> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qxlabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Scopes and permissions

> How agent access is scoped: connected apps down to individual tools and accounts, knowledge vaults down to folders and files, with you in control.

Everything an agent can reach is scoped: its [connected apps](/agents/apps-and-knowledge) down to individual tools and the account it acts as, and its knowledge vaults down to folders or files. Untick a tool and that action is out of reach entirely.

## You stay in control

An agent chooses only the proper scopes for the job, the [builder](/agents/create-an-agent/build-with-ai) connects the exact tools it needs, never the whole app. You can always change this while editing the agent, in its **Connected apps** and **Knowledge** sections, and you can change it while chatting too, just tell the agent. Every choice stays visible in the editor, so nothing is ever hidden from you.

<Frame>
  <img className="block dark:hidden" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-editor-light.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=c55d31939fe6f3af65eb296e87482d47" alt="Adjusting an agent's app tools and knowledge scope in the editor" width="2559" height="1305" data-path="images/agents/scopes-and-permissions/scope-editor-light.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-editor-dark.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=f196423604fee552d10c63c2446bec3b" alt="Adjusting an agent's app tools and knowledge scope in the editor" width="2559" height="1313" data-path="images/agents/scopes-and-permissions/scope-editor-dark.png" />
</Frame>

## Scope a vault to folders or files

A vault you attach in the agent editor's **Knowledge** section starts fully open, its row reads **Entire vault** and the agent can search everything in it. To narrow it, click **Configure scope** on the vault's row. The vault's contents appear as a tree of checkboxes, tick the folders or files you want the agent to use. Ticking a folder includes everything inside it, and you can untick individual files within to leave just those out. Click **Save** to apply. The **Entire vault** button clears your picks and restores full access, and leaving everything unticked means full access too, so an untouched vault never locks the agent out.

<Frame caption="Tick the folders and files the agent may search">
  <img className="block dark:hidden" src="https://mintcdn.com/qx-labs/tFwKBYEYIRMDA7bs/images/agents/scopes-and-permissions/vault-scope-picker-light.png?fit=max&auto=format&n=tFwKBYEYIRMDA7bs&q=85&s=5f4d936c063fcbe0ef9bef552b644989" alt="The vault scope picker with a folder and individual files ticked" width="2559" height="1310" data-path="images/agents/scopes-and-permissions/vault-scope-picker-light.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/qx-labs/tFwKBYEYIRMDA7bs/images/agents/scopes-and-permissions/vault-scope-picker-dark.png?fit=max&auto=format&n=tFwKBYEYIRMDA7bs&q=85&s=15fa91a7a1986616bfbd47c410dfcedd" alt="The vault scope picker with a folder and individual files ticked" width="2559" height="1309" data-path="images/agents/scopes-and-permissions/vault-scope-picker-dark.png" />
</Frame>

<Frame caption="The attached vault shows what's in scope">
  <img className="block dark:hidden" src="https://mintcdn.com/qx-labs/tFwKBYEYIRMDA7bs/images/agents/scopes-and-permissions/vault-scope-summary-light.png?fit=max&auto=format&n=tFwKBYEYIRMDA7bs&q=85&s=501f80f336ceb07e7be8115e30e520f1" alt="The Knowledge section listing a vault narrowed to selected folders and files" width="930" height="304" data-path="images/agents/scopes-and-permissions/vault-scope-summary-light.png" />

  <img className="hidden dark:block" src="https://mintcdn.com/qx-labs/tFwKBYEYIRMDA7bs/images/agents/scopes-and-permissions/vault-scope-summary-dark.png?fit=max&auto=format&n=tFwKBYEYIRMDA7bs&q=85&s=ac27654b6f677c92b4c8470f5096e703" alt="The Knowledge section listing a vault narrowed to selected folders and files" width="930" height="304" data-path="images/agents/scopes-and-permissions/vault-scope-summary-dark.png" />
</Frame>

Once saved, the vault's row shows a short summary of what you picked, and that selection is all the agent gets. It searches and cites only the folders and files in scope, the rest of the vault is invisible to it.

## Scope a single conversation

You can also change what an agent may use for one chat, without editing the agent. In the [chat](/agents/chat) composer, open the capabilities, connected apps, or knowledge popover and toggle what you want. Vaults go further than on and off, hover one in the knowledge popover and click **Configure scope** to open the same folder and file picker as the editor. Either way the change applies to that conversation only, and the saved agent stays exactly as it was.

<Columns cols={2}>
  <Frame caption="Open the apps popover in the composer and click the tools icon on Gmail">
    <img className="block dark:hidden" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-chat-apps-light.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=e4383da4db9eed4d1685685adce03cb0" alt="The chat composer's connected apps popover with the Gmail tools button highlighted" width="2560" height="1312" data-path="images/agents/scopes-and-permissions/scope-chat-apps-light.png" />

    <img className="hidden dark:block" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-chat-apps-dark.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=3ac9917a6c70cfe0077a29d26f06d7aa" alt="The chat composer's connected apps popover with the Gmail tools button highlighted" width="2560" height="1312" data-path="images/agents/scopes-and-permissions/scope-chat-apps-dark.png" />
  </Frame>

  <Frame caption="Pick which Gmail tools this chat may use">
    <img className="block dark:hidden" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-chat-gmail-tools-light.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=5737ea14584420ed9fb48c873759b29a" alt="Choosing the Gmail tools the agent can call in this chat" width="2559" height="1305" data-path="images/agents/scopes-and-permissions/scope-chat-gmail-tools-light.png" />

    <img className="hidden dark:block" src="https://mintcdn.com/qx-labs/jWuB4YCOb71J-Xxg/images/agents/scopes-and-permissions/scope-chat-gmail-tools-dark.png?fit=max&auto=format&n=jWuB4YCOb71J-Xxg&q=85&s=0a3ed7a8e2297c889a717ea569a33ec0" alt="Choosing the Gmail tools the agent can call in this chat" width="2559" height="1302" data-path="images/agents/scopes-and-permissions/scope-chat-gmail-tools-dark.png" />
  </Frame>
</Columns>

## What scoping means in practice

When an agent runs, only the tools you see in its editor exist for it. An agent that can read an inbox but not send from it cannot send, no matter how it is asked, and a vault scoped to one folder keeps every other document out of view. When an app has more than one account connected, the agent acts as one specific account, and you choose which.

<Tip>
  Keep scopes minimal. An agent with just the tools its job needs picks the right one more reliably, runs faster, and can't touch anything you didn't intend.
</Tip>
