Skip to content
Changelog

Report a bug

Permissions and Access

A Space controls who can find and join an area of work. The items and tools used inside it can have their own, narrower permissions.

AccessWho can find and join
Public SpaceAnyone in the workspace
Private SpaceOnly people who have been added
SidekickOnly its owner

Change a Space’s visibility and membership in Space settings → Details.

Channels use the access rules of their Space. They organize work, but do not create a separate permission boundary.

Most threads are available to people who can access their Space. A private thread can be limited to its participants, even inside a public Space.

Documents and apps have their own sharing controls. A single item can be available in the global Library and shared with specific people, private Spaces, the workspace, or through a public link when that option is allowed.

The Space where an item was created is useful context, but it is not the only thing that determines access.

A connector is a supported integration, such as GitHub or Google Drive. A connection is the specific account or credential configured through it.

Adding a connection to the workspace does not give every Space access to it. Assign each connection only where it is needed, and remember that the connected service may enforce its own permissions too.

AI acts with the effective access available to the person and conversation that started the work. It does not gain broader access simply because a tool is connected elsewhere in the workspace.

Keep sensitive access narrow:

  • Add only the connections a Space needs.
  • Keep secrets out of prompts, instructions, and thread messages.
  • Use a private Space, private thread, or Sidekick for sensitive work.
  • Review access before merging Spaces.