What an agent can see, and how the researcher controls it. Windows are the control; nothing else designates scope.
/mcp surface goes dark the moment the window closes — so a cached port and bearer buy nothing.I can see one project: foo — 3 sessions, 44 quotes.
You have two projects open: foo (3 sessions) and IKEA with uxfriends (1 session).
Which should I look at — or both?
I can see one project: foo.
Two projects: foo and IKEA with uxfriends.
Minimising is how you hold a project in scope on a small screen. Cross-project work needs several windows; the Dock is where they go. Intentional retention, so it counts.
The cost, accepted: the antenna that would tell you is inside the minimised window. Scope is real and unseeable — which is what promotes an always-on count from nice-to-have to the only way to check.
IKEA with uxfriends has left scope — its window closed. I still have foo. Shall I carry on with just that?
This is the whole scope control. The tool result is the only channel we have into the other app, so the departure is announced there, not in a dialog.
The sidecar stays warm for 90 s so reopening is instant — but its /mcp surface is already dark. Close a window and you are safe from prying robots immediately, not eventually, and not merely because a well-behaved proxy re-read a file.
Open, with Agent Access on. This is the list an agent sees.
Agent Access is on, but no window is open. An agent can name these; it cannot read them.
macOS will ask once whether Claude may access data from other apps. That prompt is how the extension finds Bristlenose.
Agents see speaker codes (p1, m1) instead of names. Job titles and personas still travel — they are what lets an agent judge whether two studies are comparable.
The summary line is the whole point. A count plus the sentence that changes it. That is what a researcher wants when they are worried, and it is the one thing no other surface can give them once windows are minimised.
Two sections, because "readable" and "permitted" are different facts — and the pale set is exactly what an agent may name but not read. Grouping them under one list would blur the distinction the whole model rests on.
Turn Off appears on every row, in scope or not: it is the permission control, and it works from here whatever the windows are doing. Closing a window is a thing you do in the app, so the pane says so rather than offering a Close button that reaches out of Settings.
"Hide names", not "Anonymise" — with the footnote saying plainly what still travels. The switch strips names; it does not de-identify, and the honest label is the smaller one.
"reading now" rides the same per-project activity signal as the sidebar antenna. While this pane is open it is the one always-visible readout of which study is being touched.
// p1 alone is no longer a citation — p1 in foo and p1 in IKEA are different humans. { "scope": { "n": 2, "fp": "7c31be04" }, // count phrases the warning; fp catches a same-size swap "project": { "key": "a3f9c210", "name": "IKEA with uxfriends" }, "quote_id": "q-p1-174", "participant": "p1", "role": "Practice manager", // people.yaml — modelled today, not yet exposed "session_date": "2026-03-09", "text": "Express delivery is the way to go." }
Provenance is mandatory; pooling is permitted. The danger was never mixing studies — it was mixing them silently. With the project on every quote and the role beside it, the agent can say the sentence that makes cross-study evidence legitimate: "this came from a usability study of product X, this from a discovery of product Y — both experienced practice managers."
Grouping is not comparability. A folder named "All discovery" may hold six unrelated clients. What licenses pooling is the population and the question, never the container.
What scope guarantees is detectability, not compliance. Claude will notice a widening and clarify because the instructions say so; another client may not. The enforceable control stays app-side — the antenna, the window, the quit.
NSApp.windows, not from notifications — which is what makes tabs safe. Visibility was considered and rejected: gating on occlusion would collapse scope the moment the Claude window covers Bristlenose.role travels even when Anonymise is on. It is what licenses cross-study pooling, and the transcripts already went to a cloud LLM to be analysed at all.ServeReaping's own comment: a tab merged into another window may not fire .onDisappear at all. When that governed memory it cost 140 MB; now it governs what an agent can read. The fix is settled — live-derive shownProjects from NSApp.windows on a sweep rather than trusting notifications — so what is owed is the measurement, not a decision. The only open item left before ship.
role travelsThe switch now means names stripped, not de-identified — and a job title beside verbatim quotes in a six-person study is a re-identification path a researcher reading that word would assume was closed. "Hide names" is smaller and true.
role and persona are freeformResearcher-typed strings, no controlled vocabulary — nothing stops Practice manager, Acme Leeds going in the box. Their help text gives no reason to think the field ever leaves the machine. A hint at the field, not a validator.
The rule stays clear; the scope broadens quietly. The fingerprint plus the agent's clarification is probably enough. First thing to watch with a real researcher.
With minimised windows in scope the sidebar is unreliable, and that is accepted for V1. The cheap version is not a menu-bar extra: Settings ▸ MCP Agents already exists and shows only the serving project. Listing the scope set there gives a worried researcher somewhere to look.
Per project, not per window — two windows on one study share a serve, and the sidebar is replicated, so the row radiates in every open sidebar at once. Most of it already works: each sidecar counts its own calls and each ServeManager polls its own port. The only collapse is refreshAppLevelFacts squeezing N answers into one, because there was only ever one exposed project. Fleet publishes a map; the sidebar keys by row.
It improves in the plural world rather than merely porting: a cross-study query lights several antennas in sequence, so you watch the shape of the question move across your studies.
Twenty studies on one product is the real prize. Nothing here blocks it: a folder share is just another source of set membership, and the handshake shape, routing and citation format all stay put. Global Anonymise returns here.