Skip to main content
Telara

Integrations / Governance

Tool and group ceilings

How credential ceilings and scoped rules work together — and what Governance Groups does not create.

Ceiling
Scoped rules

Two layers

Ceiling first, then scope

Layer 1 — Credential ceiling

The hard max for one connected credential. Tools tab: which tools the credential may ever invoke. Groups tab: which provider groups (from OAuth discovery) it may ever see. Nothing outside the ceiling can be granted later.

Layer 2 — Scoped rules

Narrower grants for a team, project, user, or role. Must be a subset of the ceiling. If no scoped rule exists, that scope inherits the ceiling.

Tools vs Groups

Same pattern, different resource

  • Tools — restrict which MCP / integration actions a credential can call, then assign subsets per scope.
  • Groups — choose which groups the provider already has (GitLab groups, Slack workspaces, etc.). Telara does not create those groups here. Telara org units are under Teams.

Discovery

When no groups appear

Group lists come from OAuth discovery on the credential. If Governance shows “No groups found,” re-authorize the credential so Telara can refresh the discovered set, then use Choose groups / Edit groups on the policy card.