Concepts
Access scope
The tables, folders, tools, and apps this worker is allowed to read and act on — nothing else.
What a access scope is
Workers don’t get vague access to everything. You grant each one exactly the data and apps its job needs — like keys on a keyring. Who can see or edit the worker itself is separate: that’s sharing, behind the Share button.
For example
The triage agent reads the support folder and writes to the Tickets table — payroll doesn’t exist as far as it knows.
Reach for it when
- You are creating an agent and deciding what it may read and write.
- An agent should work the tickets table but never see payroll.
- A function needs exactly one external app operation, no more.
Scope like you mean it
- In the agent editor, open the Access section and click Manage.
- Grant specific tables, folders, tools, and apps — start from nothing and add.
- Re-check the scope when the agent’s job changes; scopes should follow the job.
Where it lives
The Access section in each agent’s editor.
Related concepts
| Concept | In short |
|---|---|
| Agent | An AI worker with a role, instructions, and scoped access to your tables, files, and apps. |
| Function | Deterministic code for steps that shouldn’t be AI judgment: validation, math, formatting. |
| Table | Typed business data the pod reads and writes — leads, tickets, tasks — with per-row security. |
| Sharing | Who can see and use a resource: private, pod members, or the whole organization. |