Skip to content

Choose what an AI tool can reach

It uses your access, and you can narrow that further.

How far an AI tool can reach An AI tool starts from everything you can open, never workspaces where you're a guest. An app that signs in is narrowed to the workspaces you ticked, or to every workspace, now and later, with Also workspaces I join later; its access is Read and suggest changes, or Read only. A key can optionally be kept to chosen folders and the folders within them, which keeps it to one workspace; left empty, it reaches every workspace you belong to. Its access is Read and propose edits, or Read only, and its lifetime is Never expires, or 7 days to a year. For both: Read only reads and searches and changes nothing, and suggested edits wait for review by default. An app that signs inA key Everything you can open never workspaces where you're a guest Workspaces you ticked or every workspace, now and later, with Also workspaces I join later Access Read and suggest changes or Read only Only these folders Optional, with the folders within them With folders picked: one workspace Left empty: every workspace you belong to Access Read and propose edits or Read only Lifetime Never expires or 7 days to a year Read only: reads and searches, changes nothing. Suggested edits wait for review by default. How far an AI tool can reach An AI tool starts from everything you can open, never workspaces where you're a guest. An app that signs in is narrowed to the workspaces you ticked, or to every workspace, now and later, with Also workspaces I join later; its access is Read and suggest changes, or Read only. A key can optionally be kept to chosen folders and the folders within them, which keeps it to one workspace; left empty, it reaches every workspace you belong to. Its access is Read and propose edits, or Read only, and its lifetime is Never expires, or 7 days to a year. For both: Read only reads and searches and changes nothing, and suggested edits wait for review by default. An app that signs inA key Everything you can open never workspaces where you're a guest Workspaces you ticked or every workspace, now and later, with Also workspaces I join later Access Read and suggest changes or Read only Only these folders Optional, with the folders within them With folders picked: one workspace Left empty: every workspace you belong to Access Read and propose edits or Read only Lifetime Never expires or 7 days to a year Read only: reads and searches, changes nothing. Suggested edits wait for review by default.
An AI tool starts from your access and can only be narrowed from there.

When an app signs in through your browser, Stuga shows an approval page with the app’s name.

  • Under the heading, Verified by names the host Stuga used to check the app’s identity. Unverified app means the app’s identity has not been checked that way; check the address it will return to, and choose Deny if you don’t recognize it.
  • Workspaces lists the workspaces where you are not a guest, all ticked. Untick any the app shouldn’t use, or tick Also workspaces I join later to let it use every workspace you belong to, now and later.
  • Access is Read and suggest changes or Read only. Edits to document text and databases wait for review by default, unless the item is set to Let AI edits apply directly.

Choose Allow to connect, or Deny to refuse. Your answers hold until the app signs in again, when the page asks afresh.

Some setups use a key instead, a long secret the app keeps. Before you choose Create key:

  • Access: Read and propose edits, or Read only.
  • Lifetime: Never expires, or an end date from Expires in 7 days to Expires in a year.
  • Only these folders (empty = everything you can reach): pick folders to keep the AI tool inside them and the folders within them. Everywhere else, documents look to it as if they don’t exist. Leave it empty for everything you can reach.

A key that isn’t kept to folders reaches every workspace you belong to. One kept to folders reaches only the workspace you created it in.

The key is shown once. Copy it, or the setup it’s in, straight away.

Connected agents, under Settings → Your AI agents, lists every app that signed in and every key you created. A badge shows where one reaches less than you do: Read-only, the workspaces it may use, the number of folders, or when it expires.

  • Rename changes the name its changes carry.
  • Rotate, for a key, gives it a new secret. The old one stops working at once.
  • Revoke ends its access.
  • An AI tool never acts in a workspace where you’re a guest, whatever you ticked.
  • If you leave a workspace, every connection loses it.
  • A read-only AI tool can read and search, and changes nothing.