Access bundles: scoped AI access you define once and reuse everywhere
An access bundle is a named set of credentials, scopes, and instructions you attach to a team, a project, a channel, or an AI client. Define it once, and every agent that inherits it gets exactly that access and nothing more.
Works across Claude, ChatGPT, OpenClaw, Hermes, and any MCP server
AI connectors grant all or nothing. Bundles are how you fix that.
Connect Claude or ChatGPT to Drive, Gmail, or an internal API and the grant is workspace-wide: every seat can reach whatever the token can. There is no reusable, scoped unit of access to attach per team, so the boundaries your identity provider enforces do not survive the connector. An access bundle is that missing unit, and PortEden enforces it for every AI client you run.
One connection, the whole workspace can read it
Connect Claude or ChatGPT to Drive or Gmail and the token is granted once, for the whole workspace. Any seat can then ask the connector for anything it can technically reach. The sales team's assistant and the finance team's assistant pull from the same over-broad grant, because nothing narrows what each one is allowed to see.
Read access quietly turns into send and delete
A connector that can send mail, share files, or delete records hands the agent every one of those actions. Under a confused workflow or a prompt injection, the AI can do things no one approved. Its real power becomes the sum of every scope it was ever given, not the small slice the task actually needed.
When the work ends, the access stays
A grant pasted from one tool into the next has no single off switch. A project wraps, a contractor leaves, and the access lingers until an audit turns it up months later. Without one named bundle to revoke, cleanup is a manual hunt across every AI client.
Access Bundles, Scoped Per Team and Enforced Per Request
This is the model. Define a bundle once, attach it to a team, a channel, or an AI client, and every tool call is decided against the bundle that seat inherits. Read where reading is enough, write only where work happens, and anything out of scope is denied at the firewall.
What an access bundle is
An access bundle is a named set of credentials, scopes, redaction, and instructions that an agent uses wherever the bundle is attached: a team, a Slack channel, a project, or a specific AI client. You attach different bundles to different groups, so the access a seat gets follows the group it belongs to, not whoever is asking. PortEden authors each bundle as a policy group mapped from your identity provider and enforces it on every AI client you run.
Gets the docs, code, and monitoring bundles. Read on design docs and dashboards, scoped write on repos and tickets.
Gets a read-only data bundle. It can answer pipeline questions, and it cannot write anything.
Gets monitoring plus code-write. It can read alerts and open a fix, with destructive actions confirm-first.
From a setup suggestion to an enforced limit
Group access by what each connection is for. Read where reading is enough, scoped write only where work happens, and high-impact verbs gated or confirm-first. PortEden turns each of these into a hard action limit enforced on every tool call, not a setup-time suggestion you have to trust an agent to respect.
| Connection type | Recommended access | How PortEden enforces it |
|---|---|---|
Knowledge and docs | Read | Read-only action limit, with visibility and data reduction stripping sensitive fields before the model sees them. |
Communication | Read and draft | Read and draft mail; send, reply, and posting to channels stay confirm-first. DMs are excluded by default and PII is redacted from message bodies before the model sees them. |
Issue tracking | Read and write | Scoped create and update, with confirm-first on destructive actions and account scope pinned to the boards in play. |
Code | Read and write | Scoped read with confirm-before-write on branches and pull requests. A per-AI-client override lets one client write while another stays read-only. |
Data warehouse | Read | Read-only action limit. Data reduction masks identifiers and PII in result sets before they reach the model. |
Monitoring | Read | Read-only action limit, with account scope narrowed to the services and time range in play. |
Go-to-market | Read | Read-only action limit, with contact rules excluding internal-only records and data reduction tokenizing customer PII. |
One bundle, enforced everywhere
A bundle is one named set of access
Group the credentials, scopes, redaction, and instructions a job needs into a single named bundle, then attach it to a team, a Slack channel, a project, or an AI client. PortEden authors it as a policy group and maps it from Okta, Microsoft Entra ID, or Google Workspace, so you define a bundle once and reuse it everywhere it belongs.
Recommended access, actually enforced
Read where reading is enough, write only where work happens. In a setup wizard that is a suggestion. At PortEden it is an enforced action limit on every tool call, applied with the six access layers and field-level redaction, so the agent can never exceed what the bundle allows, even under a prompt injection.
The same bundle on every AI client
A bundle is enforced where the agent calls a tool, not inside one app, so it covers Claude, ChatGPT, Cursor, Grok, OpenClaw, and Hermes alike. The agent never holds the raw credential. Revoke the bundle, or drop the user from its IdP group, and access ends across every client and integration at once, with a signed audit record.
Access Bundle Questions
What is an access bundle?
How is a bundle different from an OAuth scope or an IdP group?
How do access bundles relate to PortEden policy groups and RBAC?
Can one bundle apply to Claude, ChatGPT, OpenClaw, and Hermes at once?
How granular can a bundle get?
How do inheritance and overrides work?
How do I revoke a bundle, and how fast does it take effect?
What audit evidence do bundles produce, and does PortEden see prompts?
Keep exploring
Define the bundle once. Enforce it on every AI client.
Book a 30-minute walkthrough. Bring your security questionnaire; DPA, subprocessor list, and pen-test summary available on request.