Hub Widget and Events Permissions

Prev Next

Thrive integrates with third-party tools to bring calendar, email, and task functionality directly into the platform. These integrations are used across Hub Widgets (personal productivity widgets that display a user's inbox, calendar, and tasks in their Hub dashboard) and Events (a collaborative feature for creating and managing events, synced with users' calendars).

Each integration is a separate, opt-in connection. Users choose exactly which services to connect, and Thrive only requests the permissions needed for that specific connection. A user who only wants to view their calendar will never be prompted for email permissions, and vice versa.

Note:

This page uses plain language permission names. For the exact Microsoft Graph permission names, see Microsoft Integration Permissions.

Hub Widgets

Hub Widgets give users a unified dashboard view of their email and calendar without leaving the platform. Each widget is connected independently.

Email Widget (Gmail/Outlook)

Permission

Purpose

Mail Read

Fetch and display email messages in the inbox widget

Channel/Folder Read

List available mailboxes (e.g. Inbox)

  • Read-only: Hub cannot send, delete, modify, or move emails.

  • Only requested if the user chooses to connect their email.

Calendar Widget (Google Calendar/Outlook Calendar)

Permission

Purpose

Calendar Read

List the user's calendars

Calendar Write

Create a calendar if the Events feature needs one

Event Read

Display upcoming events

Event Write

Create and edit events when the Events feature is used

Free/Busy Read

Show availability status

  • Read and write: Connecting a calendar grants Thrive read and write access to that calendar. The widget itself only displays your events. Write access is requested when you connect, so that the Events feature can create and manage calendar entries without asking you to approve a second time.

  • Only requested if the user chooses to connect their calendar.

Teams Calendar Widget (Microsoft Teams)

Permission

Purpose

Calendar Read and Write

List calendars and display Teams meetings

Event Read and Write

Display meetings, and create them when Events is used

Free/Busy Read

Show availability status

Teams Messages Widget (Microsoft Teams)

Permission

Purpose

Channel Read

List the teams and channels the user belongs to

Message Read

Display recent chat and channel messages

User Profile Read

Show the name and photo of who sent each message, and identify your own messages

  • Read-only: Hub cannot send Teams messages.

Tasks Widget (Jira/Linear)

The Tasks widget displays a live summary of a user's tasks from a connected tool. An admin connects the tool in integration settings, then each user authenticates their own account. One task provider can be connected per instance.

Note:

Task connectors are a paid add-on. To enable one, or to request a connector not currently included in your Hub, speak to your Account Director.

Permission

Purpose

Task Read

Read task name, status, priority, due dates, and tags

Project Read

List the projects or boards the user has access to

  • Read-only: Hub displays tasks but cannot create, edit, or delete them.

  • Only requested if the user chooses to connect their task tool.

Time Off Widget (BambooHR)

The Time Off widget shows a user's leave balance and upcoming requests from BambooHR, and, where an admin has switched on booking, lets them submit new time off requests without leaving Thrive.

Note:

Unlike the widgets above, this isn't controlled purely by OAuth scopes requested at connection. An admin connects the organisation's BambooHR account first; each user then connects their own account. Whether a user can book time off from Hub depends on their own permissions in BambooHR, not just a Thrive-side setting.

Permission

Purpose

View Time Off

Read the user's leave balance, scheduled leave, and the status of their time off requests

Book Time Off

Submit a new time off request – only available once an admin has switched on booking, and only if the user's BambooHR permissions allow it

  • Read-only until booking is switched on: Until an admin turns on booking, the widget only displays leave information and can't submit requests.

  • Booking also depends on BambooHR permissions: Even with booking switched on in Thrive, a user can only book time off if their BambooHR access level grants Edit permission for their Time Off categories. See the BambooHR setup guide for details.

  • BambooHR only: This widget doesn't support other HR platforms.

  • Only requested if the user chooses to connect their BambooHR account.

Events

The Events feature allows users to create, manage, and sync events with their connected calendars. Events uses the same calendar connection as the calendar widget, so no additional approval is needed if a user has already connected their calendar.

Events (Google Calendar/Outlook Calendar)

Permission

Purpose

Calendar Read

List available calendars to sync with

Calendar Write

Create new calendars if needed

Event Read

Display existing events

Event Write

Create and edit events from within Hub

Free/Busy Read

Show availability status

  • Read and write: Events creates and manages calendar entries on the user's behalf, so it needs write access.

Key Takeaways

  • Email access is strictly read-only: Thrive displays emails but cannot send, modify, or delete them.

  • Mail Read is only ever requested for the Email Widget: It is never part of calendar or Events permissions.

  • Each widget is approved separately: Connecting your calendar and connecting your email are two separate approvals. If you connect only your calendar, you are never asked for access to your email.

  • Calendar connections include write access: The calendar widget only displays events, but the connection grants read and write so that the Events feature works without a second approval.

  • Users are always in control: Each integration is a separate connection, and only the permissions relevant to that feature are requested. No blanket permissions are applied.

  • Task connectors are separate and read-only: Each user authenticates their own task tool, and Hub only reads task data. It cannot modify it.

Note:

Last checked against the Thrive Hub app registrations: 17 August 2026