Roles & scoping
Every memory carries an audience (all, dev, or commercial) and every token carries a role. Retrieval matches the two so people see what’s relevant — without a permissions project.
Who can read what
| Role | Can read |
|---|---|
admin | Sees everything in the organization — all, dev, and commercial memories. |
dev | Sees all memories plus dev-scoped memories. Does not see commercial-only memories. |
commercial | Sees all memories plus commercial-scoped memories. Does not see dev-only memories. |
Scoping is enforced server-side, before Claude sees anything. A dev-only memory is dropped from a commercial teammate’s results at the source — it’s not just hidden in the UI. This holds identically on Claude Code and Claude.ai.