Security & access
Clear access.
Thoughtful sharing.
Understand who can work in your workspace, how credential secrets are protected, and what happens when you share files or connect another tool.
01 / Workspace access
Give each person
the right role.
Access to shared workspace content follows membership and roles. The service checks the acting person’s current membership and permissions when they request workspace operations.
- Owner
- Manages workspace ownership and members, including administrator access.
- Admin
- Manages editors and viewers and can work with shared workspace content.
- Editor
- Creates and updates shared content within the feature's access rules.
- Viewer
- Reads shared workspace content. Features with separate permissions, such as Credentials, apply their own access rules.
Some actions have additional permission checks. Credential vaults, personal files, and connected mailboxes also have their own access boundaries; a workspace role is not a blanket grant to every account’s information.
Set up your team02 / Shared credentials
A clear view of
the trust model.
Credential secrets are encrypted at rest with keys Scribed holds. Access is logged. This is server-side encryption, not a zero-knowledge password manager.
Explore shared credentialsSecrets and searchable details are different.
Passwords, secret values, notes, and custom field values use AES-256-GCM encryption. Searchable metadata—including item names, usernames, URLs, tags, and field labels—is stored separately and is not encrypted as part of that secret payload.
Share a vault with the intended people.
A vault can be shared with eligible workspace members or restricted to selected members. Vault viewers can read and reveal items; editors can change items; managers can manage the vault and its grants.
Revealing a secret is a recorded action.
Secret values stay out of item lists and are returned through an authorized reveal request. Reveals appear in the vault’s activity trail. In the web interface, revealed values hide after 30 seconds or when the tab is hidden.
03 / Files & external sharing
Choose the material.
Then choose the audience.
Vault holds your personal files. Publishing to workspace Drive creates a separate copy for your team. A data room gives people outside the workspace a link to a selection of those Drive files.
- 01
Choose the files.
A data room contains selected workspace Drive files. Its visitors do not gain general access to the workspace or the rest of Drive.
- 02
Set the conditions.
Add an optional password and expiration time. Anyone with a working room link and its required password can access the material, so share both deliberately.
- 03
Change access when needed.
Disable the room or rotate its link to stop future access through that link. Changing the password invalidates existing room access tokens.
Shared copies remain separate. Deleting a personal Vault original does not delete the workspace Drive copy, and disabling a room cannot recall files someone already downloaded.
04 / API & MCP access
The tool changes.
Access still matters.
API, CLI, and MCP tools act through an authenticated account. Supported workspace operations still check that person’s membership, role, and the permissions for the requested action.
Choose what the connection can do.
Hosted MCP uses an authorization and consent flow. A read-only grant excludes tools that change state. Personal API keys have scopes and can be created with an expiration; workspace owners can also pin a key to a workspace they own.
Keep control of personal API keys.
The full key is shown when it is created. Manage your keys from account settings, revoke one you no longer need, or rotate it to create a replacement and revoke the old key.
05 / Decisions & review
Put review where
the work needs it.
Access permission and human approval answer different questions. Choose which actions a process can take and where a person should check the result.
Add approval to a Run.
An approval step can pause the workflow for a decision. Choose the approvers, information to review, and any timeout behavior before enabling the Run. Run details show the step’s result.
Review a document before accepting changes.
AI revision proposals in Documents can be accepted or rejected. Team comments and review status belong to a specific revision, helping the team distinguish the version it reviewed from later edits.
In plain words
Good questions.
Have a question about access or sharing for your team? Contact hello@scribed.ai.
Read our Privacy PolicyIs the Credentials feature zero-knowledge?
No. Scribed holds the server-side encryption keys for credential secrets. An operator with both the stored encrypted data and the relevant keys could decrypt it. Workspace and vault access rules govern access through the product.
Can an administrator read every restricted credential vault?
An owner or administrator can see vault metadata and manage access grants. Reading the items or revealing secrets still requires a vault role. An administrator can grant themselves a role through that management flow, and the grant is logged.
Does turning off a data room recall downloaded files?
No. Disabling a room, expiring it, or changing its link affects subsequent access through the room. It cannot remove copies a visitor already downloaded.
Does connecting my inbox share it with all workspace members?
No. Connected Gmail and Outlook mailboxes are attached to the individual account. Workspace membership alone does not give someone access to another member's connected mailbox.
Does every AI action wait for my approval?
No. The assistant can perform supported actions within the access granted to it. Review the request you give it and any confirmation it asks for. For repeatable workflows, add an explicit approval step to a Run where a person should decide before it continues.