Skip to main content
Telara

Platform · Scope Access

Scopes & Access Control

Every configuration, connection, policy, and agent in Telara lives at a scope. Scopes control who can see and use a resource — from your entire organization down to just you.

The four scope levels

From org-wide to personal

Scopes form a hierarchy. Organization is the broadest — anything at this scope is shared across your entire company. Personal is the narrowest — only you can see and use it.

Organization
tenant

Available to everyone in your org

Company-wide GitHub access, shared Jira connection

Team
team

Available to a specific team and its members

Engineering team Slack channels, design team Figma access

Personal
user

Private — only you can access this

Your personal GitHub token, private Notion workspace

broadest access  →  most private

Why this model

Org-wide resources should work like shared infrastructure

Organization scope

Think of it like HR policies or company-wide tools — everyone has access, no one needs to set it up individually. A connection configured at the organization scope is available to all teams and members automatically.

Personal scope

Private resources are only visible to you. A personal API token or private notebook stays yours — it cannot be shared or made visible to others without being re-created at a broader scope.

Team scope

Resources scoped to a team are visible to all members of that team. Useful for team-specific integrations, shared configurations, or permission policies that apply to one group but not the whole company.

Deployment scope rules

A configuration can only be deployed within its scope

When you deploy a configuration, the deployment scope cannot be broader than the scope the configuration itself was created at. This prevents a private or team-specific setup from accidentally being exposed org-wide.

Example: scope escalation is blocked

If "Infra Team MCP" was created at the Team scope, you cannot deploy it to Organization. It can only be deployed to Team or Personal. To make it org-wide, an admin would need to create a new configuration at the Organization scope.

Configuration scopeOrganizationTeamPersonal
Organization
Team
Personal

What lives at each scope

Scope applies to all resource types

Configurations

An organization-scoped configuration is available for every team and user to deploy. A personal configuration is only visible to you.

Connections

Connecting an integration at the organization scope shares credentials org-wide (useful for shared service accounts). Personal connections use your own credentials.

Permissions & Policies

Policies created at the organization scope act as defaults for everyone. Team or project policies apply only to members of that team or project.

Automations

Workflows defined at the organization scope can be triggered by anyone. Team or personal automations are only visible and runnable within that scope.

Related

For how credential ceilings interact with these scopes, see Tool and group ceilings.