← Pando

Claude Desktop, reading and writing your own notes

Claude and Pando, for notes Claude reads and writes.

You open Claude Desktop to plan a week, a trip or a piece of work, and what Claude needs is in your notes: the list you started on Monday, the decision from Tuesday’s meeting, the name you could not remember. So you paste the notes into the chat, Claude works on them, and you copy the result back out by hand. The next time, you paste whichever copy you saved last, and the chat and the notes drift apart.

Keep the notes in Pando and add it to Claude Desktop or claude.ai as a custom connector with the address https://pando.ink/mcp. Once you approve it, Claude reads and searches your outline, writes in it if you chose read and write, and by default has a bullet of its own, “Claude's memory”, to keep what it learns in.

Claude has a memory of its own, and it is a different thing. Anthropic’s help says it is on by default for Free, Pro and Max, off on Team and Enterprise until an owner turns it on, and that Claude "saves memory as a set of individual topics as you chat". You can read and edit each topic in Settings, then Memory. Claude saves them on its own, or when you tell it to remember something, and Anthropic’s memory pages describe no API or connector that reads them from outside Claude; taking them out is copy and paste. Notes are what you write yourself: the list you tick, the draft you correct, in the shape you choose, where another app or agent can reach them too.

Set it up

  1. Open claude.ai or the Claude desktop app, then Customize, then Connectors, then click + and choose Add custom connector.
  2. Give it the address https://pando.ink/mcp and approve it when Claude sends you back to Pando.

Claude Free allows one custom connector, so on Free, Pando takes that one place. On Team and Enterprise an Owner adds it first, under Organization settings, then Connectors; you then find it under Customize, then Connectors, marked Custom, and press Connect. Anthropic is rolling out a two-step Add custom connector dialog, and if yours has two steps, choose Sign in now under Authentication. Under OAuth client, either choice works: Use Claude’s published identity, the one marked recommended, or Register automatically.

In a chat, the + button at the lower left, then Connectors, is where you switch Pando on or off for that conversation. Anthropic’s docs also let you block a single tool: under Customize, then Connectors, select the connector and set the tool’s permission to Blocked. Blocking Pando’s delete tool that way still lets Claude rewrite a line, so it guards against deletes, not changes. A lock, further down, guards against both.

What you approve in Pando

Claude sends you to a page headed Connect Claude?, which says it will create an agent in your Agents list and give it access to your outline. It offers two levels. Read and write your outline lets Claude read every bullet, add, change, move and delete. Read your outline only lets it read and search everything, and refuses every change outside the bullets you gave it to remember in. At either level it starts with your whole outline. Below them, a box ticked by default makes a bullet under Home called “Claude's memory” for it to write in, even at read only; untick it and it remembers nowhere until you assign a bullet under Agents and API keys. The approval has no expiry and works until you revoke it.

What Claude can do in your outline

Pando gives Claude twelve tools. With them it reads a branch or searches every outline it can reach, adds bullets, rewrites, moves and deletes them, and asks what changed since it last looked instead of reading everything again. It can keep what it learns about the work in the bullet “Claude's memory”, if you left that box ticked, apart from your notes. You ask in plain words: add these three to my Groceries list, or what did I decide about the venue.

Claude has no tool that puts back what it deleted. You do that yourself from the Trash, in Settings, which restores a deleted bullet with everything under it; a line Claude rewrote or moved does not come back that way. Changes, set to Hour, Day or Week, lists every bullet written in that time, but not who wrote it, so Claude’s lines and yours look the same there.

Holding it to one bullet

To keep Claude out of the rest of your notes, open the branch it may use, open Agents and API keys in Settings, tap Claude’s row under Your agents, which is marked whole outline, and press Let it reach only “…”, the bullet you are in, where the quotes hold that branch’s words. From then on Claude reads and writes that branch and everything under it, remembers there, and reaches nothing else in your outline, even if you approved it to read only. The button is offered only inside a bullet of your own, not at Home.

Locks

A lock stops changes, not reading. Choose Protect it from changes in a bullet’s menu, and nothing can change or delete it, or anything under it, until you turn it off, Claude included. Open the menu again and choose How it is protected…, where Refuses sets whom it refuses: Everyone, including me, or Agents only, which refuses Claude and still lets you edit. Claude has no tool to put a lock on, and it cannot take one off. Set Reaches to Its shape only and the lines under it stay writable, which suits a template.

A key, where Claude takes one

An agent you create under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked never starts on your whole outline: it reaches nothing until you hold it to a bullet with the same press. Its key begins with pf_ and is shown once. Claude takes a key only through request headers, which Anthropic’s docs call a beta "available to a limited set of organizations"; if the Add custom connector dialog shows no Request headers section, yours does not have it. There you choose No sign-in and give an Authorization header the value Bearer, a space, and the key.

Anthropic says Claude stores the key as the connector’s credential, describes request headers for one credential everyone in an organization shares, and says to use OAuth where each person signs in with their own account. On Team and Enterprise, where an Owner adds the connector, that means everyone in the organization who uses it reads and writes that bullet as one agent; put a key there only for a bullet meant for all of them, and use the sign-in otherwise. This route has not been tried against Pando, and a connector’s authentication cannot be changed after it is added, so switching means removing the connector and adding it again.

Taking it back

In Pando, open Agents and API keys in Settings and, under Keys rather than Your agents, press the row @claude · @claude, which ends in revoke. It revokes with no second question, and what Claude already wrote stays where it is. Claude’s row under Your agents stays too, still marked whole outline, but with its key revoked it reaches nothing; connect Claude again and a new agent arrives, @claude-2. In Claude, the connector is removed under Customize, then Connectors; on Team and Enterprise an Owner removes it under Admin settings, then Connectors.

When this is not the answer

What it costs

Nothing, for 1,000 bullets, with every feature included and no payment card.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this