What gets synced, and why these permissions?
Edventory requests the narrowest set of scopes that make the feature work — nothing more.
| Scope | What it allows |
|---|---|
…device.chromeos.readonly | Read your Chrome device list: serial, asset ID, enrollment, organizational unit, AUE date, and last activity. |
…device.chromeos | Move and deprovision Chrome devices — used only when you choose to deprovision from Edventory. |
…apps.licensing | Read seat counts for your Google Workspace for Education and Chrome Education Upgrade licenses. |
🔒
None of these scopes can read user email, Drive files, calendars, or any personal content. They cover Chrome device management and license counts only. You can review or revoke the authorization any time from the same Domain-Wide Delegation screen in Google Admin.