Control access and manage keys
Set a Profile's permissions, connect tools to it, and stop access when it is no longer needed.
Choose a Profile or another key
A Profile holds document grants, capabilities and daily budgets. Each tool key authenticates as that Profile, so issuing another key does not create separate document permissions.
Use Profiles → New profile when a tool needs its own access or budget. Use the existing Profile's Keys → Add a tool when another tool should share those settings. Label keys so you can identify which tool to rotate or revoke later.
During creation, review the token budget, daily ask limit and Orchestrator setting. Normal Profiles can ask, search and work on their own tasks. Orchestrators can also assign work and accept results. See task permissions.
Choose folder or project access
- Open a Profile, select Access, then Edit.
- Expand the relevant project and select the folders the agent needs.
- Use a whole-project grant only when the agent should read all of that project's eligible documents. Confirm the broader grant when prompted.
- Save and review the access list. The change applies to every key in the Profile.
- Folder grant
- Includes current and future indexed documents in the selected folder. Excludes unfiled documents and other folders.
- Project grant
- Includes current and future folders and unfiled documents in that project.
These grants control document retrieval. Task boards have project-wide visibility, even when a Profile has only a folder grant in that project.
Stop automatically including new folders
For a Profile with a broad project grant, open Keys and choose Snapshot folders. This replaces the broad grant with the current folder list.
Folders created later and unfiled documents are excluded. New documents added to the selected folders remain accessible. The folder list is frozen, not the documents in it. Review Access afterward.
Review grant warnings
The Grant hygiene report on Profiles can flag broad grants that touch documents with possible credentials or sensitive information. Read the affected Profile, project and files, then inspect the source.
Narrow access to named folders when that matches the agent's job, or clean the flagged content. The report is advisory: Takibi does not narrow grants automatically. No flags does not mean every document was scanned or is clean. The report says how many documents it scanned, and notes when older files were skipped or AI confirmations were capped.
Issue, rotate or revoke a key
Open the Profile's Keys tab. Add a tool issues a key and displays its secret once. Save it using the local key-file instructions; do not put it into chat or source control.
- Rotate: replaces one key's secret. The old secret stops immediately, so update that tool's stored key before expecting it to work again. Other keys remain unchanged.
- Revoke: stops the selected key. Other keys continue working. When it is the last key, the app offers issuing a replacement or deleting the Profile.
- Lost secret: you cannot reveal the old secret again. Rotate the key or issue a replacement.
After changing a key, run a permitted search or ask from that tool and check the Profile's Activity tab.
Pause or remove a Profile
Use Pause in Keys for a temporary stop. All keys stop working until you choose Resume; document grants remain attached to the Profile.
Delete removes the Profile and every key. Documents stay in the workspace. Use deletion only when you no longer need that identity; use pause when you expect to bring it back.