A clear boundary
around your work.

Choose who joins a workspace, what each connected agent can do, and which provider accounts it can use.

On this page

Workspaces define the boundary.

A workspace has owners, admins, and members. Server-side checks resolve current membership for the web app, MCP tools, and background operations. Belonging to one workspace does not grant access to another.

Invite only the people who should have access to that workspace. Resources and connected accounts are shared within the workspace according to the application’s permissions.

Signing in is not agent authorization.

Each agent connection requires a separate authorization. Choose a workspace, all or selected projects, permitted actions, connected provider accounts, and an expiry. A browser login alone does not give an MCP client access.

  • Read context without granting editing access.
  • Allow suggestions for human review without direct write permissions.
  • Grant task, resource, schedule, or file operations only when needed.
  • Reconnect and consent again to increase permissions.

Review and direct editing are different permissions.

An agent with permission to propose changes can send suggestions to the Review page. Approval and rejection happen in the web app.

An agent with direct write permissions can make the corresponding changes without a separate approval each time. Choose read/propose access for workflows that need review before an edit.

Reduce access when the work changes.

Use Agent access to restrict or revoke a grant. Future authorization checks reject the old grant and its tokens. Removing a workspace member also prevents their agents from continuing authorized work.

Revocation cannot undo an external provider request that is already running or retrieve information a client previously received. Review the connected agent provider’s own data practices before authorizing it.

Provider connections have their own scope.

Google sign-in and Google Drive access are separate. Drive uses the per-file drive.file scope. This release supports files created through MCPBinder and does not include a Google file picker for importing arbitrary existing files.

Provider credentials are encrypted on the server using AES-256-GCM and are not returned to the browser or MCP clients. Disconnecting Drive removes local access and attempts to revoke Google access; Google’s account permissions page provides an additional revocation control.

Clear claims, including the limits.

MCPBinder records revisions and attribution for work changes. It uses server-side access checks and database constraints for workspace isolation. We do not present this page as a security certification, an independent audit, or a promise of end-to-end encryption.

Background operations can fail or require review. Check the operation’s final status before relying on a file creation, export, or delivery.

Read the connection guide

Give your work
a place to belong.

Start free with your own workspace. Invite people and connect your agents when you’re ready.

Start free