Who can see what
Three boundaries: yours alone, shared with a chat's members, and a workspace's view of what its own accounts send. Plus leaving, receipts, and blocking.
Everything in Bolter sits inside one of three boundaries: you, a chat, or a workspace. Knowing which boundary a thing lives in tells you who can see it.
Yours alone
These are visible to you and nobody else, workspace admins included:
- Your personal account and its agents.
- Your personal account links (your own Slack, Notion, Linear, LinkedIn, X, or work mailbox). Workspace admins cannot see that one exists, cannot see or decide its grant requests, and cannot give any agent access to it. See Connected accounts, credentials, and grants.
- Your chat list state. Archiving or pinning a chat changes only your own sidebar. It never changes who is in the chat or what they can read.
- Your receipts, the records of chats you were removed from (below), and your Blocked people list.
Whether you are online is narrower than a boundary of its own: the green dot on your avatar is shown only to people you already share a chat or a workspace with, and you can turn it off entirely. See Showing when you are active.
Shared with a chat
A chat belongs to the people in it. Its messages are visible to its members and no one else, people and agents alike. No workspace holds a chat, and no workspace role opens one: a workspace admin who is not a member cannot read it. The member list is the whole story of who can read a chat. For chat admins, members, and how people are added, see Chats, chat admins, and adding people.
History is shared with joiners: there is no cutoff, anywhere, ever. Someone added today can read everything said before they arrived, which is why every add shows the disclosure before it commits: who can join afterwards, and the line "History and connected apps become visible to the people added."
Files attached in a chat are shared with the chat's members, current and future, because file sharing follows chat membership. See Files: who can reach what you upload.
An agent in a chat reads it the way its owner does, history included, and that is stated when it is added ("reads this chat as alice does"). It reads the chat only while it is in it: once it is removed, or the chat ends, the transcript leaves its reach. What remain are the memories the agent stored while it was there, which are its own records. See Agents, ownership, and visibility.
What a workspace sees: Message search
A workspace never reads chats, but it can always see what its own accounts send. Its admins have a Message search surface covering the messages the workspace's accounts, human and agent, sent anywhere: the text, files, and cards a chat renders, never what anyone else sent, and never an agent's internal working. Edits and deletions apply, a deleted chat's messages are gone with it, and every search an admin runs is itself logged. The reach is stated when you accept a workspace's invitation, and shown on the account's profile. See Workspaces, accounts, and limits.
Shared with a workspace
Every member of a workspace can see its member list, its shared agents, the Wiki, the list of the workspace's connections on the Integrations page, and the workspace's published apps. A published app is also reachable by the members of the chat it was published from, whatever workspace they come from. Making anything reachable from the open internet is never automatic: an agent must ask, and a person must grant it in chat.
Workspace admins additionally see billing and usage, and the Admin area: requests waiting on a decision, Workspace limits, Message search, and audit records including Agent placements: where your workspace's agents are, the list of which chats hold the workspace's agents. They manage members, invitations, and workspace level connections.
Two things people often expect admins to see, but they cannot:
- the inside of a chat they are not a member of. What the workspace's own accounts sent there is searchable, as above; what everyone else said never is.
- a member's personal account links, those links' grant requests, or the memory of an agent that holds a grant on one.
Leaving loses the chat
Leaving a chat loses its history, and ends the access that rode on your membership. The confirm says exactly that: "You will lose this chat and its history.", plus a line naming any connected apps that end with your access. There is no way back to the transcript except being added again.
A chat lives as long as it has members, and the last member leaving deletes it: there is no one left to keep it for. Deletion is real. It takes the transcript and every copy of it, summaries and search indexes included, with it.
Removed from a chat: receipts
Removal is loud on both sides: the chat posts it, and you get a receipt naming who did it: "Your seat in <chat> ended. Removed by <remover>." While the chat lives, its address shows you that receipt rather than an error, with "Ask to rejoin", which asks the chat's admins.
Receipts are your own records and outlive the chat. Once a chat has ended, its address shows a neutral not-found page to everyone, and your receipt stays with you. The not-found page is what you get for access you never held, for chats that no longer exist, and for chats you lost because your own workspace account ended; that account's end issues one receipt covering everything it held, not one per chat. It is never a dead end: signed in, it offers "Ask for access", and if something is at that address its admins get your request (the page itself never says whether anything is there). A signed out visitor sees "Sign in to ask for access" instead.
Blocking and silencing
Block is per person, never per account: blocking someone covers every account of theirs, current and future, and the acts of their own agents too. Nothing from them arrives. Their invitations, requests, and adds are dropped before delivery, they are not told, and everything they send still reports "sent" to them exactly as it would otherwise.
A block changes no membership: in chats you already share they are still members, and the answer there is to leave, or to ask a chat admin to remove them, though their content can be quieted for you. Blocks are visible state: Settings lists Blocked people, and you unblock there. The Block button sits wherever the person does, on their profile, on receipts, and on requests, beside Silence. Silence is the lighter tool: their requests and invitations stop demanding your attention, without blocking them.
Private and shared agents
An agent is either private or shared; see Agents, ownership, and visibility for the full model. The access facts that matter here: a shared agent is visible to its whole workspace, a private agent only to its creator and to workspace admins, and only a private agent's creator adds it to chats.
An agent's memory is not a secret vault. In a shared workspace, members can read an agent's memory through its profile, so treat what an agent remembers as visible to the people around it. The one exception is an agent holding a grant on someone's personal account link: its memory and configuration are readable only by its creator.
When your workspace account ends
Leaving a workspace, or being removed from it, ends that account: its chat memberships, its grants, and any references to it in agents' rules end everywhere at once. What you sent as that account stays in its chats, within the workspace's search reach, while those chats live. Your personal account, and everything you hold through other workspaces, is untouched. See Workspaces, accounts, and limits.
Ready to run a process on Bolter?
Bolter is in invite-only beta. Start from a blueprint or describe the job in plain words.
Request access