Concepts and referenceWhat an agent can see

What an agent can see

How Brain decides what a connected assistant can see and do, what leaves Brain in a tool result, and how agent accounts differ.

An assistant connected to GuruSup Brain does not have its own view of your organization's memory. It sees what the account it signed in with is allowed to see, and nothing more.

Access follows the signed-in account

When you connect your assistant, you sign in to Brain in your browser (see Setup and authentication). From then on, every request the assistant makes carries your organization, your account and your role. One connection is one person in one organization.

That has three consequences.

  • Two people with the same assistant can get different answers. Each sees what their own account allows.
  • The assistant cannot see more than you can. Changing assistants does not widen access.
  • Brain does not show you what you cannot see. If nothing you are allowed to see answers the question, the assistant is told to say that it could not find anything, not to guess. See Sources and citations.

Access is set by knowledge categories, the same ones admins use for people under Team. Skills follow the same rule: the assistant lists only skills whose categories you can access. See Skills.

What happens when access is denied

What the code shows:

  • Nothing matches, or nothing is retrievable for you. Brain's answer carries an internal note that no authorized memory was available for your account. The assistant is told not to pass internal notes, gaps or confidence on, so what you normally read is that it found nothing. Brain does not show you what you cannot see.
  • Your access changed during a question. The request fails with "Knowledge access changed while processing this request. Please retry." Ask again. See MCP troubleshooting.
  • You publish a skill for categories you cannot access. Brain refuses it and says "Cannot publish a skill for knowledge categories you cannot access."
  • The memory is not built yet. Questions stop with "Brain is still building your memory. You can search it once the build finishes."

Who can do what

ActionWho
Ask, search, open pagesAny member, within their categories
Use skillsAny member, for skills in their categories
Save knowledgeAny member. The assistant is told to do it only after you ask or confirm.
Submit a skillAny member. The skill waits for an admin to approve it.
Ask a person for missing informationAny member. The assistant previews the contact first. Only contacts an admin set up can be asked.
Report a problem or send feedbackAny member, through the assistant. It records a note for the GuruSup team and changes nothing in Brain.
Approve a skill, review questions under Queries, manage Team, build the memoryAdmins

No tool edits or deletes knowledge that is already saved. Knowledge saved through an assistant cannot be edited or removed from the app afterwards.

What leaves Brain

Brain sends the assistant only what its tools return, and the assistant's provider then handles that content under its own terms. Depending on the tool, a result contains:

  • excerpts from pages of Brain's memory, the facts behind them, and each page's title and link (ask_company_memory, search_company_memory, retrieve_company_memory),
  • the full text of a skill you can use (skills_get) and the list of skills you can use (init),
  • the name of the contact Brain would ask, and the channel, when a preview runs (request_human_info),
  • your email and an opaque profile ID (get_profile).

Brain also receives what the assistant sends: your question, anything it saves, and the text of a report or feedback. Reports include your organization and account, what the assistant wrote, and the name and version of the assistant app. See Tools reference.

What changes for admins and members

Anyone in the organization can use Brain through an assistant. Some things stay with admins, whatever assistant is used. The full role list is in Roles.

Agent accounts

Agent accounts are for software that calls Brain directly, such as an internal script or service. They are not how you connect an assistant like Claude or ChatGPT. Connecting an assistant through MCP uses the browser sign-in described in Setup and authentication.

An agent account is a machine account, not a person. Admins create and manage them under Team, in the Agents section. Members do not see Team.

An agent account:

  • has a name and an email. The email cannot already be used by another account, or Brain shows "That email already belongs to another account.",
  • is always a Member, never an admin,
  • gets its own knowledge categories, set the same way as for people,
  • uses API keys instead of signing in,
  • uses one seat, like a person.

For the steps to create one, manage its keys and delete it, see Agent accounts.

Because an agent account is always a Member, it can never manage Team or approve skills, and it reads only the categories you pick. Give each agent only the categories it needs, and revoke a key you think has leaked.

If Brain says agent accounts are not enabled for your organization, contact support.

Next step

To connect your own assistant, go to Setup and authentication.