> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cohesive.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Security and privacy

> Understand shared access, private conversations, connected accounts, and model credentials.

Cohesive controls access through organization membership and permissions on Workspaces, Canvases, and files.

## Shared work and private conversations

Workspace membership grants access to its shared work. A Canvas or file can also have direct access grants. Removing one grant doesn't remove another grant the recipient still has.

Agent conversations remain private to their owner. Generated artifacts on a shared Canvas are visible to its collaborators. [Comments](/product/collaboration/comments) are shared Canvas discussions.

Public links are a separate access mechanism: anyone with a [published Canvas](/product/collaboration/public-canvases) or [file link](/product/files/publishing) can read that snapshot. Unpublishing stops serving it, but doesn't recall copies already saved by readers.

## Connected apps

Connectors use the account authorized during setup. A personal connection belongs to that user in the current organization; an organization connection can be available to members' agents.

External access depends on the connected account's permissions. A shared organization connection doesn't necessarily enforce each member's separate permissions in the external app. For example, HubSpot owner mapping helps interpret “my deals”; it isn't a per-owner access restriction.

Many connections use OAuth. Some providers use API keys or other credentials. Review the authorization and configuration presented for the connector.

## Model provider credentials

[ChatGPT and Claude subscriptions](/product/account/model-providers) connect through provider sign-in. API keys can also be supplied for supported agent options.

Cohesive stores provider credentials encrypted and doesn't place the real credential in the agent's sandbox files. Its infrastructure provider applies credentials to outbound requests at the network boundary and can see the credential and requests it handles.

Connecting a subscription doesn't import your existing provider conversations. Requests for the selected agent are processed through the selected provider account.

Use **Replace** or **Disconnect** in Model providers to change that connection. Check the displayed funding source afterward.

## Agent commands and HTML blocks

[Permission modes](/product/agent/permissions) control when agent commands require confirmation. **Allow all** skips those confirmations in the session; it doesn't add resource access.

[HTML blocks](/product/canvas/blocks) use a restricted browser sandbox without network access or persistent browser storage. Their local interactive state is different from a saved file edit.

## Security reviews

For current compliance documentation, data processing terms, retention questions, or a security review, email [support@cohesive.ai](mailto:support@cohesive.ai).
