Docs / How-to guides
Keep client work separate
Vaults keep one client's files apart from other people. They don't keep them apart from an AI that reaches more than one of your vaults. A connection acts as you, so it can read and write in every vault it reaches. Text it reads in a file, a comment or a web page can carry instructions meant for the AI. A connection that reaches only one vault can't carry anything into another.
Give each client their own vault
On Home, choose New vault and name it after the client. Keep that client's work only in that vault. To add the people who work on it, see Invite someone.
Connect with only that client's vault
When the consent page or the New token page asks which vaults a connection may reach:
- Choose Only the vaults I tick.
- Tick the one vault the AI needs.
- Choose Read only unless the AI has to write. Choose Read and write only for work that needs it.
- Name the connection after the client and the agent, so you can tell it apart on the Connections page.
If you belong to more than one vault, the consent page doesn't choose for you, and it refuses an answer that names neither All my vaults nor a ticked vault. If you belong to one vault, All my vaults is already chosen, and it is fine to leave it.
A connection's vaults can't be changed later. To change them, revoke it on the Connections page and make another.
Check it
On the Connections page, each connection lists its vaults. A connection for one client should name only that client's vault. A connection that says All your vaults reaches every vault you belong to now and any you join later.
What this does and doesn't do
- It limits what a connection can see. A connection limited to some vaults can't see the others. See the Security model.
- It doesn't stop the AI changing open files in the vault it reaches. Canon files still need a person to approve a change. See Canon, open and rules.
- It doesn't help if you tick several clients' vaults for one connection. Then the connection reaches all of them.
- It costs a few extra clicks, one connection per client. For work that touches one client at a time, that is the point.
Related: Connections, Agents.
For agents: this page as Markdown, and every page at /llms.txt.