gloss

For school IT teams

Gloss is a planner app for university students. A student signs in with their school Google or Microsoft account so Gloss can find deadlines and schedule changes in their email. This page has what you need to decide whether to allow it.

Gloss is published by Standby Ops LLC (District of Columbia). It is not affiliated with any university. Questions: [email protected]. Security reports: [email protected].

What Gloss accesses

Exact scopes

ProviderScopeWhy
Googlehttps://www.googleapis.com/auth/gmail.readonlyRead messages to find deadlines, exam changes and events
Googleopenid, emailKnow which school address was connected
Microsoft GraphMail.Read (delegated)Read messages to find deadlines, exam changes and events
Microsoftoffline_access, openid, emailKeep syncing without asking the student to sign in every hour; know which address was connected

Sign in to the Gloss account itself (Sign in with Apple, Google sign in, or an email code) is separate and asks only for basic profile information. Google's review of Gloss's Gmail access, including the independent CASA security assessment, is in progress; until it passes, Gmail connections are limited to 100 students in total.

How Gloss handles the data

Full details: privacy policy (draft for legal review), vendors that receive student data, security.

Google Workspace: approve or block Gloss

In the Google Admin console, go to Security, then Access and data control, then API controls, then Manage App Access (older consoles say Manage Third-Party App Access).

  1. Under Configured apps, click Configure new app and search for Gloss or for Gloss's OAuth client ID (listed below once Google's review is complete).
  2. Pick the organizational units it applies to.
  3. Choose the access level:
    • Specific Google data with gmail.readonly plus the sign in scopes (openid, email): allows exactly what Gloss needs. Recommended.
    • Trusted: allows Gloss, including restricted services.
    • Blocked: Gloss can't access any Google data for those users.

If your domain uses Don't allow users to access any third-party apps for unconfigured apps, or marks Gmail as a restricted service, students see "Your school needs to approve Gloss" until Gloss is configured as above. Workspace for Education domains can set different rules for users designated under 18. Google's guide: Control which apps access Google Workspace data.

Microsoft Entra: approve or block Gloss

Many tenants, including every tenant on Microsoft's managed default consent settings, don't let students consent to Mail.Read themselves. Those students see a request for admin approval. To approve Gloss for your tenant:

  1. Open the admin consent link below as a Privileged Role Administrator, Cloud Application Administrator or Application Administrator, or approve the student's request in Enterprise applications, then Admin consent requests.
  2. Review the permissions (Mail.Read, offline_access, openid, email) and accept for your organization.
  3. Optional: restrict to specific students under Enterprise applications, Gloss, Properties, Assignment required.

Admin consent link (shape; the client ID is filled in when Microsoft publisher verification completes):

https://login.microsoftonline.com/organizations/v2.0/adminconsent?client_id=01e691ed-477b-4041-bdc3-387cabc792e8&scope=https://graph.microsoft.com/Mail.Read offline_access openid email&redirect_uri=https://joingloss.app/it/consented/

To block Gloss: Enterprise applications, Gloss, Properties, set Enabled for users to sign-in? to No. This stops all tokens being issued to Gloss in your tenant. Microsoft's guides: Grant tenant-wide admin consent and Disable user sign-in for an application.

Without email access

If you don't approve Gloss, students can still use it with their course site calendar link, their class schedule and their syllabi. Nothing in Gloss requires email access.

Contact

For questions, a security questionnaire or a data processing agreement, email [email protected]. To report a vulnerability, see Security.