Control Who Can Access Your External Knowledge Base
Manage access to your External KB with public and restricted visibility modes, domain-based invitations, and per-article permission overrides.
Access control in the External KB gives you precise command over who can read your content. You can open your entire knowledge base to anyone with a link, lock it down to specific customers or domains, or mix both approaches — applying broad product-level defaults while carving out exceptions at the individual article level.
Visibility Modes
Every piece of External KB content operates under one of two visibility modes:
Product-Level vs. Article-Level Visibility
You can set a default visibility mode for an entire product hub, and then override that default on individual articles. Article-level settings always take precedence over the product-level default.
| Level | How to set it | Scope |
|---|---|---|
| Product | External KB → Products → Your Product → Settings → Visibility | Applies to all articles in the product unless overridden |
| Article | Article editor → Access panel → Visibility | Overrides the product-level setting for this article only |
This means you can, for example, keep a product hub Restricted by default while publishing a handful of introductory articles as Public — without changing the product-level setting.
Inviting Customers to Restricted Content
When an article or product hub is Restricted, you have two ways to grant access:
- Specific email addresses — Invite individual customers by their exact email. They receive an access link and must sign in with that address.
- Email domain — Invite an entire company by entering their domain (e.g.,
@acme.com). Anyone who authenticates with an email address on that domain gains access automatically.
You can combine both methods on the same article or product hub. For example, you might grant access to @enterprise-client.com and also add a few individual addresses from a different company.
External User Roles
When you invite external users to restricted content, you assign them one of two roles:
Setting Article Permissions
Navigate to External KB, select your product, and click on the article you want to configure. The article opens in the full editor view.
In the right-hand sidebar, locate the Access panel. If the sidebar is collapsed, click the panel icon or press A to expand it.
Select one of the three options:
- Public — anyone with the link can read
- Domain-restricted — only users whose email matches an approved domain
- Invite-only — only specific email addresses you list
For Domain-restricted, enter the domain in the format @company.com. For Invite-only, paste one or more email addresses separated by commas or newlines. You can add both individual addresses and domains to the same article.
Click Save Access Settings. The new visibility applies instantly — no republish is needed. Users who no longer meet the criteria lose access on their next page load.
AI agent scope is set separately. AI agents access your External KB using the scope you defined when you connected the agent — not the visibility settings on individual articles. If you restrict an article after an agent has been granted broad access, the agent may still be able to read and cite it. To update an agent's scope, go to the agent's connection settings and adjust its KB access explicitly.
Before toggling any article from Restricted to Public, review the full article content carefully. Restricted articles may contain customer-specific pricing, proprietary integration details, or other sensitive information that is not appropriate for general audiences. This change cannot be automatically undone if the article is cached or indexed by a search engine after it is made public.
Frequently Asked Questions
Yes. Set the product-level visibility to Restricted and leave the invited users list empty initially, or populate it with your customer base. Any visitor who is not authenticated or not on an approved domain will see a login prompt instead of the article content. If you want all articles gated by login — even general onboarding content — set every product hub to Restricted.
Go to External KB → Products → Your Product → Settings → Visibility → Manage Access. Find the email address or domain you want to remove and click the Revoke button next to it. Access is removed immediately. If the customer is actively viewing a page, they will be redirected to the access-denied screen on their next navigation action or page refresh.
Yes, in two ways. First, articles set to Public are eligible to be crawled and indexed by external search engines like Google. Articles set to Restricted are served behind authentication and will not be indexed by external crawlers. Second, within the in-product search experience, customers only see results for articles they are authorized to access — so restricting an article also removes it from that customer's search results automatically.