Scopes
A connection lists only the tools its scopes open. The consent text is what a person sees when they approve the connection. A scope marked "by name only" is never in a default grant: a client must ask for it by name.
| Scope | Consent text | Tools | By name only |
|---|---|---|---|
knowledge:read | Read the knowledge base (projects, documents, search) | listProjects, listDocs, searchKnowledge, readDoc, listBrains, getBrain, getBlueprint, searchBrain, writeDoc, editDoc | no |
knowledge:write | Create and edit documents you own in the knowledge base | writeDoc, editDoc | no |
skills:run | Run skills that are enabled for external use | checkExecution, skill_<name> | no |
meetings:read | Read meeting transcripts and documents | getMeetingTranscript | no |
improvements:admin | Export improvement suggestions and write their dispositions (admin only) | no MCP tool | yes |
apps:invoke | Read and change records in Sasha Apps you can use | listAppFiles, readAppFile, writeAppFile, editAppFile, deleteAppFile, checkApp, open_app__<app>, app__<app>__<action>, app__<app>__<table>__{list,get,create,update,delete,aggregate} | no |
apps:write | Edit the source files of Sasha Apps you manage (admin and staff only) | listAppFiles, readAppFile, writeAppFile, editAppFile, deleteAppFile, checkApp | no |
getDocs, suggestImprovement and checkSuggestion need no scope.