Sharing posture
Whether your own memory, files and skills may be read by the agent in a thread other people are in — Isolated by default, Open as an explicit, bounded, labelled and audited exception.
Updated 9/15/2026
Threads can have more than one person in them. When you send the next prompt in a thread a colleague is also in, the agent's reply is read by both of you — so the question is whether the agent may bring your personal memory, your library files and your own skills into a reply someone else reads. The sharing posture answers it, in code, at four layers.
The four layers
| Layer | Who sets it | Values |
|---|---|---|
| Account | an owner (Settings → Privacy) | Isolated (default) · Open |
| Project | a project admin | Follow account · Isolated |
| You | you (Profile → Privacy) | Follow account · Isolated · Open |
| Thread | the person who opened it | Follow · Isolated · Open |
The four compose fail-closed: a turn is Open only when the account, the project (if the thread has one), your row and the thread all say Open. One Isolated anywhere wins. "Open" at the account means members may opt in — nobody is opted in by it.
Isolated — the default
In a thread other people have written in:
- your personal memories are not recalled into the reply;
- what the agent learns from the thread is saved to the account, never to you — a fact three people established belongs to the account;
- your own skills are not on the agent's belt;
- your library files are reachable only when you attach them.
A thread only you have written in is your own: everything works as it always has.
Open — bounded, labelled, audited
On your own live turn (you pressed send — never a schedule, a webhook or another agent), in a shared thread that resolves to Open:
- up to 8 of your personal memories join recall, each labelled [from <your name>'s personal memory] and kept in its trust tier;
- up to 200 of your library files are listed by name; text-extractable
ones can be read through
carried_file_read, images and other binaries stay names until you attach them; - the agent is told, in one paragraph, what Open changes and what it does not, and to use only what the request needs.
In your own thread, Open lists the files and project skills of the 25 most recent shared threads you wrote in (out of the 100 newest), so a document from last week's shared conversation is one path away.
The other participants see a muted line — Used <name>'s personal context — never the content. One audit row per run lists exactly what was carried, by origin and id.
What Open never does
- widen writes;
- carry another participant's resources on your turn;
- carry credentials, connections or ChatGPT grants;
- carry message history between threads;
- run for a non-human trigger;
- cross accounts;
- bypass a private thread's participant check;
- skip security screening;
- change the ledger rule.
Your own skills are not carried into shared threads until the security screener can review them — a stated gap, not a silent one.
Where to set it
- Account — Settings → Privacy — personal context in shared threads.
- You — Profile → Privacy, one choice per account you belong to.
- Project — the project page → Personal context in shared threads.
- Thread — the
Sharing:chip in the thread header, for the opener.
Ask Zero
Ask a question about connect0 and get an answer grounded in the docs, with links to the sources. Signed in? Zero answers with your account in mind.