> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hyperspell.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Permissions

> How Hyperspell decides who can see what, from the moment data arrives to the moment an agent answers.

The most useful knowledge in a company lives in places not everyone should see: inboxes, direct messages, call notes. A brain that ignores this either leaks or gets switched off. Hyperspell's permission model is built to let people search everything the company knows without anything traveling further than it should.

## One brain, many views

Everything is stored once, in one company brain. There are no separate personal or team copies. Each document carries a list of who may see it, and every question is answered from the documents the asker is allowed to see. Two people asking the same question can get different answers, because they see different slices of the same brain.

Agents work the same way. When you connect Claude, ChatGPT, or a coding agent, it acts as you and sees only what you see.

## Shared and personal data

Where a document comes from decides who sees it by default. Every integration is set up in one of two ways, and some tools support both.

|                              | Shared integration                                     | Personal integration                              |
| ---------------------------- | ------------------------------------------------------ | ------------------------------------------------- |
| Who connects it              | An admin, once, with an API key or service account     | Each person, with their own login                 |
| Typical tools                | Knowledge bases, project trackers, CRMs, shared drives | Email, calendars, direct messages, personal notes |
| Who sees the data by default | Everyone in the organization                           | Only the person who connected it                  |

Admins pick the mode for each tool during setup and can change it later in Settings. The choice matters because Hyperspell does not copy the permission lists of the source tools. A Google Drive folder that only three people could open in Drive becomes visible to the whole organization once it arrives through a shared integration. So the rule of thumb is simple: set up a tool as shared only when everything it contains may be seen by everyone. For tools where that is not true, use personal connections, and rely on [content rules](/advanced/content-rules) to share the parts that should travel.

<Note>
  Today a document is visible either to the person who connected it or to everyone in the organization. Narrower audiences, such as a single team, are not yet available.
</Note>

Meeting-notes tools are the one exception: Gong, Fireflies, Fathom, Fellow, and Granola. Recordings often include one-on-ones, so a shared connection for these tools does not make its content visible to everyone automatically. If you want a company-wide meeting corpus, [tell us](mailto:hello@hyperspell.com) when you connect it and we will turn that on.

## How content rules change the defaults

The defaults above are a starting point. [Content rules](/advanced/content-rules) let admins adjust them based on what a document says, rather than where it came from.

## When people leave

When a member is removed from the organization:

* Their identity and all their access are removed. Their connected agents stop working.
* Documents only they could see are deleted.
* Documents that were shared with the organization, or that other people also brought in, stay in the brain.

The company keeps what the company paid for, and the person's private data does not linger.

Disconnecting a single personal integration works the same way on a smaller scale. The content that integration brought in is removed, unless the same document also arrived through someone else's connection or a shared one.

## Where data is stored

Data is stored in the region you chose when you created your account, either the United States or the European Union, and is never copied between regions. See [Regions and data residency](/resources/data-residency) for what runs where, and [Security](/resources/security) for encryption, backups, and our operational practices.

## In short

* Everything is stored once. Access is decided per document, per person.
* Shared integrations are visible to everyone. Personal integrations are private to the person who connected them.
* Hyperspell does not mirror the source tool's permissions. Choose shared only for content the whole company may see.
* Filter rules hold content back. Sharing rules offer personal content to the team, with the owner's consent. Filters always win.
* Agents inherit the permissions of the person who connected them.
* Every answer shows its sources.
