Xero - Access & permissions
Elevale uses OAuth 2.0 to read metrics from Xero. Elevale does not modify data in the external system. Tokens and keys are encrypted server-side after validation.
Who can connect
Workspace admins and users with permission to manage Workspace Settings integrations.
Connections are managed from Workspace Settings → Integrations.
Requires [Business+] on your workspace plan.
What Elevale accesses
Read-only metrics exposed as KPI data points (see the Data points article).
Connection metadata (account IDs, property IDs, organisation tenants) needed for sync.
No write access to campaigns, repositories, accounting records, or CRM objects unless the provider API requires it for authentication only.
OAuth scopes
accounting.reports.read profit & loss and balance sheet reports.
accounting.transactions.read transactional detail where needed.
accounting.contacts.read contact-related metrics.
offline_access refresh tokens for scheduled syncs.
Disconnect and data retention
Disconnect from Workspace Settings → Integrations to revoke stored credentials and stop scheduled syncs.
Previously synced KPI history remains until you delete or convert those KPIs.
Subprocessors and data handling: Subprocessors and integrations