Vercel Security & compliance

Over-permissioned or team-wide integration

Part of the Account supply chain check · fix arrives as a guide

What it is

An installed integration holds broad scopes or is installed across the whole team rather than scoped to specific projects.

Why it matters

The integration can read every project it can reach, including environment variables and deployment logs. One integration installed for one project ends up with access to all of them.

How to fix it

Scope integrations to the projects that need them and review the permissions each requested. Remove any whose access is wider than what it does.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.