Platform · Scope Access
Scopes & Access Control
Every configuration, connection, policy, and agent in Telara lives at a scope. Scopes control who can see and use a resource — from your entire organization down to just you.
The four scope levels
From org-wide to personal
Scopes form a hierarchy. Organization is the broadest — anything at this scope is shared across your entire company. Personal is the narrowest — only you can see and use it.
Available to everyone in your org
Company-wide GitHub access, shared Jira connection
Available to a specific team and its members
Engineering team Slack channels, design team Figma access
Private — only you can access this
Your personal GitHub token, private Notion workspace
Why this model
Org-wide resources should work like shared infrastructure
Organization scope
Think of it like HR policies or company-wide tools — everyone has access, no one needs to set it up individually. A connection configured at the organization scope is available to all teams and members automatically.
Personal scope
Private resources are only visible to you. A personal API token or private notebook stays yours — it cannot be shared or made visible to others without being re-created at a broader scope.
Team scope
Resources scoped to a team are visible to all members of that team. Useful for team-specific integrations, shared configurations, or permission policies that apply to one group but not the whole company.
Deployment scope rules
A configuration can only be deployed within its scope
When you deploy a configuration, the deployment scope cannot be broader than the scope the configuration itself was created at. This prevents a private or team-specific setup from accidentally being exposed org-wide.
Example: scope escalation is blocked
If "Infra Team MCP" was created at the Team scope, you cannot deploy it to Organization. It can only be deployed to Team or Personal. To make it org-wide, an admin would need to create a new configuration at the Organization scope.
| Configuration scope | Organization | Team | Personal |
|---|---|---|---|
| Organization | |||
| Team | |||
| Personal |
What lives at each scope
Scope applies to all resource types
Configurations
An organization-scoped configuration is available for every team and user to deploy. A personal configuration is only visible to you.
Connections
Connecting an integration at the organization scope shares credentials org-wide (useful for shared service accounts). Personal connections use your own credentials.
Permissions & Policies
Policies created at the organization scope act as defaults for everyone. Team or project policies apply only to members of that team or project.
Automations
Workflows defined at the organization scope can be triggered by anyone. Team or personal automations are only visible and runnable within that scope.
Related
For how credential ceilings interact with these scopes, see Tool and group ceilings.



