Agent scope — V1

What an agent can see, and how the researcher controls it. Windows are the control; nothing else designates scope.

Scope = every open project window whose project has Agent Access on.
Nothing is designated, nothing persists, nothing follows focus. Widen by opening a window, narrow by closing one. ⌘` changes nothing.
Derived from the window roster, never from running serves. A sidecar lingers 90 s after its window closes so ⌘W-then-Dock-click stays free — but scope is a permission, not a cache, and the two must not share a predicate.
Closing is immediately safe. The sidecar stays warm; its /mcp surface goes dark the moment the window closes — so a cached port and bearer buy nothing.

The antenna, three tiers

already shipped — the meanings sharpen, the glyph doesn't change
No antennaAgent Access off. Absence is the information.
PaleAccess on, no window. Not in scope — open one and it is.
SolidIn scope right now. Radiates while an agent is reading.
1

One window, access on

scope = 1
Projects
🏉foo3
🌪folder-of-horrors42
🎓New Project 2
🐟IKEA with uxfriends1
foo
1 window · 1 serve
Claude

I can see one project: foo — 3 sessions, 44 quotes.

The simple case. One window, one project in scope. Nothing to disambiguate, so nothing to confirm.
2

Two windows, both access on

scope = 2 · confirm
Projects
🏉foo3
🌪folder-of-horrors42
🎓New Project 2
🐟IKEA with uxfriends1
foo
frontmost
IKEA with uxfriends
behind
Claude

You have two projects open: foo (3 sessions) and IKEA with uxfriends (1 session).

Which should I look at — or both?

Frontmost is irrelevant. foo being in front gives it no priority. This sentence is what replaces every silent re-pointing bug.
3

Two windows, one has access off

scope = 1
Projects
🏉foo3
🌪folder-of-horrors42
🎓New Project 2
🔒Acme — pre-announce6
foo
access on
Acme — pre-announce
access off
Claude

I can see one project: foo.

The confidential study is open on screen and invisible to the agent — no antenna, no handshake row, not even its name. Open ≠ shared. Access is the permission; the window is only the scope.
4

Minimised — in scope, deliberately

scope = 2
Projects
🏉foo3
🐟IKEA with uxfriends1
foo
on screen
IKEA with uxfriends
minimised · still in scope
Claude

Two projects: foo and IKEA with uxfriends.

Minimising is how you hold a project in scope on a small screen. Cross-project work needs several windows; the Dock is where they go. Intentional retention, so it counts.

The cost, accepted: the antenna that would tell you is inside the minimised window. Scope is real and unseeable — which is what promotes an always-on count from nice-to-have to the only way to check.

5

You close a window mid-conversation

2 → 1 · immediate
Projects
🏉foo3
🐟IKEA with uxfriends1
foo
still open
IKEA with uxfriends
⌘W · sidecar warm 90 s, unreadable now
Claude

IKEA with uxfriends has left scope — its window closed. I still have foo. Shall I carry on with just that?

This is the whole scope control. The tool result is the only channel we have into the other app, so the departure is announced there, not in a dialog.

The sidecar stays warm for 90 s so reopening is instant — but its /mcp surface is already dark. Close a window and you are safe from prying robots immediately, not eventually, and not merely because a well-behaved proxy re-read a file.

Settings ▸ MCP Agents — where you check the scope

the pane exists; today it shows only the serving project
MCP Agents
2 projects readable by agents.
Close a window to remove one. Turn off Agent Access to stop a project being readable at all.
IN SCOPE
🏉foo reading now
🐟IKEA with uxfriends minimised

Open, with Agent Access on. This is the list an agent sees.

READY WHEN YOU OPEN THEM
🌪folder-of-horrors 42 sessions

Agent Access is on, but no window is open. An agent can name these; it cannot read them.

CONNECTION
AgentClaude Desktop
ExtensionInstalled · v0.1.0

macOS will ask once whether Claude may access data from other apps. That prompt is how the extension finds Bristlenose.

PRIVACY
Hide names

Agents see speaker codes (p1, m1) instead of names. Job titles and personas still travel — they are what lets an agent judge whether two studies are comparable.

The summary line is the whole point. A count plus the sentence that changes it. That is what a researcher wants when they are worried, and it is the one thing no other surface can give them once windows are minimised.

Two sections, because "readable" and "permitted" are different facts — and the pale set is exactly what an agent may name but not read. Grouping them under one list would blur the distinction the whole model rests on.

Turn Off appears on every row, in scope or not: it is the permission control, and it works from here whatever the windows are doing. Closing a window is a thing you do in the app, so the pane says so rather than offering a Close button that reaches out of Settings.

"Hide names", not "Anonymise" — with the footnote saying plainly what still travels. The switch strips names; it does not de-identify, and the honest label is the smaller one.

"reading now" rides the same per-project activity signal as the sidebar antenna. While this pane is open it is the one always-visible readout of which study is being touched.

What a quote looks like when two studies are in scope

the citation currency changes
// p1 alone is no longer a citation — p1 in foo and p1 in IKEA are different humans.
{
  "scope": { "n": 2, "fp": "7c31be04" },   // count phrases the warning; fp catches a same-size swap
  "project": { "key": "a3f9c210", "name": "IKEA with uxfriends" },
  "quote_id": "q-p1-174",
  "participant": "p1",
  "role": "Practice manager",          // people.yaml — modelled today, not yet exposed
  "session_date": "2026-03-09",
  "text": "Express delivery is the way to go."
}

Provenance is mandatory; pooling is permitted. The danger was never mixing studies — it was mixing them silently. With the project on every quote and the role beside it, the agent can say the sentence that makes cross-study evidence legitimate: "this came from a usability study of product X, this from a discovery of product Y — both experienced practice managers."

Grouping is not comparability. A folder named "All discovery" may hold six unrelated clients. What licenses pooling is the population and the question, never the container.

What scope guarantees is detectability, not compliance. Claude will notice a widening and clarify because the instructions say so; another client may not. The enforceable control stays app-side — the antenna, the window, the quit.

Settled

decided this pass — not open for re-litigation

Still open

ordered by when they have to be answered
Before ship

Tab release is unmeasured, and the roster is now a security boundary

ServeReaping's own comment: a tab merged into another window may not fire .onDisappear at all. When that governed memory it cost 140 MB; now it governs what an agent can read. The fix is settled — live-derive shownProjects from NSApp.windows on a sweep rather than trusting notifications — so what is owed is the measurement, not a decision. The only open item left before ship.

Copy

"Anonymise" over-promises once role travels

The switch now means names stripped, not de-identified — and a job title beside verbatim quotes in a six-person study is a re-identification path a researcher reading that word would assume was closed. "Hide names" is smaller and true.

Copy

role and persona are freeform

Researcher-typed strings, no controlled vocabulary — nothing stops Practice manager, Acme Leeds going in the box. Their help text gives no reason to think the field ever leaves the machine. A hint at the field, not a validator.

Watch in use

Ten windows means ten projects in scope

The rule stays clear; the scope broadens quietly. The fingerprint plus the agent's clarification is probably enough. First thing to watch with a real researcher.

Build, post-V1

Somewhere to read the scope set

With minimised windows in scope the sidebar is unreliable, and that is accepted for V1. The cheap version is not a menu-bar extra: Settings ▸ MCP Agents already exists and shows only the serving project. Listing the scope set there gives a worried researcher somewhere to look.

Build

Activity animation must be per project, in every window

Per project, not per window — two windows on one study share a serve, and the sidebar is replicated, so the row radiates in every open sidebar at once. Most of it already works: each sidecar counts its own calls and each ServeManager polls its own port. The only collapse is refreshAppLevelFacts squeezing N answers into one, because there was only ever one exposed project. Fleet publishes a map; the sidebar keys by row.

It improves in the plural world rather than merely porting: a cross-study query lights several antennas in sequence, so you watch the shape of the question move across your studies.

V2

Folders as a share unit

Twenty studies on one product is the real prize. Nothing here blocks it: a folder share is just another source of set membership, and the handshake shape, routing and citation format all stay put. Global Anonymise returns here.