Integrations
Trust model
Integrations on WePeople are designed for engineering leads who need shared signal — not surveillance. Every connector publishes what we read, what we refuse to read, and how secrets and access are handled.
Read / do-not-read
WePeople ingests structured metadata from connected tools: timestamps, event types, counts, and identifiers needed to attribute activity to monitored workers. We do not install endpoint agents, capture keystrokes, or scrape content pages.
The default rule: if a data type is not listed in our connector docs or marketing read matrices, we do not request the OAuth scope or API field that would expose it.
By connector
High-level summary — detail lives in each integration guide:
Slack
Read: presence (active / away), message and reaction event timestamps, channel IDs for selected public channels. Never: message bodies, DMs, private channel content, files.
GitHub
Read: commit timestamps, line add/delete counts, PR lifecycle and review events. Never: source code, diffs, commit message bodies, review comment text.
Jira
Read: issue lifecycle transitions, story points on completed work, issue keys, assignee IDs (mapped workers). Never: descriptions, comments, custom fields, attachments.
Encryption
Integration OAuth tokens and secrets are encrypted at rest with AES-256-GCM. Data in transit uses TLS. APIs and UI expose hasToken indicators — never raw secrets.
Rotating the deployment encryption key invalidates stored tokens; organizations must reconnect affected integrations. Disconnecting a module deletes its encrypted credentials immediately.
Role-based access
Organization roles — Viewer, Member, Admin, and Owner — control who can connect integrations, manage channel and repo scope, invite members, and change retention. Permissions are tunable under Organization → Permissions.
- Connect / disconnect integrations — typically Admin or Owner.
- View monitoring and reports — all roles (same surfaces for ICs and leads).
- Developer apps & API keys — scoped separately; see developer platform.
Privacy & deletion
Retention windows depend on your plan — activity and events are deleted after the configured period, not archived indefinitely by default. Organization Owners can delete the org; end-user deletion follows published procedures.
- Privacy model — product documentation.
- Privacy policy — legal disclosure and contact for requests.
- Billing & retention — plan-based history limits.
- Integrations hub — security bullets and connector marketplace.