Companies, Locations, and Organization - Gusto
Gusto company identity, administrators, locations, departments, notifications, and company-token introspection. Generated from Gusto's complete 2026-06-15 App Integrations reference inventory: every admitted method/path is checked against its own official Markdown-wrapped OpenAPI fragment, with raw page and extracted-contract hashes retained in the audit fixture. A single openapi_source is intentionally omitted because Gusto publishes split per-endpoint fragments whose server is the demo origin; pinning one fragment would falsely claim production-wide coverage. This leaf is isolated to CompanyAccessAuth operations and uses per-company OAuth with rotating refresh tokens; system access tokens cannot authorize it. The X-Gusto-API-Version header is fixed to 2026-06-15. Every documented scope is declared and reads are uncached; sensitive payroll and HR reads are marked sensitive-read and require approval unless session-granted, while ordinary reads remain unheld. Mutations are grant-off and approval-gated, explicit-null and structurally unsafe request bodies fall back to bounded body_raw, and JSON unsafe integers remain exact strings. No work-entity Source is declared because the App Integrations surface exposes no semantically honest task, note, or project entity.
What this pack installs
- gusto-companies-organization Ingredient
Trust & control
What installing this whole pack would let it do. Recued grants these permissions at install — review them there before approving.