AI Chat and agents
Configure a provider, review AI changes, protect sensitive content, and connect approved desktop agents with scoped leases.
VaultGuard Sync (Cloud): AI Chat and agent access
VaultGuard AI tools use the same selected-vault, path-permission, hidden-path, and audit boundaries as other protected operations. Enabling AI does not give the model unrestricted access to the vault.
Choose the right AI surface
Built-in AI Chat
Use the panel inside Obsidian for questions, summaries, structured inspection, and reviewable note changes. It is the simplest route for everyday knowledge work.
External Agent Access
Use the optional desktop agent bridge when an approved external client such as Codex, Claude Code, or another supported MCP client needs governed VaultGuard tools. It is disabled independently from AI Chat and requires a time-bounded lease.
Configure AI Chat
- Open VaultGuard settings โ AI Chat.
- Choose the supported provider or subscription transport you are authorized to use.
- Complete provider sign-in or add the provider credential locally.
- Select a compatible model.
- Choose whether writes require a review confirmation. Confirmation is the safer default.
- Open VaultGuard Chat: Open AI chat panel.
Provider accounts, subscriptions, and per-token charges are separate from the VaultGuard Cloud plan unless a commercial agreement says otherwise.
What AI Chat can do
Subject to the current user's permissions and the active tool surface, AI Chat can:
- discuss permitted knowledge in the selected vault;
- search and inspect allowed notes;
- create or revise Markdown through reviewable mutations;
- explain effective access;
- propose or set supported file permissions with confirmation;
- work with supported photos or pinned documents; and
- use bounded history, template, or automation tools when those capabilities are enabled.
Unsupported tools fail closed. The model cannot read hidden directories or a VaultGuard exclusion merely because the prompt asks it to.
Review writes and permission changes
Keep confirmation enabled for normal use. Review:
- the target vault and file;
- the proposed diff;
- who will gain or lose access;
- whether the request moves content to an external AI provider; and
- the expected result before approving.
Changing permission mode does not disable vault scope, hidden-path blocks, encryption, or server-side permissions.
Provider privacy
A remote provider receives the content required for the requested turn. Ask narrow questions and avoid whole-vault sweeps for sensitive material. The provider's own retention, training, regional, and account policies still apply.
VaultGuard stores conversation history locally through its protected history path and audits governed tool actions without intentionally copying note bodies into the audit log. Metadata about actions remains visible to the service.
Use external Agent Access safely
- Enable the separate Agent Access module on desktop.
- Sign in and bind the intended vault.
- Create a lease with the narrowest available scope and duration.
- Connect the approved client without placing the bearer token in a note, prompt, screenshot, or source file.
- Revoke leases when the task ends.
An external lease does not automatically receive every in-app AI capability. Exact-version recovery and governed Obsidian automation can remain confined to separately gated in-app paths.
When an action is denied
Do not ask the model to bypass the control. Check the selected vault, user membership, path rule, optional module, lease scope, attachment type, and confirmation state. If a broader permission is genuinely needed, an authorized administrator should change it through the normal permission workflow so the decision remains reviewable and audited.