Canonical page: https://tellenze.com/trust

Access and privacy

# Shared purpose.  Clear access.

Know who can read the work, what a connection can change and when a private draft becomes shared. Clear boundaries make collaboration easier to understand.

[See who can read what](#visibility-guide)[Explore workspace controls](https://tellenze.com/platform/workspace-controls)

- Workspace membership

- Work visibility

- Authorized action

Permitted work

Illustrative model · Each action follows the permissions it needs.

An owner and an audience

## Start with the work’s home.

Workspace membership is the first boundary. Projects, Teams, documents, workshops and published editions then apply their own access rules.

### Join the workspace.

Active members can sign in using a method their workspace offers. Signing in does not give them access to every item.

### Check the Project or Team.

Work belongs to a Project or Team. People need specific permission to open a private project. Its creator and active administrators keep access under the project’s rules.

### Keep links in context.

A saved link is a reference. It does not grant permission to the linked task, document, repository or design file.

[Read Project and Team access](https://tellenze.com/help/projects-teams)[Check feature requirements](https://tellenze.com/availability)

Private and shared spaces

## Know the audience  before you share.

The same work can inform a private briefing, a shared conversation or a report. Each has its own audience.

Visibility guide · current membership and each area’s access rules still apply
Area | Who can read it? | What to keep in mind |

Work items and linked documents | Members who can access the relevant Project, Team or document. | A link helps people find material. They still need permission to open the item it points to. |

Personal Looper chats and briefings | The member who owns the chat or briefing. | Private chats stay private. Posting a reply into a work-item conversation shares that reply separately. |

Work-item conversations | People who can read that work item. | Questions, decisions and posted assistant replies remain beside the shared work. |

Private workshops | Only invited participants, including administrators. | Refinement and retrospective rooms keep their own participant lists. Retrospective notes are private to their author while people write, then shared within the room. |

Review drafts | Their author. | Draft instructions, audience briefs and private editing fields stay in the draft. Administrators cannot open another author’s draft. |

Published review editions | Named readers selected by the author. | Readers can see the approved edition even without access to its sources. They still need source access to open its links. |

Sharing a review is a decision

## A private draft.  A reviewed edition.

The author chooses the work, writes the report, previews its contents and names the readers. Preparing a draft through Looper or an agent does not publish it.

A published edition is a fixed report that can include approved information from the source work. Check it for the intended audience, including readers who cannot open the original source.

[Read review sharing](https://tellenze.com/help/reviews)

Illustrative sharing decision · a delivery update

PRIVATE AUTHORING

### Prepare the story.

The draft, audience brief and AI instructions belong to the author.

PREVIEW + NAMED READERS

### Share the approved edition.

Readers receive that fixed report. Readers still need source access to open its links.

Withdrawing an edition removes workspace reader access. It cannot recall files already downloaded.

Give connections the access they need

## The right access. For the right action.

A connected tool needs access to the source and permission for the action. Connecting it does not open work you cannot access.

MCP · member authorization

### Your agent follows your access.

MCP (Model Context Protocol) lets a compatible agent client connect using your membership and a selected machine profile. Your current membership, source access and enabled tools decide what it can find and do.

Current member accessEnabled action

A machine profile can map a local folder to give the agent context. Tellenze’s hosted service does not check whether that folder exists on your computer.

[Explore MCP access](https://tellenze.com/developers/mcp)

API · selected App permissions

### Your App uses the access you choose.

An App is a named API connection for another system. It can use only the projects and actions you selected, within its owner’s current access. Workspace documents need a separate permission. Reading and changing work also need separate permissions.

Owner’s current accessSelected App permissions

Apps cannot manage members, permissions or Required Context policies. Revoking access stops future use while earlier contributions keep their record of who made them.

[Explore App permissions](https://tellenze.com/developers/api)

Reading before supported changes

## Choose the guidance.  Keep its version clear.

Required Context is required reading for supported agent actions. Where configured, it uses exact document revisions, including workspace guidance and any relevant project or procedure requirements.

01 · Pin and review

### Choose the required reading.

A policy selects fixed document revisions. Saving a newer document does not change the policy’s published reading.

02 · Retrieve

### Read what applies now.

The agent finds and retrieves the required guidance. It may need to read again if the policy, target, procedure or access changes, or its reading receipt expires.

03 · Acknowledge

### Record that it was retrieved.

A receipt records that the guidance was retrieved. It does not prove understanding. Review the proposed work and check the result separately.

Required Context applies to supported actions that require reading first. People still make the review decision. For email and provider Powerups, check the destination and current fields before explicitly running the action.

[Read Required Context](https://tellenze.com/help/required-context)[See reviewed Powerups](https://tellenze.com/platform/powerups)

Change or remove access

## Update the access.  Keep the history.

Removing a connection or changing membership controls future access. Existing records can keep their decisions, contributor details or delivery results.

[Review connection setup](https://tellenze.com/guides/connect-your-tools)

### Revoke a connection.

Members can revoke MCP authorization or an owned App. Rotating an App token invalidates the old token immediately.

### Suspend a member.

Administrators can suspend membership, removing current browser sessions and revoking MCP authorizations. Restored members need fresh agent authorization.

### Disable a provider.

Disabling an email provider stops connections and sending, while keeping drafts and history. Check the setup guide to see what disabling another integration does.

### Change an edition’s readers.

The review author can update named reader access or withdraw an edition. Previously downloaded copies remain outside that control.

A few useful details

## Ask about the boundary that matters.

Can an administrator read every private area?

Administrators cannot read another author’s review draft or enter a private refinement or retrospective room without being a participant. Project administration and these private areas have separate access rules.

Can an agent read work that I cannot open?

An agent connection follows your current source access. An App is also limited by its selected permissions. A prompt or saved source link cannot give it access to hidden material.

Does a Required Context receipt prove that the agent understood it?

It records that the agent retrieved the required guidance for a supported action. It does not prove understanding or correctness. Review the proposed change and check the acceptance criteria.

Where can I ask about storage, retention or provider processing?

[Contact Tellenze](https://tellenze.com/contact) with the workspace and requirement you are checking, such as data location, retention, backups, provider processing or support access. Confirm those arrangements before bringing information that depends on them.

Before your team starts

## Bring the questions your team needs answered.

This guide explains who can see the work and what connections can do. For operational details and legal terms, check the relevant published documents and discuss your team’s requirements with us.

[Discuss your requirements](https://tellenze.com/contact)[Read the Privacy Policy](https://tellenze.com/privacy)[Read the Terms of Service](https://tellenze.com/terms)

Keep your next step clear

## Find the guide for your next step.

[Browse all guides](https://tellenze.com/guides)

COME TAKE A LOOK

## A little less busy.  A lot more together.

Curious? Join the waitlist and see how we welcome your team.

Tell us a little about your team. We’ll explain the next steps and invite you when we have capacity for your workspace.

[Join waitlist](https://tellenze.com/waitlist)Start with your email. No payment needed to join.
