Microsoft Copilot security directory
Coupa (Independent Publisher)
Published by NovaGL
High risk
Coupa P2P connector — 162 operations. No Authentication — Bearer token passed via Access-Token header, rewritten to Authorization by policy. Dynamic host via connection parameter.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Can spend money on your behalf: This connector can initiate charges, orders, or subscriptions. An AI executing these actions could trigger unauthorized financial transactions.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 152 tools or capabilities.
- Account: Get All
- Account: Get by ID
- Address: Get All
- Address: Get by ID
- Approval: Get All
- Approval: Get by ID
- Budget Line: Get All
- Budget Line: Get by ID
- Commodity: Get All
- Commodity: Get by ID
- Contract: Add Approver
- Contract: Complete
- Contract: Create and Publish
- Contract: Create Term
- Contract: Get All
- Contract: Get Attachments
- Contract: Get by ID
- Contract: Get Term by ID
- Contract: Get Terms
- Contract: Post Attachment (Text or URL)
- Contract: Remove Approver
- Contract: Submit for Approval
- Contract: Update Term
- Data Source: Get All
The interactive security report will load automatically.