Agent permissions for your team's files.
One folder Claude Code, Cursor and Codex all read. No agent reads past the person who created it, every write is a version, and you can share a folder outside your company.
- Switch from Claude to ChatGPT. Easy.
- Collaborate on projects. Easy.
- Connect the tools you already use, like Slack and GitHub. Easy.
- Search public context from thousands of open repositories. Easy.
Sign Up!Free to start. No card required. 1000 GB included.
Connect your AI
- 1Paste this into Claude Code.
Add the agentleFS MCP server at https://agentlefsmcp-server-dev.up.railway.app/mcp to this client, then walk me through signing in to it in the browser. If it does not work, tell me to ask whoever runs this deployment, with what you tried and what came back.
Stuck? Write to us with what you tried, and a person will answer. contact@agentlefs.com
How it works
Your AI is connected to this filesystem and searches it whenever you ask it something. It looks for related documents in your own folders and in public sources at the same time.
Your AI works with your private context, and finds the best public context to go with it.
agent-sort
affaan-m/ECC
Build an evidence-backed install plan for a specific repo by sorting skills, commands and rules.
AGENTS.md
NousResearch/hermes-agent
How this repository expects an agent to work in it.
pair-agent
garrytan/gstack
Pair a remote AI agent with your browser.
agent-tracing
lobehub/lobehub
Agent tracing CLI for execution snapshots. Use for traces, snapshots and LLM call inspection.
llms.txt
mem0ai/mem0
The project, written for a model rather than for a reader.
CLAUDE.md
alirezarezvani/claude-skills
House rules an assistant is expected to have read before it edits anything.
Examples, captured 2026-09-09. Browse all of it
Collaborate with people and their AI
A shared folder is a project. Several people work in it, and so do their AIs, on the same files at the same time. Ask yours to write up what you worked out and the next person's AI reads it. Everyone in the folder sees everything under it, and never the folders above it. Create an organization and give people different levels of permission, or keep the whole store to yourself.
Every write lands as a new version, so nothing an agent does is destructive.
One store
- You
- approvereverything
- Share with Priya
- editorhandbook/
- Designer
- readerone file
- On-call agent
- readerrunbooks/
- CFO
- approverfinance/
Versioning
Every write lands as a new version, whether you made it or an agent did. Open a document's history to read any version or diff it against the one before. Restoring puts the old text back as the newest version. Nothing behind it is ever overwritten.
One document, oldest version first
- v1you
- v2your agent
- v3a colleague
- v4your agent
- v5restored from v2
v3 and v4 are still there, and still readable. A restore adds a version.
agentleFS is seven verbs
Connect the client you already have open, add the folders it should read, grant people and agents a level on them, share any of it with your team, view who reaches each file, restore any document to the way it read before, and audit every read and every refusal — so an agent retrieves exactly what the person behind it may see, and you can prove it afterwards.
Need an API for your own dev needs?
The same store, called from your own product. Give each of your users a principal, and every read returns only what that user may see. You never build an ACL table.
Read the SDK docsPrivacy and your data
- We do not use your content to train or improve AI models. Not ours, and not anyone else's.
- agentleFS makes no call to any model. Your assistant does the answering, using the documents we serve it under your own credentials.
- Search is indexed on our own systems with a local algorithm. Building the index sends your content nowhere.
- Connect a client running a model on your own machine and no frontier lab is in the path at all. Your content stays on hardware you control.
FAQ
Getting started
What is agentleFS?
Agent permissions for the files your team shares. Permissions attach to folders and inherit down the tree. Agents reach it over MCP and see only what the principal behind them may see.
Do I need to create an organization to try it?
No. Signing in creates a personal workspace. Creating an organization is optional.
How do I make my first folder?
Name it and add files in one flow. A folder comes into existence with its first content. Permissions, history and audit all scope to the folder you are standing in.
Is it folders and files, or a database with folders bolted on?
Folders and files, nesting like a filesystem. Underneath is a content-addressed git object model in Postgres. Every document carries its own line of versions, and every past permission state is queryable.
Connecting an agent
Which clients can connect?
Anything that speaks MCP. The console has ready-made steps for nine clients: Claude Code, Claude Desktop, Cursor, the two Codex surfaces, ChatGPT, Gemini CLI, VS Code and Cline. Every other client takes the same endpoint.
Should I install the plugin or add the MCP server?
The plugin, where there is one. It registers the same server and brings the skills that explain what you can reach, plus the slash commands on Claude Code, so it is one step instead of two. Claude Code, Claude Desktop, the Codex CLI and the Codex app can install it. Every other client adds the server directly, and connects exactly the same way.
Do I have to paste an API key into my editor?
Not for yourself. A person signs in through the browser over OAuth. Tokens are for agents your application runs, which have no browser to redirect.
What can my agent do once connected?
List folders, list and read documents, and search everything it can reach. It writes and edits where it holds an editor grant.
list_org_folders · list_org_docs · read_org_doc · search_org_knowledge · write_org_doc · edit_org_doc · delete_org_doc · brief_meDoes search match keywords or meaning?
By meaning where a vector index exists, and by text where it does not. The authorization filter runs in the SQL WHERE clause before ranking. Content you cannot reach never enters the candidate pool.
My agent will not connect. Who do I ask?
Write to contact@agentlefs.com with your client, what you ran and what came back. A person reads every message.
Can several agents work in the same folder at once?
Yes. An agent claims a document or one of its sections before it edits, and another agent's write into that claim is refused until the claim is released or expires. Agents ask each other things with typed messages, addressed by name or by what an agent is responsible for. When two agents edit the same document at once, one edit lands and the other is refused and told to re-read.
claim · message · edit_org_doc expected_commitBuilding on it
Is there a REST API, or only MCP?
Both, over the same authorization. It covers documents, folders, renames, moves, search and grants. The OpenAPI spec is served from the API itself.
GET /v1/documents · POST /v1/grants · GET /v1/openapi.yamlCan I build my own product on top of this?
Yes, and that is what the REST API is for. Give each of your users a principal, and every read you make for them returns only what they may see. Your own code manages access with POST and DELETE on /v1/grants.
Does the API leak what a user may not read?
No. A path they cannot reach returns 404, and so does a path that does not exist. The two are deliberately the same status and the same body.
NOT_FOUND · 404 · absent, OR present and not yoursCan an agent's MCP token call the REST API?
No, /v1 refuses a token minted for MCP. Mint a separate key for your application code.
How do writes avoid duplicating or clobbering?
A create carries an Idempotency-Key, so a retried request is the same request. An update carries If-Match, so a stale write returns 409 instead of overwriting a concurrent edit.
Idempotency-Key · If-MatchPermissions
What are the access levels?
Three rungs, each containing the one below: reader, editor, approver. An approver can share and manage access, and edit, at or below where it holds the grant. There is no fourth level.
Is a token scoped to a folder?
No. A credential authenticates a principal. What that principal can do in a folder is derived at request time from its live grants.
credential → principal → groups → grants → filesIf an agent may not see a document, what does it get?
Nothing that reveals the document exists. Denied content is never returned, listed, matched or counted. From outside, refused and absent look identical.
Does a grant on a folder cover files added later?
Yes. A folder grant reaches content added after it. A grant on a single file reaches only that file.
Can two people have different access to the same folder?
Yes, and that is the normal case. Each grant is independent, so one folder serves an approver, an editor, a reader and an agent at once. A grant on a path inside the folder can only widen what the folder already gives.
Can I make an exception for one file inside a folder someone can edit?
No. Access only ever adds, so there is no deny rule and no exception list. Keep the sensitive path outside every broad grant instead, which is why a grant's scope is a path rather than a folder. A subtractive rule was removed on purpose: it broke the monotonicity the read filter depends on.
Can I grant to a group instead of naming people?
Yes, and a group nests at any depth. A grant to a group reaches every current member, so adding someone to the group is how you grant them. Removing them from the group is how you revoke.
Do people and agents use the same permission system?
Yes, both are principals and take the same grants. The only difference is how they authenticate: a person signs in through the browser, and an agent carries a minted token. Nothing in the authorization model knows which is which.
Do labels affect who can see a file?
No. Labels drive search and filtering only. Access comes from grants on the file and the folders above it.
Can my agent tell me who can read a document?
Yes. Ask it, and it calls who_can_read, which lists the people and groups that reach a folder or document, directly or by inheritance. It names people and never shows their content. It only answers for something the asker can already reach.
who_can_readSharing
Can I share a folder with someone outside my organization?
No. Sharing reaches members of your organization. Invite the person to the organization first, then share with them.
Can I share with someone by email?
Yes, if the address is the one they sign in with and they are a member here. It becomes the same grant as picking them from the list.
Can I see what I am about to share before I send it?
Yes. The share form shows what is in it as you can see it. It also says how many files are withheld from you.
Your content
Can I watch an agent edit a document I have open?
Yes. The editor is live, and an agent's write arrives in the page you are reading without a reload. Every write is still its own version, so you can see exactly what the agent changed and restore an earlier one.
What can I put in it?
Text and markdown documents, and binary files. Documents get a collaborative editor and their own version history. A dragged-in directory lands as one commit.
Can I see what a document used to say?
Every document keeps its own line of versions, and editing one never rewrites another. History opens from the editor and diffs a version against the one before it. Restore this version puts that text back as the newest version.
What happens if an agent writes something wrong?
The agent's write becomes a version of its own, and the version before it is still there. Open the document's history and restore the older one. The audit trail names which principal made each write. Restoring is a console action today, so an agent cannot undo its own.
Can it stay in sync with GitHub or Google Drive?
A connector mirrors a repository or a Drive folder into a folder of its own, created where you add it, and keeps it current. That folder is read-only here because upstream owns it. Stored credentials are encrypted and never returned to the console.
Is there a review step before new content is readable?
No, content is live the moment it lands. Uploading grants you the file, and a connector grants the readers you chose at install. Nobody else reaches it until you widen that.
Can I get my content back out?
Yes. The REST API reads any document you can reach.
Isolation, audit and revocation
How is my organization isolated from anyone else's?
Two independent walls. Postgres row-level security separates organizations. A relationship-based authorization graph decides who reaches what inside one.
What is in the audit log?
Every retrieval, navigation, write, grant, token mint and policy change, including the ones that were refused. Each record carries a hash of the one before it. A removed entry breaks the chain.
record_hash = sha256(payload + prev)How fast can I cut off access?
Immediately. Revoking a token or a grant is a database change, and the next request sees it. There is no cache to wait out and nothing to re-mint. Someone with the document already open in the editor loses it too.
What happens to their access when someone leaves?
Revoke their grants and their tokens, and the next request sees it. Their principal stays, because the audit trail refers to it and a deleted principal would leave unattributable records. Content they wrote stays where it is, under its own history.
Do you train models on my content?
No. Not our models and not anyone else's, and your content is never included in a training set. agentleFS makes no call to any model at all. Search is indexed on our own systems with a local algorithm, so building the index sends your content nowhere.
Can I use a local model so nothing leaves my machine?
The answering happens in the client you connect rather than here. We serve that client the documents you have given it access to, and it decides which model reads them. Point it at a model running on your own machine and no model provider is in the path.
Can I delete my data completely?
Yes. Deleting a document hides it everywhere and keeps it recoverable by you. Erasing one destroys its content, its history, its comments and its name, and nothing brings it back. An approver of the document does both from the console.
How do I remove everything, including my organization?
Write to the address on the privacy page and we remove it. There is no self-service control for a whole organization or a whole folder yet. We would rather say that than point you at a button that does not exist.
Where do I read the privacy policy?
At /privacy, linked from the footer of every public page. It carries the long version of the model-use answer above, what we store, and how to get it deleted.
/privacyCan an agent be given narrower access than the person who runs it?
Yes, and that is the intended shape for anything unattended. Give it its own principal and grant it only the folders it needs. Mint its token with an expiry.
admin mint-token --principal=<id> --roles=<subset> --ttl=<secs>
