Custodos is live: every leading AI model, your data stored securely in Switzerland.Start free trial
Company Brain

Brain permissions

Every brain has its own permissions, separate from the other rights in the workspace. This page shows which levels exist, how to share a brain and when workspace admins have access.

Last checked on 28 September 2026

On this page

The three access levels

Custodos has three levels per brain: full access, Can edit and Can use. Whoever creates a brain always has full access. Workspace admins have full access when the workspace policy or the creator provides for it.

WhatFull accessCan editCan use
Use the brain in chat and with agents, read documents in the preview, Test the Brainyesyesyes
Add sources, edit text, replace or delete documentsyesyesno
Change name, description and Instructions, move the brain to a folderyesyesno
Share: set access and peopleyesnono
Change Active in new chats by default and the data protection levelyesnono
Delete the brainyesnono

Sharing a brain

  1. 1

    Open sharing

    Open the brain and click Share. Only people with full access see this button.
  2. 2

    Choose the audience

    With Everyone in the workspace every member can use the brain in chat. With Selected people only only the people listed see it.
  3. 3

    Add people

    Under Add people search by name or e-mail and give each person the role Can edit or Can use. Remove takes someone off again.
  4. 4

    Save

    Click Save. Custodos confirms with Sharing saved.

Access for workspace admins

Whether workspace admins can access every brain is a workspace policy. Admins set it under Settings in the Sharing section with the Admins have access to every brain switch.

SwitchWhat applies
onWorkspace admins can open, edit and share every brain, restricted ones included.
offWhoever creates a brain decides with Include workspace admins whether the admins get full access. Otherwise admins are ordinary members on that brain and are never listed automatically.

Access is checked on every request

Custodos checks permission again on every request, not only when a brain is attached. When a share is tightened, the brain returns nothing more to the person concerned from that moment on, including in existing chats, projects and agents.

An agent never widens access. Each person only gets answers from brains they may read themselves. More under Sharing agents.

Source references in older replies stay visible. Someone who no longer has access sees Page not found on clicking one.

When someone leaves the workspace

When a person leaves the workspace or is removed, Custodos deletes their access to every brain. The brains they created remain, with all their documents.

If such a brain has nobody with Can edit, it passes to the workspace admins, unless they have access anyway. The activity log records this per brain as Brain passed to the admins.

Tracing changes

Changes to brains and their permissions appear in the activity log, which admins open under Settings. The entries include these:

Each entry shows who made the change and when. How to open and read the log is described under Activity log.

  • Brain created, Brain edited and Brain deleted
  • Brain sharing changed and Brain access changed
  • Admin access to brains changed
  • Original file downloaded from a brain

Read next

Still have a question? Write to us.