CASA Certificate Justification

Restricted Scopes

Pucho.ai is an agentic AI automation platform where users build workflows ("agents") using Gmail, Drive, and Sheets integrations. To enable user-defined automations, Pucho requires specific restricted scopes:
gmail.readonly: Lets agents extract emails like OTPs or leads for CRM logging or triggers, without modifying inbox content.
gmail.compose: Enables sending AI-personalized replies or confirmations based on user-defined events; inbox access is not granted.
drive: Required to create, update, or organize files (e.g., AI-generated reports or PDF uploads).
drive.readonly: Used for reading spreadsheet data or checking files to trigger logic without editing them.
Scopes are activated only per workflow step. No data is accessed unless a user configures it. All actions are logged, OAuth tokens are encrypted, and Pucho aligns with CASA and GDPR standards.

Sensitive Scopes

Pucho.ai lets users build AI-driven agents for workflow automation using Google apps. Sensitive scopes are required only when a user adds related steps.
gmail.send: Sends emails like confirmations or AI-written replies. Inbox access is not requested.
calendar.events & calendar.readonly: Used to read, create, or sync events (e.g., auto-schedule meetings).
contacts: Adds leads or clients to Google Contacts from form or CRM data.
spreadsheets, documents, presentations, forms.responses.readonly: Read/write Docs, Slides, Sheets, or Form data during automation.
tasks: Manage reminders or to-dos tied to workflows.
youtube, youtube.readonly, youtube.upload: Manage uploads or metadata for content workflows.
All scopes are user-triggered, encrypted, and CASA/GDPR-aligned.
Want to print your doc?
This is not the way.
Try clicking the ⋯ next to your doc name or using a keyboard shortcut (
CtrlP
) instead.