- Approves the app in the tenant.
- Gives the app read and write access to the selected site only (
Sites.Selected).
Types of permission
- Delegated: the app acts on behalf of the signed-in user, with that user’s rights.
- Application: the app acts as itself, without a signed-in user.
Sites.Selected exists only as an Application permission. To give the app access to one specific site, SharePoint requires a user token with the delegated scope Sites.FullControl.All. That’s why a Global Administrator must sign in once. The delegated token is used only for this setup step.
What we use the scopes for
Delegated permissions (Global Administrator, one-time setup)
SuperOffice doesn’t store tokens for
User.Read and Sites.FullControl.All. You may remove these 2 delegated scopes after setup.Application permission (SuperOffice Document Library, ongoing)
This permission is stored and used continuously. Don’t remove
Sites.Selected, or features that depend on the system user stop working.Steps and required roles
If you aren’t a Global Administrator, copy the authorization link from the wizard and send it to someone who is.
If your tenant doesn’t allow users to approve apps themselves, other users see Need admin approval until a Global Administrator has approved the app.
For the full list of roles needed for setup, see Requirements.