Vercel
Security & compliance
Over-permissioned or team-wide integration
Part of the Account supply chain check · fix arrives as a guide
What it is
An installed integration holds broad scopes or is installed across the whole team rather than scoped to specific projects.
Why it matters
The integration can read every project it can reach, including environment variables and deployment logs. One integration installed for one project ends up with access to all of them.
How to fix it
Scope integrations to the projects that need them and review the permissions each requested. Remove any whose access is wider than what it does.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.