Skip to content
Security/Access and writes

Access control

Tano has distinct access boundaries: membership roles in an online workspace, OS permissions on a local folder, and permissions of an agent you configure separately. None automatically substitutes for another.

Online membership roles

The workspace service distinguishes owner, writer, and reader. Owners can manage membership; writers can change content; readers can view it. Unauthorized users cannot access workspace content. Desktop two-way file sync requires owner or writer access, and readers in a live session cannot submit edits.

Membership is managed by the connected service. A writable local folder does not grant online membership. See Online workspace and File sync.

Local file boundary

A local desktop workspace is scoped to the folder you select and does not follow symlinks outside it. Markdown and attachments remain ordinary files; the OS determines whether other applications on the device can access them.

Local MCP offers Markdown listing, reading, creation, and conditional writing within its selected scope, not arbitrary command execution. It also restricts hidden paths and symlinks. See MCP integration and File access and writes.

Configure agent access separately

AGENTS.md can describe working conventions but cannot constrain an agent client's own file, network, or terminal permissions. Grant the directories and tools needed for the task, and review external edits and conflict notices. Local desktop activity records show a tool channel and content differences; they do not prove a model or person's identity.