Pulse reads Asana. It never writes back, creates tasks or changes status.
Security & data
Built to be trusted with your Asana.
Pulse reads delivery data to do its job, so how it handles that data is part of the product — not an afterthought. Here is exactly what it asks for and how it is kept.
Principles Read-only Least-privilege Server-side Tenant-isolated
Trust is a product feature, not a setting.
Six read scopes, and no more. No write scopes are ever requested.
Access tokens are encrypted and held server-side. They never reach the browser.
Every customer’s data is scoped to their tenant, resolved on the server.
Signing in
- Sign-in is through Google Workspace (OpenID Connect), restricted to your organisation’s domain.
- There is no public sign-up. Unknown accounts are not created automatically.
- Sessions are opaque and server-side; only a hash of the session token is stored.
- The session cookie is Secure, HttpOnly, SameSite and uses the __Host- prefix.
Connecting Asana
- Authorisation uses the OAuth authorisation-code flow with PKCE and one-time state.
- The six scopes requested are read-only: workspaces, portfolios, projects, tasks, users and teams.
- Tokens are stored encrypted and used only server-side.
- You choose which teams, portfolios and projects are in scope — Pulse reads only those.
How your data is handled
- Pulse reads native Asana fields — dates, status, milestones, dependencies, owners and assignees.
- It does not require or read custom fields to be useful.
- Missing, stale or ambiguous data is shown as such. Pulse does not infer certainty Asana doesn’t provide.
- When the source data is stale, current-action suggestions are held back rather than presented as fresh.
What Pulse never does
- Write anything back into Asana.
- Request write or admin scopes.
- Invent a score, date or status the data doesn’t support.
- Mix one organisation’s data with another’s.
Early access
Questions before you connect?
If your security team needs detail beyond this page, ask us directly — we’d rather answer than gloss over it.
Read-only Asana access · no pricing commitment · pre-release