This option controls what permissions are available to the access tokens generated when using these credentials in untrusted contexts. For example, this setting is used when the credentials are bound in a Pipeline job using the withCredentials step.

In other contexts, such as organization folder scans, multibranch project branch indexing, and GitHub commit status updates, this setting is ignored.