For IT admins
Approving WeekNav for Microsoft 365 or Google Workspace
Someone in your organization wants to connect their work calendar to WeekNav, a weekly planner. This page lists exactly what WeekNav asks for, why, and how to approve it. Security questions: security@weeknav.com.
Microsoft 365 (Entra ID)
WeekNav is a multi-tenant app using delegated permissions only: it acts as the signed-in user and can reach only that user's calendars and calendars shared with them.
| Permission | Why WeekNav needs it |
|---|---|
openid, profile, email, User.Read | Sign the user in and show which account is connected |
Calendars.ReadWrite | Show the user's events beside their plan, and create the time blocks they schedule or accept |
Calendars.ReadWrite.Shared | Show calendars a colleague has shared or delegated to the user, if the user turns them on |
offline_access | Keep the calendar in sync when the app isn't open |
To approve for everyone: a Cloud Application Administrator or Application Administrator can grant tenant-wide consent in the Entra admin center under Enterprise applications → WeekNav → Permissions → Grant admin consent. A one-click admin consent link will be published here when WeekNav opens to Microsoft 365 organizations. If your tenant uses the admin consent workflow, the user's request will reach you there.
Google Workspace
| Scope | Why WeekNav needs it |
|---|---|
openid, email, profile | Sign the user in |
calendar.calendarlist.readonly | List the user's calendars so they can choose which ones WeekNav shows |
calendar.events | Show events and create the time blocks the user schedules or accepts |
If your domain restricts third-party apps, add WeekNav as a trusted app under Security → Access and data control → API controls in the Google Admin console.
How WeekNav handles calendar data
- Reads event titles, times, status and meeting links only; never stores descriptions, attendee lists or attachments.
- Writes only blocks the user creates or explicitly accepts; AI proposals are never written automatically.
- Access tokens are encrypted at rest with a per-workspace key; disconnecting revokes the token at Microsoft or Google and deletes cached events.
- Each account's data is isolated in the database by row-level security.
- Hosted in the United States. Data is not sold, not used for advertising and not used to train AI models. See the Privacy Policy.