OAuth scopes control access at a granular level. They tell an application which parts of a user’s profile, account, or stored data it can touch. Managing these scopes well is not optional when handling personally identifiable information. PII data includes names, emails, phone numbers, addresses, ID numbers—anything that