> For the complete documentation index, see [llms.txt](https://www.cakewalk.security/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://www.cakewalk.security/docs/ai-agent-access/how-to-guides/connection-access.md).

# Connection Access

Choose whether every Member can self-add any Agent Connection, or only the ones you allow for their User Groups.

Connection access is the org-wide setting that decides which Agent Connections a Member can see and add. It has two values. **Open** leaves the catalog available to everyone. **Curated** limits each User Group to the Agent Connections you allow it, so a sensitive Connection reaches only the groups that should have it.

Curated works off the User Groups that already sync from your HRIS or IdP, so access follows your own org structure without a second place to maintain.

***

### 📖 Key concepts

* **Open**: The default. Every Member sees and can self-add every active Agent Connection.
* **Curated**: Members see only the Agent Connections allowed for their User Groups.
* **Allowed Connection**: A pairing of one User Group with one Agent Connection. A Member of that group can add and use that Connection.
* **Union across groups**: A Member gets every Connection allowed for any group they belong to. Joining a group only widens access.
* **Restricted**: The state of a Connection a Member holds but no longer has access to. Their credential is kept and Agent access is blocked. See [Connection and Agent Statuses](/docs/ai-agent-access/concepts/connection-and-agent-statuses.md).

:bulb: *Why this matters*: Under Open, any Member can point an Agent at any Connection in your catalog. Curated is how you make Cakewalk the gate: an Agent reaches a Connection only when the Member's group is allowed it.

***

### ⚙️ Choose a mode

* **Navigation**: Settings → Connection access.
* **What you see**: two cards, **Open** and **Curated**, with the active one selected.
* **Actions**:
  * Select **Curated** to start the setup flow.
  * Select **Open** to lift every restriction.
  * **Manage access** (on the Curated card, once Curated is on): reopens the setup screen to change what each group is allowed.

Nothing changes for your org until you finish setup and confirm. Open is the default for every account and stays that way until an Admin switches.

***

### 🔒 Turn on Curated

Selecting **Curated** opens **Setup curated access**, a full screen with your User Groups on the left and, for the group you select, every Agent Connection in your catalog on the right.

Cakewalk proposes a starting point so the switch does not cut anyone off: a Connection is switched on for a group when at least one member of that group already has access to it. Because access is the union across a Member's groups, no Member loses a Connection they hold at the moment you turn Curated on. What changes immediately is the catalog each group can add from, which narrows to the set you leave switched on.

{% stepper %}
{% step %}

#### Review each group

Select a group on the left. Use the search box to find one by name. The connections table shows:

* **Connection** and **Description**: the Agent Connection.
* **Accesses**: group members who have access to this app.
* **Connections**: group members who set up this Connection in Cakewalk.
* **Access**: the toggle that allows or blocks this Connection for the selected group.

The two counts differ on purpose. A Member can hold access to an app and never have connected it in Cakewalk.
{% endstep %}

{% step %}

#### Set what each group is allowed

Toggle a row to allow or block one Connection for the selected group. Use the toggle in the column header to switch every row for that group at once. **Switch off all connections for {n} groups** in the footer clears every group, so you can build the list up from nothing.

Your changes are held while you move between groups. Nothing is saved until you finish.
{% endstep %}

{% step %}

#### Finish and confirm

Select **Finish**. If your choices would take a Connection away from someone using it today, Cakewalk shows **Turn on curated access** with the members affected. Confirm to apply.

Curated is on from that moment. Every later change goes through **Manage access** and confirms the same way.
{% endstep %}
{% endstepper %}

{% hint style="info" %}
Members who are in no synced group cannot be reached by any rule, so they see no Connections under Curated. Cakewalk flags them on the setup screen, on the Curated card and on the [Users](/docs/ai-agent-access/how-to-guides/users.md) page, and never writes group membership back. Assign them to a group in your HRIS or IdP and the next sync covers them.
{% endhint %}

***

### 🔄 What happens when access changes

| Change                                 | Effect                                                                                                                                              |
| -------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- |
| **You allow a Connection for a group** | Members of that group can add it. Any Connection they hold that was Restricted is released and usable again straight away, with no need to sign in. |
| **You block a Connection for a group** | Members lose it unless another of their groups still allows it. A Connection they already hold becomes **Restricted**.                              |
| **A Member joins a group**             | They gain everything that group is allowed, on top of what they already had.                                                                        |
| **A Member leaves a group**            | They keep whatever their remaining groups allow, and lose the rest.                                                                                 |
| **You switch back to Open**            | Every Restricted Connection is released and usable again. Connections a Member paused themselves stay paused.                                       |

Group membership arrives through your HRIS or IdP sync, so these changes apply on their own as your directory changes.

***

### 👤 What a Member sees

* The **Add connection** panel lists only the Agent Connections their groups are allowed. Everything else is absent from the catalog.
* A Connection they already hold that is no longer allowed keeps its card in [My Connections](/docs/ai-agent-access/how-to-guides/connections/my-connections.md) with a **Restricted** chip, under the **Paused** tab. Hovering the chip explains why.
* The only action on a Restricted card is **View details**. A Member cannot resume it, and cannot connect it. Only a change to what their groups are allowed brings it back.

Nothing is deleted. The credential stays in the vault, which is why access resumes without a fresh sign in.

***

### ➕ Creating a Connection while Curated is on

Under Curated, a new Agent Connection needs a group before it can be used, so the creation flows ask for one:

* **From the catalog**: the **User groups** field appears for each Connection you select. **Confirm** stays unavailable until every selected Connection has at least one group.
* **A custom Connection**: the **User groups** field appears in the form and is required to save. See [Add a Custom Connection](/docs/ai-agent-access/how-to-guides/connections/add-a-custom-connection.md).

Once created, the Connection's groups are listed on its detail page under [All Connections](/docs/ai-agent-access/how-to-guides/connections/all-connections.md).

***

### 🔗 Related pages

* [Connection and Agent Statuses](/docs/ai-agent-access/concepts/connection-and-agent-statuses.md)
* [My Connections](/docs/ai-agent-access/how-to-guides/connections/my-connections.md)
* [All Connections](/docs/ai-agent-access/how-to-guides/connections/all-connections.md)
* [Users](/docs/ai-agent-access/how-to-guides/users.md)
* [Roles and Permissions](/docs/ai-agent-access/concepts/roles-and-permissions.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://www.cakewalk.security/docs/ai-agent-access/how-to-guides/connection-access.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
