Brain permissions
Every brain has its own permissions, separate from the other rights in the workspace. This page shows which levels exist, how to share a brain and when workspace admins have access.
Last checked on 28 September 2026
On this page
The three access levels
Custodos has three levels per brain: full access, Can edit and Can use. Whoever creates a brain always has full access. Workspace admins have full access when the workspace policy or the creator provides for it.
| What | Full access | Can edit | Can use |
|---|---|---|---|
| Use the brain in chat and with agents, read documents in the preview, Test the Brain | yes | yes | yes |
| Add sources, edit text, replace or delete documents | yes | yes | no |
| Change name, description and Instructions, move the brain to a folder | yes | yes | no |
| Share: set access and people | yes | no | no |
| Change Active in new chats by default and the data protection level | yes | no | no |
| Delete the brain | yes | no | no |
Sharing a brain
- 1
Open sharing
Open the brain and click Share. Only people with full access see this button. - 2
Choose the audience
With Everyone in the workspace every member can use the brain in chat. With Selected people only only the people listed see it. - 3
Add people
Under Add people search by name or e-mail and give each person the role Can edit or Can use. Remove takes someone off again. - 4
Save
Click Save. Custodos confirms with Sharing saved.
Access for workspace admins
Whether workspace admins can access every brain is a workspace policy. Admins set it under Settings in the Sharing section with the Admins have access to every brain switch.
| Switch | What applies |
|---|---|
| on | Workspace admins can open, edit and share every brain, restricted ones included. |
| off | Whoever creates a brain decides with Include workspace admins whether the admins get full access. Otherwise admins are ordinary members on that brain and are never listed automatically. |
Access is checked on every request
Custodos checks permission again on every request, not only when a brain is attached. When a share is tightened, the brain returns nothing more to the person concerned from that moment on, including in existing chats, projects and agents.
An agent never widens access. Each person only gets answers from brains they may read themselves. More under Sharing agents.
Source references in older replies stay visible. Someone who no longer has access sees Page not found on clicking one.
When someone leaves the workspace
When a person leaves the workspace or is removed, Custodos deletes their access to every brain. The brains they created remain, with all their documents.
If such a brain has nobody with Can edit, it passes to the workspace admins, unless they have access anyway. The activity log records this per brain as Brain passed to the admins.
Tracing changes
Changes to brains and their permissions appear in the activity log, which admins open under Settings. The entries include these:
Each entry shows who made the change and when. How to open and read the log is described under Activity log.
- Brain created, Brain edited and Brain deleted
- Brain sharing changed and Brain access changed
- Admin access to brains changed
- Original file downloaded from a brain
Read next
Still have a question? Write to us.
