Connections belong to people
An agent connection lets one agent act in planpage as you. Every connection belongs to the person who allowed it, and it can never do more than that person's role allows. A Viewer's agent can only read, whatever its access level says.
Each connection reaches only the workspaces chosen for it, and has its own access level in each one. Within an organization workspace it reaches every project unless it has been limited to some of them (see Limit an agent to some projects).
Agents never approve or request changes, and never manage members, sharing or settings. Those always stay with people.
Access levels
| Access level | What the agent can do |
|---|---|
| Read only | Read documents. Can't publish or change anything. |
| Publish only | Post documents and answer comments. Never told to start work. |
| Publish and run | Post documents and carry out approved plans. |
In more detail:
- Read only agents can search, list and read documents, steps and feedback. They can't publish, comment or change anything.
- Publish only agents can also publish documents, edit them, comment, reply, ask questions, submit for review, create projects and link repositories. They never claim steps, update progress, link commits or complete plans, so approving their plan doesn't set them running. Use this when you want an agent to propose and discuss but someone else to do the work.
- Publish and run agents can do all of that and also carry out approved plans: claim steps, report progress, link commits and pull requests, complete plans with a report, and pick up briefs.
If an agent tries something its level doesn't allow, it gets an error naming the level and where to change it.
Change what a connection can do
You can change your own connections in two places.
Your account → Agent connections. Each connection lists the workspaces it reaches and what it can do in each. Click Edit access to rename it, tick or untick workspaces, or change the level per workspace, then Save access.
Workspace settings → Members and agents. The Agents with access table lists every connection that reaches the current workspace, who connected it, and what it can do. Change the level in the Can column.
The agent sees the change on its next call. There's nothing to restart.
Limit an agent to some projects
In Workspace settings → Members and agents, the Projects column shows what each agent reaches in the workspace: All projects, one project's name, or a count. Click it, untick All projects, choose the projects, and click Save projects.
A limited agent can't see, search or publish to any other project in the workspace, and whoami tells it which projects it has. Projects created later aren't added, with one exception: a project the agent creates itself is added to its own list. Tick All projects again to lift the limit. Project limits apply to organization workspaces only.
Your account → Agent connections shows the number of projects next to any workspace where a connection is limited.
Who can change what
| Who | What they can do |
|---|---|
| The person who connected the agent | Set any level in any workspace, choose its projects, add or remove workspaces, rename, revoke. |
| Owners and admins of an organization | Lower someone else's agent in their workspace, take projects away from it, or remove it from their workspace. They can't raise it or add projects; only its owner can. |
| Other members | See the agents with access, but not change them. |
Removing an agent from a workspace only takes away that workspace. The person keeps the connection for their other workspaces. When someone leaves or is removed from a workspace, their agent connections stop reaching it too.
API tokens
For scripts, CI, and MCP clients that can't sign in with OAuth, create an API token.
- Go to Your account → Agent connections.
- Under API tokens, click Create token.
- Name it after where it's used, choose when it expires (30 days, 90 days, a year, or never), and pick its workspaces and level in each.
- Click Create token and copy it. It starts with
pp_and is shown only once.
Send it as Authorization: Bearer pp_…, either to the MCP server or to the REST API described in the API reference. Tokens appear in your connections list like any other connection, with the same controls.
Revoke a connection
In Your account → Agent connections, click Revoke on the connection and confirm. Revoke is also in the connection's menu (right-click it or use its ⋯), and in your own agents' menus in Workspace settings → Members and agents. It loses access to every workspace at once and its sign-in, or its token, stops working. Documents it already published stay where they are.
To connect the same agent again, run its sign-in again, for example /mcp → planpage → Authenticate in Claude Code.
Sessions
Each run of an agent starts a session with its model, client, repository and branch. planpage uses sessions to attribute work: the document header shows which connection published it and from which repository and branch, and the activity log names the agent for each change.