Privacy & permissions
What Agile Gauge can see in your Azure DevOps organization, what it can't, and where your data actually goes.
The three permissions it requests
Agile Gauge asks for exactly three scopes when it's installed, all of them read-only:
| Scope | What it's for |
|---|---|
vso.project | Reading project metadata, for the project picker. |
vso.work | Reading teams, sprints/iterations, work items and their history — what every view is built from. |
vso.graph | Looking up team members' identities, used specifically by Sprint Capacity to match capacity settings to people. |
No write permission is requested at all. Agile Gauge cannot create, update or delete anything in your Azure DevOps organization.
Where your data is actually read
Agile Gauge runs entirely inside your own browser, as a tab inside Azure Boards. It reads directly from your own Azure DevOps organization using the permissions above, and every view is rendered in that same browser session. Your work item content is not copied into a database we operate — there is no server of ours sitting in between you and your own Azure DevOps data for the numbers you see.
A small, separate connection does exist for account-level functions unrelated to your work item content — such as checking subscription status once licensing opens, and limited technical usage/error information used to keep the product working. That connection is deliberately restricted to a fixed, small set of fields; your work items, sprint names, and their content are never part of it.
An in-product "Data & Privacy" summary screen is not currently part of the extension. This page describes the actual, current permissions and architecture; it isn't describing a screen you can open inside Agile Gauge today.
Because everything renders in your own browser against your own Azure DevOps, a support request about incorrect-looking numbers needs a description and, ideally, a screenshot — we don't have a copy of your data to look at on our end. See Support.