Overview
How might we design granular consent so people can trust and act on AI output?
When to use
- Essential for AI assistants, enterprise agents, and connector ecosystems where least-privilege permissions reduce risk and let users tailor scope to the specific task without losing the rest of the integration.
When to skip
- Tiny prototypes with a single harmless capability where toggles add clutter.
- Environments that only support coarse OAuth scopes and cannot honor fine toggles.
- One-shot local tools with no persisted permissions.
Rules
A single “Allow all” default that collapses granularity.
Toggles that look independent but still require re-auth of everything on change.
No plain-language description of what each capability can do.
Hiding previously granted scopes so users cannot audit them later.
Evidence
| Product | Implementation |
|---|---|
| GitHub Apps | Fine-grained repository and permission scopes at install time. |
| Google Workspace add-ons | Per-API scopes rather than blanket account access. |
| iOS / macOS privacy panes | Per-capability access to photos, mic, and screen recording. |
| ChatGPT / Claude connectors | Connector permissions broken into discrete actions where platforms allow. |
