Security and privacyPermissions model

Permissions model

How roles and categories control what people and agents can see in GuruSup Brain, and what categories do not do.

Roles

Brain has two roles: admin and member.

RoleKnowledge access
AdminReaches every category while the account is active
MemberReaches only the categories an admin has granted to that person

Categories

Brain sorts what it learns into categories that match business functions. There are eleven: general, marketing, sales, finance, product, engineering, operations, customers, hr, legal and leadership. When Brain answers a question, it only uses knowledge from categories the asker can reach.

An admin grants a member access to a category from the Team page. A category that has no content yet starts closed to members when its first page arrives.

Agent accounts

Agent accounts are machine accounts that use a static API key. Their knowledge access is set by the same categories as people. An admin chooses which categories each agent account can reach.

What categories do not do

  • They are business-function groups, not walls between individual people.
  • Brain does not copy permissions from your source apps. If a page in Notion or a channel in Slack has its own access rules, Brain does not read or apply them. What matters is which pages you share and which channels the app has joined. See Connectors and scopes.