# AI permissions

## Open AI Permissions

Open **Settings > AI Permissions**. Each switch controls a separate capability,
so Memory access, Library access, Profiles, guarded changes, and deletion can be
configured independently.

Changing a switch affects connected clients. It does not delete saved Memories,
Profiles, Templates, or API keys.

## Why separate controls help AI

A connected AI works more predictably when the available tools match the task.
Separate controls allow a connection to search Library Templates without
receiving Memory tools, or use Memories without receiving creator workflow
tools. Profile access and destructive actions can remain disabled when they are
not needed.

This limits unnecessary access and makes the available capability set easier to
understand. Permissions define what a connected tool may request; they do not
instruct the AI to use every enabled feature.

## Access Memories through MCP

When enabled, connected MCP clients can see the Memside Memory tool group. When
disabled, those tools are removed from the available MCP tool list.

Disable this setting when a connected client should use Library Templates but
should not access Memories.

## Access Library through MCP

When enabled, connected MCP clients can see the five Library tools for public
search and owned creator workflows. When disabled, Library tools are removed
from the MCP tool list while Memory tools can remain available.

Example configuration for public Template discovery only:

```text
Access Memories through MCP: Off
Access Library through MCP: On
```

## Allow connected AI access to Profiles

The **AI Profile - Allow Connected AI Tool Access** switch is the account-level
control for Profile retrieval through supported MCP and API clients.

Profile access requires both:

1. the account-level switch to be enabled; and
2. **Available to AI** to be enabled on the selected Profile.

Turning off the account-level switch blocks all connected Profile reads without
changing the saved setting on each Profile.

## Require MCP approval for Memory changes

**Memory Changes - Require MCP Approval** is a Beta control for supported MCP
clients. When enabled, supported clients present an approval prompt before a
guarded Memory change is applied.

Client support varies during Beta. A client that does not support the approval
flow cannot apply a guarded change. This control applies to MCP, not ordinary
website editing.

## Allow AI deletion requests

**Memory Deletion - Allow AI Requests** permits a connected AI tool to request
permanent Memory deletion. Every deletion still requires the explicit
confirmation phrase generated for that specific Memory.

Keep this setting disabled when deletion through connected tools is not needed.
Enabling the switch does not authorize silent or bulk deletion.

## Common configurations

### Read Memories and search Library

Enable Memory access and Library access. Keep deletion disabled unless a clear
workflow requires it.

### Use Library without Memory access

Disable Memory access and enable Library access. This exposes Library tools
without exposing the Memory tool group.

### Keep Profiles private from connected tools

Disable account-level Profile access. Saved Profiles remain available for
management inside Memside.

### Maximum confirmation for Memory changes

Enable the MCP approval requirement and keep deletion requests disabled.

## After changing permissions

Some clients cache their tool list. Start a new conversation or reconnect the
Memside integration if a newly enabled tool does not appear or a disabled tool
remains visible.

## Related pages

- [User AI Profile](/product/user-ai-profile/)
- [Connection overview](/connect/mcp-and-api/)
- [Use Library with MCP](/library/use-with-mcp/)
- [Security and Privacy](/help/security-and-privacy/)
