Skip to content

Permissions and data

Updated View as Markdown

Indent works with your systems the way a teammate does: only through the tools you connect, with the access you grant.

What Indent can access

Indent can only use integrations your organization or you have connected — GitHub, Slack, databases, and MCP servers such as Notion, Linear, HubSpot, Datadog, and Sentry. Nothing is reachable until it’s connected, and Indent acts within the access that connection grants. To add or remove access, manage the connection from Integrations. See Connecting MCP servers.

Database permissions

PostgreSQL queries run in read-only transactions. ClickHouse connections apply or require read-only mode. BigQuery runs SQL with the connected service account’s IAM permissions, so use a read-only service account to prevent changes to source data. See Connecting your database.

Secrets are provided through the app

When a task needs a secret, such as an API key or database password, provide it through the app. Saved values are masked after you enter them. Build variables are available to the image build, and runtime variables are injected into the computer’s shell and background processes. Commands and programs running there can read those values. See Setting up environments.

Organization and personal scope

Every integration connects at one of two scopes:

  • Organization — the connection is shared with your team, and anyone in the organization can use it.
  • Personal — the connection is owned by you, and only you can use it.

Each integration’s page shows the scopes it supports. Database connections, GitHub App installations, and the Slack workspace app are organization-scoped. GitHub and Slack also offer personal account connections. Teammates can see whether you have connected a personal account, but they cannot use it.

Using a personal integration’s tools requires a private session. A connected personal GitHub account can also author a pull request you request in any session where you participate. See Private sessions.

Who can see a session

By default, a session is visible to everyone in your organization, so teammates can follow the work and pick it up. If you created the session, open the share control in the session header to make it private.

Direct messages with Indent in Slack and any session on your computer in the desktop app are always private. Slack channel threads stay visible to your organization.

Navigation

Type to search…

↑↓ navigate↵ selectEsc close