- Who owns the connection - the workspace (aka the credential is a shared key) or just you
- Who can use it - workspace members and agents, or only you and agents you explicitly grant it to.
- What it can access - the tools, resources, and provider permissions available through the connected account.
Choose workspace or personal
The scope belongs to the connection, not the app. When an app supports both connection types, the same app can have a workspace connection and one or more personal connections.
Workspace connections
A workspace connection gives Ando access to a shared company system. It belongs to the workspace, even if one person completes the setup. Use a workspace connection when people and agents should work from the same company account or shared source of truth. For example:- Connect Linear so agents can find, create, and update issues without each member connecting it separately.
- Connect GitHub so engineering agents can investigate issues and open pull requests in company repositories.
- Connect Notion so agents can reference a shared knowledge base.
- Connect a support system so agents can work from shared customer conversations.
Personal connections
A personal connection gives Ando access through an account that belongs to you. You manage it and choose whether agents you created can use it. Use a personal connection when the account, identity, or data should remain yours. For example:- Connect Granola for your meetings and notes, then give only your personal agent access.
- Connect Notion for private pages that are not part of the company knowledge base.
- Connect GitHub when an agent needs to work through your individual GitHub account.
The same app can be both
GitHub is a common example:Understand permission boundaries
Connection scope answers who owns and can use the connection. It is only one layer of access.- Provider permissions are the permissions granted when the account is connected. Ando cannot reach beyond them.
- Agent access determines which agents can use the connection. Personal connections must be granted explicitly to an agent you created.
- Tools are actions such as searching GitHub or creating a Linear issue. Disabled tools cannot be used through that connection.
- Resources narrow where tools can act when an app supports resource controls. For example, a GitHub connection can be limited to selected repositories.
- Approval rules can require your confirmation before an agent uses a sensitive tool.
Before you connect
Check three things:- Ownership: Is the workspace granting access, or are you?
- Audience: Which people and agents should be able to use the connection?
- Access: Which tools and resources should they have, and which actions should require approval?