Trust model
The access, audience, sharing and approval boundaries that govern OpenTag’s work.
Access is scoped
OpenTag works within a workspace and the source access granted to it. Slack channel membership, the conversation's audience and connection-sharing choices govern what can be used.
Automatic joining of new internal public channels is enabled by default after setup. Admins can disable it or exclude names. Private and Slack Connect channels require invitation. See Channels and access.
Sharing is explicit
An integration can be private, shared with the team, or limited to document categories and verified existing access. A Team grant can let teammates use the connecting account's authority; it is not equivalent to every teammate connecting their own account.
Review the grant before sharing an account. How connections work explains each permission model.
Read-only limits changes
A read-only connection prevents the write operations excluded by that connection. Use it for accounts where OpenTag should inspect information without changing it.
A write-capable connection can execute operations without a separate approval card for every change. Gmail sends have explicit, message-bound approval; secure credential entry and approval-declared skill scripts also wait for a person. Approvals describes these boundaries and routine behaviour.
Audiences remain distinct
Personal memory and personal wiki context are separate from shared company knowledge. Private-channel context is restricted by the room and verified membership. Slack Connect answers do not gain unrestricted access to internal company context.
Review where a result will be posted before asking for information from a connected account. Access to a source and the choice to publish its contents are different decisions.
Check results and records
Source citations, conversation records and routine history help you inspect the work. They do not guarantee a correct answer. Check the evidence for consequential conclusions and review records after changes.
For storage and deletion, see Data handling. For the current security packet and compliance status, use the security page or email team@tryopentag.com.