Better ways to work.
More room to grow.

Using Korium well

Sharing and access

Shared memory is useful because the next person can use what the last one learned. That makes it important to choose who can read it, who can write to it and what should never be there.

Browse the documentation

Choose the right workspace

A team workspace is shared company memory. It is not a collection of private chats with identical branding. Check the workspace before saving material, especially if you belong to several organizations.

Scopes such as billing.refunds organize memories inside that space. A scope name is not a permission boundary. If teams need separation, use the account or organization structure approved for that requirement.

People and clients have different permissions

Workspace roles govern what a person can do. Administrators manage the workspace and its members; members can contribute within their permissions; viewers have read access. Review the role when inviting someone rather than giving everybody administrative access.

MCP clients also receive OAuth scopes. engram.read grants reading tools and engram.write grants writing tools. A hidden client-side tool is not a substitute for server-side authorization.

Read-only is useful for a reviewer or reporting agent. It still needs permission to access the workspace whose material it reads. See the scope reference.

Keep untrusted material in its place

A document, transcript or retrieved memory can contain bad information or instructions aimed at the assistant. Treat that material as a source to assess, not as authority to change permissions or take actions.

Review imported claims before treating them as company decisions. Preserve the source and uncertainty. Require the normal human approvals for external actions even when a memory suggests what should happen.

Don’t save credentials

Keep passwords, API keys, access tokens and refresh credentials out of captures, examples, screenshots and support messages. The CLI stores its sign-in in the Mac keychain. MCP clients manage their own credentials.

A leaked credential is not repaired by marking a memory superseded. Rotate or revoke it through the system that issued it and contact the appropriate administrator. Follow your organization’s incident procedure.

Know where your data goes

Korium separates tenants at the data layer and uses encryption in transit and at rest. The published security overview, privacy notice and subprocessor list explain the service’s data handling.

The terms say Kyroco will not use Customer Content to train, fine-tune or improve general-purpose or foundation models. They also describe model providers used for memory operations. Read the terms rather than assuming “not used for training” means no provider ever processes data.

An assistant you connect can receive the memories it retrieves. Its own data terms also matter. Ask about contractual residency requirements before supplying regulated or restricted material.

Keep an exit plan

You can export your material. Plan that before closing an account, and verify the export contains what you need. A company memory should not depend on one person retaining access to an old conversation.

Correcting or superseding a memory does not erase it or reclaim room. Account deletion, retention and termination are governed by the terms and DPA; the account FAQ explains the practical distinction.

Use the setup checklist before changing an automated workflow. Check your installed client’s help if its interface differs.