Microsoft Copilot security directory
Harvest
Published by Microsoft
High risk
Harvest is a simple tool to help track the time spent by your team on each project and task.
Security assessment
Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
- Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
- Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.
Available capabilities
This add-on exposes 13 tools or capabilities.
- Add new client
- Add new contact
- Add new user
- Add user to a project
- Create time entry
- Delete time entry
- Get time entry by id
- Get user info
- List all clients
- List all contacts
- List projects
- List tasks
- Update time entry
The interactive security report will load automatically.