Why Arrange's Calendar Connection Permissions Look Broader Than Expected
Written By Brian Gabay
Last updated 2 days ago
Any time a calendar is connected to Arrange, whether it's your own Google or Microsoft 365 calendar synced for scheduling, or a client/hiring manager’s calendar connected through Arrange Connect, the permission screen shown during setup can look more expansive than what Arrange actually uses. This is common, and it usually comes down to how Google and Microsoft structure their permission systems, not anything specific to how a particular connection is set up. Here's what's actually happening.
What Arrange actually does with calendar access
When a calendar is connected, Arrange reads existing events only to determine free versus busy time blocks. That gets matched against the availability preferences that were set, and only open time options are ever shown to whoever is scheduling, never event titles, attendees, or any other calendar content. Once a time is confirmed, Arrange writes the interview onto that calendar. That's the full extent of what happens, regardless of whose calendar it is or which part of Arrange triggered the connection.
Why the Google permission screen can look broad
Google's Calendar API has multiple permission levels, and they carry different consent language. A narrow "view your availability" scope exists specifically for free/busy checking, but because Arrange also needs to write the confirmed interview back to the calendar, Google shows calendar access in broader terms on the consent screen, even though nothing beyond availability and the interviews Arrange creates is ever touched. Separately, Google also asks for a basic "see your email address" permission on almost any connection. That's just account identification, confirming which account is connecting, not access to anyone's inbox content.
Why the Microsoft 365 permission screen can require admin approval
For Microsoft 365 connections, it helps to understand the difference between two permission types:
Delegated permissions mean the app can only act as the specific person who authorized it, and only to the extent that person could already do themselves. This is what Arrange uses. If someone connects their calendar, Arrange can see and touch what that person has access to, nothing more.
Application permissions mean an app has its own standing identity, separate from any signed-in user, and can act across an entire organization on its own. Arrange does not use this type of access.
Many organizations, particularly ones with stricter security policies, turn off the ability for individual users to approve third-party apps on their own. When that's the case, an IT administrator has to approve the app before anyone in the organization can use it, even when the permissions being requested are delegated and scoped to just the one connecting user. Admin approval alone doesn't mean broader access was requested, it usually just reflects that organization's consent settings.
How your IT team can verify this
For Microsoft 365, an administrator can check the exact permission type directly in the Microsoft Entra admin center: Enterprise apps → Arrange → Security → Permissions. This will show whether the permissions are delegated or application level, independent of anything Arrange says about it.
If something still looks off
If your organization's IT team reviews the permissions and still has concerns, reach out to Arrange support with details on what they're seeing. We're happy to look into it directly, and if needed, escalate with Microsoft or Google using the relevant application details.