Skip to content

Permissions

Knowledge Graph read access starts from one grant — View knowledge graph (knowledge-graph:read) — and can then be narrowed or re-opened on any namespace, folder or file. The same permissions apply to KG Studio, chat context, and every MCP tool.

  • No rule: everyone with View knowledge graph reads everything, as before.
  • Rules allow or deny read for a role, a team, a user, an agent or everyone, on a namespace, a folder, or one file.
  • The deepest rule wins. A folder rule covers everything below it; a rule on a subfolder or a file overrides it. Deny Legal/ and allow Legal/Public/, and Legal/Public/ stays readable.
  • At the same level, the more specific subject wins: user, then agent, then team, then role, then everyone. Deny HR/ for everyone and allow it for the HR team, and HR team members read HR/.
  • Between rules of the same kind at the same level, deny wins — for example when you belong to two teams and one is allowed, the other denied, on the same folder.
  • Agents read only what both they and their user may read. An agent rule narrows what an agent sees on anyone’s behalf; it never widens what the user may read.

When you may not read a file, nothing derived from it reaches you:

  • its text, sections and page index;
  • entities that only it mentions;
  • relations that only it states between two entities you can otherwise see;
  • similarity links to it.

Disabled files and folders are excluded from every tool and search, whatever the permissions.

  1. Open KG Studio and the namespace in the explorer.
  2. On the namespace, a folder or a file, open the row menu and choose Permissions….
  3. Effective access lists every role, team, user and agent with a rule here or above, whether each may read, and where that comes from (set here or inherited).
  4. Add rule: pick the kind (role, team, user, agent or everyone), the subject, and Allow or Deny, then add it. Remove a rule with its remove button.
  5. On a namespace or folder, Rules below lists the rules set deeper inside it, so a rule that hid a folder can always be found and removed.

Changing permissions needs Manage knowledge graph permissions (knowledge-graph:acl); administrators have it by default. Every change is recorded in the activity log. A change applies to the next search or tool call. A KG Studio graph that is already open keeps the access it was opened with for up to 15 minutes; reopening the graph, or signing out and in, applies the change at once. A file moved into a folder you cannot read leaves an open graph within a few seconds, once the graph refreshes. Graph data your browser cached under the old permissions is discarded when the graph reopens and when you sign out. A namespace holds at most 256 rules.

A file you may read can be downloaded through a link the browser fetches directly from storage. Those links carry their own access and are not re-checked against Knowledge Graph rules:

  • A link already issued keeps working until it expires, even if the file is hidden from that person afterwards.
  • Links are issued only to people who may read the file at that moment, and only for that file.
  • Treat a shared link like a copy of the file: to be certain nobody keeps access, replace or delete the file.
  • Rules move with what they are on. Renaming or moving a file carries the rules set on that file; moving a folder carries the rules on it and on everything inside it. If the same subject already has a rule at the destination, the stricter one (deny) is kept. The move is recorded in the activity log.
  • Rules above the new location apply. A moved file is governed by the folders it now sits in, so a move can hide a file from people who read it before, or show it to people who could not. A move that changes who may read what moves needs Manage knowledge graph permissions; without it the move is refused.
  • You can only move what you can read, to where you can read. Moving a folder needs read access to everything inside it; a move you are not permitted to make is answered like a missing file. A folder cannot be moved into itself, and while a folder move runs, other moves and uploads into the same folders wait for it.
  • Deleting a file, folder or namespace deletes its rules.