Scope Early access
Give each AI a window, not the whole building.
Every AI tool asks for access to everything. qbrin connects to your systems once, then hands each tool or agent only the sources its job needs. Pick a job and see its window.
- Per agent and per key
- Preview from 30 days of use
- An unreadable scope reads nothing
Granted today
6 sources
168,250 documents
Used, 30 days
3 sources
229 documents cited
With this scope
2 sources
27,630 documents
3 · Choose what the window shares
- 48,210in workspace–Out of reach
- 3,120in workspace–Out of reach
- 21,950in workspace3Would cut
- 67,340in workspace–Out of reach
- 18,420in workspace212In window
- 9,210in workspace14In window
Bars show documents each source supplied to the job’s answers in the last 30 days (sample data).
With this scope, a code-review bot can reach 2 of 6 sources: GitHub, Jira. Over the last 30 days its answers cited 229 documents. This scope would have cut 3 (1%), from Drive (3).
It reads code and the tickets behind it. It has no reason to open mail or chat.
Sample figures for illustration. In the console they come from the agent’s own last 30 days of cited documents.
The problem
Every tool. Every byte.
Every AI tool asks for broad access: read all repos, read all mail, join every channel. It is faster to say yes. Ten tools later, ten vendors hold a key to everything, and nobody can say what any of them can see. The risk is not the sum of the tools. It is every tool times every byte you own.
357
agents, one corpus
In qbrin’s own deployment, one organisation carried 357 agents, and every one of them searched the same corpus. Retrieval was scoped by organisation and by nothing else. That is the gap Scope is built to close.
How it works
Four steps. One door.
You choose what a job needs. qbrin checks the choice against real use, then holds the line at its own retrieval.
- 01
Connect once
qbrin connects to your mail, chat, drive and code tools one time. The AI tools you want scoped call qbrin instead of each system.
- 02
Set what a job needs
Pick the sources for one agent, or for one AI-tool key. A scope can only narrow what your organisation already allows.
- 03
Preview before you save
qbrin replays the scope against the agent’s last 30 days of cited documents and shows what it would have cut. Until scopes are switched on, a saved scope is stored but not applied, and the console says so.
- 04
qbrin enforces at its own door
The window is applied where qbrin already retrieves: its search, and its MCP gateway for outside AI-tool keys. A scope that cannot be read means the tool reads nothing.
01 · For agents
Scope for agents: a source list per job.
Each agent gets its own list of sources. A baseline set for the whole organisation applies to every agent, and an agent can only narrow it further. The editor shows every source, what the agent cited from it in the last 30 days, and what your scope would have cut.
- Tick sources one by one, or choose only what the agent used
- An unreadable scope means the agent reads nothing, never everything
- Applied at qbrin’s own retrieval, the place every answer comes from
What this agent can read: Only gdrive, slack.
| Allowed | Source | In workspace | Cited, 30 days |
|---|---|---|---|
| Not allowed | gmail | 48,210 | 9 |
| Not allowed | calendar | 3,120 | – |
| Allowed | gdrive | 21,950 | 131 |
| Allowed | slack | 67,340 | 64 |
| Not allowed | github | 18,420 | – |
| Not allowed | jira | 9,210 | – |
Over the last 30 days its answers cited 204 documents. This scope would have cut 9 (4%), from Gmail (9).
Cited means a document an answer used, not everything the agent searched. A scope can only narrow what your organisation already allows.
02 · For AI tools
Scope for AI tools: a key with a window.
An outside AI tool connects with an API key. Give that key a source list and it works only through MCP, where qbrin applies the window. Other qbrin APIs refuse a scoped key, because they would return everything.
- A scoped key reaches only its sources, and only through MCP
- Every other qbrin API refuses it
- Narrow or revoke it from the same inventory that Know shows
- AI toola code-review bot
- Scoped keygithub, jira
- qbrin MCPapplies the window
- Windowonly those sources
- Data scope
- github, jira
- Through MCP
- Allowed
- Other qbrin APIs
- Refused
A key with a scope works only through MCP, which is how AI tools such as an editor assistant connect. Other qbrin APIs refuse it, because they would return everything.
Keys have no per-key citation history, so there is nothing to preview a key’s scope against. Start narrow and widen it only if the tool cannot do its job.
Residual exposure
What qbrin cannot narrow.
qbrin narrows what qbrin hands out. It cannot narrow a grant it does not hold.
Through qbrin
An agent, or an AI tool with a qbrin key. It asks qbrin for data, and qbrin gives it only the window you set.
Straight to your systems
An app with its own OAuth grant to your mail, chat or code. It never asks qbrin, so a scope cannot reach it.
Roll it out
A safe order. One agent first.
Scope is built so the first step cannot break what already works. Nothing changes for an agent or key that has no scope.
Deploy with the switch off.
Scopes ship behind one switch, and it starts off. A saved scope is stored but not applied, and the console says so.
Scope one low-stakes agent.
Use the preview to choose its sources from its last 30 days. Saving a scope for one agent changes nothing for an agent that has none.
Check the Defend feed.
Look at what the gate is catching, refusing and holding, and read the preview for that agent, before you change anything else.
Turn it on.
Switch scopes on. Scoped agents and keys are held to their windows. Everything without a scope stays exactly as it was.
Give your AI the task, not your company.
Book a demo to see how a scope is chosen from an agent’s last 30 days of use. Scope is in early access.