Netskope requires the following read-only scopes:
| Permissions Required by Netskope | Description | Purpose |
|---|---|---|
| read:orgs:admin | View organization details | Retrieve information about your Atlassian organization |
| read:domains:admin | View organization domains | Retrieve the domains claimed by and verified for your organization |
| read:policies:admin | View organization policies | Retrieve organization-level policies |
| read:directories:admin | View identity directories | Retrieve the identity directories connected to your organization |
| read:workspaces:admin | View product workspaces | Retrieve the product workspaces under your organization |
| read:tokens:admin | View API tokens | Retrieve information about user API tokens in your organization |
| read:keys:admin | View API keys | Retrieve information about organization admin API keys |
Atlassian does not allow the scopes of an existing API key to be changed. If any scope is missing, you must create a replacement key with the full scope set and reconnect your Netskope instance. Grant all of the scopes above when creating the key.
Netskope requires read-only scopes only. This connector cannot modify any data in your Atlassian organization.

