your rolePermissions you can give an app
ViewerThe four View permissions, and See contact details, résumés and phone screens.
MemberAll except the three admin permissions.
Admin or OwnerAll 18.
  • Your admins’ settings apply too. Owners and admins decide in Settings → AI connectors what AI apps may do at all. Posting on LinkedIn and billing changes start turned off. Admin controls
  • If your role is lowered, the connection keeps working, but only with what your new role allows.

Staying signed in

  • The app never gets your password. It gets short-lived access, valid for 15 minutes, which it renews automatically in the background. You do not have to do anything.
  • Every request is checked against your current role and your admins’ settings, not only the ones you had when you connected.
  • You stay connected for up to 90 days, as long as you use the connection at least once every 30 days. Then the app asks you to sign in again.
  • A connection request expires after 10 minutes. If the sign-in page sat open too long, start again from your app.

Change what an app may do

To give an app more, approve the extra permission when Tahoe asks. To give it less, or to change the tools it sees, disconnect it in Settings → Connected apps and connect again with different choices. Manage your connections

Examples

Example

Launch the Columbus HVAC outreach campaign tomorrow at 9am.

Jordan Rivera at Kestrel Labs connected with the Recruiter preset, which does not include sending email. The app opens Tahoe once to ask for Send email from your mailbox. Jordan approves, and the campaign is scheduled from the Gmail mailbox Jordan connected in Outreach → Mailboxes. The next campaign does not need another approval.

Example

Move Sam Lee to the Offer stage for the Field Coordinator job.

A hiring manager with the Viewer role connected with Full access. Because a Viewer can only look, the sign-in page showed Manage jobs and pipelines as Needs a higher role, and the app can only report the pipeline. A recruiter on the team makes the move instead.