Workspaces#
A workspace is an explicit grant. VOOL can read and write inside it, and nowhere else.
What is this for?#
Keeping every read and write inside a boundary you chose, and giving each project its own context that does not leak into another project.
How do I use it?#
- Grant a folder in Settings → Workspace. Removing it revokes access immediately; there is no cached copy kept outside the workspace.
- Bind chats to a project. A chat bound to a project folder works inside that folder: its file tools, its memory, and its receipts belong to that project. Bind from Projects → New project (or pick an existing one) inside the chat.
- Name an explicit path in the conversation when you mean one specific place.
What permission or connection does it require?#
None beyond the grant itself. The workspace is the permission boundary for reading; changes inside it still follow Permissions.
What can go wrong?#
A chat that needs its project folder reports a stable reason when the folder is not usable, and pending requests wait rather than being cancelled:
| Reason | Meaning | What to do next |
|---|---|---|
unbound | The chat has no project folder | Bind it: Projects → New project / pick existing |
missing_chat / deleted_chat | The chat identity is not usable | Reopen the chat from the list |
project_missing | The bound folder no longer exists at that path | Re-bind the chat to the folder's current location |
unreadable | The folder exists but cannot be read (permissions) | Repair the folder's access, then retry |
Scoping advice#
- Point a workspace at a project, not at your home directory.
- Keep credential files, key material, and password stores outside any workspace.
- Use a separate workspace per project so context from one does not reach another.
Anything inside a workspace can be read by a tool call, and in cloud mode can therefore be included in what is sent to your provider. Scope deliberately.