The calendar subscribe URL for your pipeline is a capability link. Possession is permission — anyone holding it can read the titles and deadlines of everything you have saved, with no login.
This is not a flaw. Every calendar subscription on every platform works this way, because calendar clients cannot log in on your behalf. It just means the URL needs handling like a password.
Why it matters here
Your pipeline is competitive information. It shows what your organization is going after, what stage each pursuit is at, and when. For a business bidding on contracts, that is genuinely sensitive.
Where these leak
In roughly this order:
- Pasted into a shared Google Doc or Notion page
- Attached to a support ticket or bug report
- Sent in a group chat so a colleague can subscribe too
- Included in a screenshot of a calendar settings screen
- Left in a browser session on a shared machine
If it leaks, rotate it
You can rotate the calendar token. This revokes the existing URL immediately and issues a new one.
Anyone still subscribed to the old URL stops receiving updates — including you, on your own devices. After rotating you need to re-subscribe everywhere you had it.
That inconvenience is the point: revocation is real rather than cosmetic.
Good practice
Do not share one URL across a team. If several people need the deadlines, put them on a shared team calendar that you control, and keep the OpenGrants feed on one account.
Rotate when someone leaves. A departing colleague’s subscribed calendar keeps working otherwise.
Rotate if you are unsure. It costs a re-subscribe and nothing else.