Calendar connection is per-user. Each user authorizes their own mailbox and calendar access. All permissions are delegated — Atonom acts on behalf of the signed-in user, not at the application/tenant-wide level. Tenant admins can optionally restrict who may connect a Microsoft calendar using an Entra security group — see the Entra Integration guide.
Google Calendar
Atonom requests the following scopes when a user connects Google Calendar:Admin notes (Google Cloud)
If your organization manages its own Google OAuth client for Atonom:- Create or use a Google Cloud OAuth 2.0 client (Web application type).
- Enable the Google Calendar API for the project.
- If your Google Workspace admin restricts third-party app access, allowlist the Atonom OAuth client for the scopes above.
Microsoft Calendar (Outlook / Office 365)
Atonom requests the following Microsoft Graph delegated scopes when a user connects Microsoft Calendar:Admin notes (Microsoft Entra)
If your organization manages its own Entra app registration for Atonom calendar access:- Register a multi-tenant application (or single-tenant, if your deployment uses a specific tenant ID).
- Add the delegated Graph permissions matching the scopes above.
- Grant admin consent in your tenant if your policy requires it for those permissions.
- Optionally restrict which users may connect calendars using an Entra security group — see Calendar Access Security Group in the Entra integration guide.
Scope summary
Disconnecting
Users can disconnect their calendar from My Settings → My Calendar. Disconnecting removes stored OAuth tokens for that provider from Atonom; it does not revoke the app in Google or Microsoft. Users who want to fully revoke access can do so from their Google Account permissions or Microsoft account app permissions pages.Need help?
If users see authorization errors, missing calendars, or shared-calendar failures:- Confirm the OAuth client in Google Cloud or Entra includes the scopes in this document.
- For Microsoft shared calendars, verify
Calendars.Read.Sharedis granted. - For Microsoft tenants with conditional access or consent policies, ensure the Atonom app is allowed and admin consent has been granted where required.

