Chrome Extension permissions explained

Last updated: July 31, 2026

Kula Everywhere only sees what it needs to do its job — and Chrome, not Kula, is what actually controls and discloses that access. This article explains what the extension can see, what it deliberately can't do, and how your Kula account role factors in.

Who can do this: Any Kula user who sources candidates — typically Recruiters, Hiring Managers, Admins, and Super Admins.

Where to find it: Chrome shows the extension's permissions when you install it from the Chrome Web Store, and you can review or remove them any time from chrome://extensions/


What Kula Everywhere has access to

  • Kula Everywhere is scoped to activate only on specific domains: LinkedIn, GitHub, Gmail, and Kula's own domains. It runs as a native Chrome side panel — not an overlay injected into every page — and it stays closed on every site outside that list. It's on those pages that it reads profile data to parse and enrich candidates, and sends what it captures back to Kula.

  • This is a deliberate scope, not a technical ceiling — broader platform support (for example, sourcing sites beyond LinkedIn, GitHub, and Gmail) has been requested but isn't built yet. If the extension doesn't activate somewhere else, that's expected today.


What it deliberately can't do

  • Chrome, Firefox, and Safari all enforce a hard security boundary that applies to every browser extension, including Kula Everywhere: an extension cannot read the contents of files you've downloaded, upload a downloaded file to an external service, or do either of those without you explicitly picking the file yourself — even if the extension has been granted downloads-related permissions. This is intentional, and it's there to prevent extensions from silently exfiltrating data off your machine.

  • In practice, this is why some extension actions need a manual step from you (for example, manually attaching a downloaded PDF when automatic parsing fails) rather than happening invisibly in the background. It isn't a bug or a missing feature — it's a boundary Kula can't route around, and no browser extension can.


How your Kula role factors in

The extension doesn't have its own, separate permission system. What you can see and do inside Kula Everywhere — which jobs you can add a candidate to, which Flows you can start — follows the same account role you already have in Kula (Recruiter, Hiring Manager, Admin, Super Admin, and so on). There's nothing extra to configure specifically for the extension.


Good to know

  • The extension only activates on LinkedIn, GitHub, Gmail, and Kula's own domains. It stays hidden everywhere else on purpose — this isn't a bug, and other sourcing platforms aren't currently supported.

  • Extensions can't auto-upload your downloads, by browser design. If a workflow needs a downloaded file, you'll be asked to select it yourself — no extension, including Kula Everywhere, can bypass this.

  • There's no separate "extension permission" to grant or manage inside Kula. Access follows your existing account role.

  • A "No ATS Found" message is not a permissions error. It means the extension can't tell which Kula account you're connected to — see Installing the Kula Chrome Extension for how to fix it.

FAQ

  • What does Kula Everywhere actually have access to? It activates only on LinkedIn, GitHub, Gmail, and Kula's own domains, where it reads and parses candidate profile data. It stays inactive everywhere else.

  • Why does the extension only work on LinkedIn, GitHub, and Gmail? That's the current supported scope by design. Broader platform support has been requested but isn't built yet.

  • Can the extension automatically read or upload files I've downloaded? No — this is a security boundary every browser enforces for every extension, not something specific to Kula. Downloaded files always require you to select them manually.

  • Do I need a special role or extra permission to use the extension? No — the extension follows the same account role you already have in Kula. There's nothing separate to set up.

  • The extension says "No ATS Found" — is that a permissions problem? No, it means the extension can't identify which Kula account you're connected to. For more, see Installing the Kula Chrome Extension

Need help?

If you have questions or need assistance, reach out to us at support@kula.ai or use the in-app chat.