Keeping an agent out of the rest of your notes
The usual shape of this question assumes the answer is all or nothing: you connect the assistant to your notes, and now it has your notes. A connector, the way ChatGPT always connects and Claude almost always does, starts that way: it reads your whole outline. It does not have to stay that way.
Hold it to one bullet. Open the bullet it needs, open Agents and API keys in Settings, tap the agent’s row under Your agents, and press Let it reach only “…”, the bullet you are in, where the quotes hold that bullet’s words. It then reads and writes that bullet and everything under it, and reaches nothing else in your outline. A connector you approve starts with your whole outline, and keeps it until you make this press.
Set it up
- Point the client at https://pando.ink/mcp, which speaks streamable HTTP.
- Authenticate with OAuth 2.1 and dynamic client registration, or paste a key from Agents and API keys as a Bearer token.
What you can limit, and how
- What a connector may do. When you approve one you choose read and write or read only, and either way it starts able to read every bullet. Let it reach only, on its row, then holds it to one bullet, where it may read and write even if you approved it to read only.
- Its memory. You assign one bullet as the agent’s memory root, and you pick where in your outline it sits. It may write there even when it may only read everything else.
- What an agent’s key reaches. Create the agent under Agents and API keys with “Let it read and write this outline” and “Give it a bullet of its own to remember in” both unticked, and it reaches nothing until you give it a bullet: zoom into the branch it needs, open Agents and API keys again, tap its row under Your agents, and press Let it reach only “…”, the bullet you are in. It reaches that bullet and everything under it, read and write, and a bullet it cannot reach is not in any answer it gets, including search. The key goes in a Bearer header, which Claude Code, Codex, Cursor, Gemini CLI, Cline and Devin can send. ChatGPT cannot send one. The Claude apps can, but only through the Request headers setting of a custom connector, which Anthropic calls a beta for a limited set of organizations: an administrator enters the key there, and that one key then serves every member.
- What is protected. A protected bullet refuses every change, and so does everything under it. The agent is told it is protected before it tries, so it plans around it rather than failing into it.
What the agent sees when it asks
The whoami tool answers with its memory root, or with nothing when you have assigned none, in which case remembering is refused outright. The shared_with_me tool lists what it reaches besides its memory, which for a connector starts as your whole outline, and says of each one whether it may view or edit. Both of them name the roots they searched, so an answer of zero results is a real zero rather than a silent miss.
You see the writes as they happen
When an agent writes, its chip pulses in your top bar and the bullet appears on your screen. Nothing is written invisibly, and nothing waits for a sync you have to remember to run.
What this does not do
It does not stop the model you connected from seeing what you did hand it. What it reads goes to your agent’s provider under your own subscription, exactly as if you had pasted it, and for a connector you have not held to one bullet, that can be any bullet in your outline. These limits decide what is in reach, not what happens to it afterwards.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this