Settings, connections
Connect Xero
A Xero login can reach several organisations. ChurnRisk reads only the ones selected here.
What ChurnRisk asks for
Every permission below is read-only, and each one is used by a feature that ships today.
offline_accessRefreshes the access token so scheduled reconciliation keeps running without asking the tenant to reconnect.accounting.contacts.readReads contacts, which are the canonical customer candidates for the identity graph.accounting.transactions.readReads invoices with their line items, payments, credit notes, and quotes, which carry cadence, value, product family, and quote conversion.accounting.settings.readReads the item catalogue, which is what maps a line item to a product family.
ChurnRisk never asks for permission to change anything in Xero.
Choose organisations
Authorization
Selecting organisations records what ChurnRisk may read. Granting access happens at Xero, on https://login.xero.com/identity/connect/authorize, with the scope string offline_access accounting.contacts.read accounting.transactions.read accounting.settings.read.
The Xero app credential is held outside this repository, so consent stops here (BUILD/DEFERRED.md, p11).