Integrations / Governance
Tool and group ceilings
How credential ceilings and scoped rules work together — and what Governance Groups does not create.
Ceiling
Scoped rules
Two layers
Ceiling first, then scope
Layer 1 — Credential ceiling
The hard max for one connected credential. Tools tab: which tools the credential may ever invoke. Groups tab: which provider groups (from OAuth discovery) it may ever see. Nothing outside the ceiling can be granted later.
Layer 2 — Scoped rules
Narrower grants for a team, project, user, or role. Must be a subset of the ceiling. If no scoped rule exists, that scope inherits the ceiling.
Tools vs Groups
Same pattern, different resource
- Tools — restrict which MCP / integration actions a credential can call, then assign subsets per scope.
- Groups — choose which groups the provider already has (GitLab groups, Slack workspaces, etc.). Telara does not create those groups here. Telara org units are under Teams.
Discovery
When no groups appear
Group lists come from OAuth discovery on the credential. If Governance shows “No groups found,” re-authorize the credential so Telara can refresh the discovered set, then use Choose groups / Edit groups on the policy card.



