> ## Documentation Index
> Fetch the complete documentation index at: https://getsoda.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Approve Soda for your organisation

<Info>
  This page is for IT admins who approve apps for their organisation.
</Info>

Soda is the memory layer for customer-facing teams. It learns from existing conversations to build a living memory of every customer, prospect, and account.

If your organisation requires admin consent for new apps, people can't sign in to Soda with their work account until you approve it. Approval is one time, for the whole organisation. Until then, your team sees an approval screen when they sign in. See [what they see](/docs/getting-started/install-and-sign-in#if-your-company-needs-to-approve-soda).

## What Soda asks for

At sign-in, Soda asks for each person's name, email address, and read-only access to their calendar. In Microsoft Entra and the Google Admin console, the app appears as **Soda**.

Mailbox access is separate and optional. Each person chooses whether to connect their mailbox later, so Soda can read their email and help them create meeting follows. Your organisation may need to approve this separately, in the same way.

## What Soda never does

* It doesn't send email. Follow-ups are saved as drafts, and the person decides whether to send them.
* It doesn't add, change, or delete anything on a calendar.
* It doesn't join meetings.

For what Soda keeps from each source, see [What Soda captures](/docs/privacy/what-soda-captures).

## Microsoft Entra

### Scopes requested at sign-in

| Scope | Why Soda asks for it |
| - | - |
| `openid` | Signs the person in. |
| `email` | Their email address. |
| `profile` | Their name. |
| `offline_access` | Keeps Soda connected, so they don't sign in again every day. |
| `Calendars.Read` (Microsoft Graph) | Reads their calendar, so Soda knows who they're meeting and when. Read-only. |

### Approve a pending request

If someone at your organisation clicked **Request approval**, their request is waiting for you.

<Steps>
  <Step title="Sign in to the Microsoft Entra admin center">
    Go to [entra.microsoft.com](https://entra.microsoft.com) and sign in as at least a Cloud Application Administrator.
  </Step>

  <Step title="Open Admin consent requests">
    Go to **Entra ID** > **Enterprise apps**. Under **Activity**, select **Admin consent requests**.
  </Step>

  <Step title="Select Soda">
    On the **My Pending** tab, select **Soda**.
  </Step>

  <Step title="Review and approve">
    Select **Review permissions and consent**, check the scopes match the table above, and approve. Microsoft lets everyone who asked know.
  </Step>
</Steps>

### No pending request

Your tenant may have admin consent requests turned off, so people can't ask. Grant consent directly instead.

<Steps>
  <Step title="Open Enterprise apps">
    In the Microsoft Entra admin center, go to **Entra ID** > **Enterprise apps** > **All applications**.
  </Step>

  <Step title="Select Soda">
    Search for **Soda** and select it.
  </Step>

  <Step title="Grant admin consent">
    Under **Security**, select **Permissions**. Review the scopes, then select **Grant admin consent**.
  </Step>
</Steps>

Microsoft's guides: [Review and take action on admin consent requests](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/review-admin-consent-requests) and [Grant tenant-wide admin consent to an application](https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/grant-admin-consent).

## Google Workspace

### Scopes requested at sign-in

| Scope | Why Soda asks for it |
| - | - |
| `openid` | Signs the person in. |
| `email` | Their email address. |
| `profile` | Their name and profile picture. |
| `https://www.googleapis.com/auth/calendar.readonly` | Reads their calendar, so Soda knows who they're meeting and when. Read-only. |

### Set Soda to Trusted

<Steps>
  <Step title="Sign in to the Google Admin console">
    Go to [admin.google.com](https://admin.google.com) and sign in as an administrator.
  </Step>

  <Step title="Open app access">
    Go to **Menu** > **Security** > **Access and data control** > **API controls**. Select **Manage Third-Party App Access**.
  </Step>

  <Step title="Find Soda">
    Find **Soda** in the list of apps.
  </Step>

  <Step title="Set its access to Trusted">
    Change Soda's access to **Trusted**.
  </Step>
</Steps>

**Trusted** lets Soda use every Google service, including ones you've marked as restricted, such as Calendar or Gmail. Each person still approves Soda's access when they sign in.

Google's guide: [Control which apps access Google Workspace data](https://support.google.com/a/answer/7281227).

## Questions

For anything else your security review needs, [contact support](/docs/troubleshooting/contact-support).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.