The agent
Intabula's built-in AI agent works on your vault through a fixed set of typed operations. It has no shell and no tool that writes files directly. It runs on the Claude or Codex subscription you already have (no API key, no per-token billing), or on open-weight models via OpenRouter with your own key.
Providers
One agent panel supports three providers, and you switch between them in the panel. All three get the same vault operations listed below and the same approval mode. Web access and linked-folder reading work differently per provider, as described under Read-only context tools.
- Claude: uses the Claude Code login on your Mac. Claude Code must be installed. If you aren't signed in, the panel shows an Open Terminal button that opens Terminal with
claude auth loginalready running; you finish the sign-in in your browser, and Intabula doesn't see the token. Usage counts against your Claude plan. - Codex: uses your locally installed Codex CLI and its existing sign-in. The same Open Terminal button starts the Codex sign-in if needed. Usage counts against your Codex plan and its limits.
- OpenRouter: open-weight models (DeepSeek, GLM, Qwen) on an API key you supply, billed against prepaid OpenRouter credits per token. Intabula runs the agent loop itself. The key is stored on your Mac, encrypted with a secret held in the macOS keychain.
Vault operations
These are the only ways the agent can touch your vault. Operations marked as writes pause for your approval when approval mode is on.
| Operation | What it does | Write |
|---|---|---|
list_collections | List the collections in the vault with record counts. | No |
get_schema | Read a collection's pinned fields and inferred field stats. | No |
query_records | Query a collection's records with filters and sorting. | No |
search_vault | Full-text search across titles, fields, and bodies (accent-insensitive). In the agent panel it also searches drafts and past conversations. | No |
get_record | Read one record's fields and body. | No |
get_backlinks | List the records that link to a given record. | No |
list_needs_attention | Read the needs-attention inbox, with suggested fixes for each item. The seven item kinds are listed in Data model. | No |
list_recent_changes | List records changed within a look-back window, newest first, whoever changed them. | No |
open_record | Open a record in the app for you. Agent panel only. | No |
open_collection | Open a collection in the app for you. Agent panel only. | No |
pin_field | Promote a recurring field to an official typed column. | Yes |
create_record | Create a record with frontmatter fields and a Markdown body. | Yes |
update_record | Edit fields or body. The edit splices only the changed segment. | Yes |
rename_record | Rename atomically. Every wikilink across the vault is rewritten, under a journal. | Yes |
move_record | Move a record between collections; references follow. | Yes |
delete_record | Delete a record. Links that pointed to it show up in the needs-attention inbox. | Yes |
create_view | Save a table or Kanban view to the sidebar. | Yes |
create_bot | Give a collection a bot with a charter and schedule. The bot is saved switched off; only you can turn it on. Not available to bots themselves. | Yes |
save_conversation | Save a conversation as a record in a collection. Agent panel only. | Yes |
list_drafts | List your drafts, newest first. | No |
get_draft | Read one draft in full. | No |
update_draft | Append to a draft, rewrite it, or start a new one. | Yes |
discard_draft | Delete a draft. | Yes |
file_draft | Save a draft as a record in a collection and clear the draft. | Yes |
The five draft operations are not available to bots. When the agent uses a draft in an answer, it is instructed to say the content came from a draft, since drafts are unfinished notes.
Read-only context tools
Outside the vault, the agent can read sources you attach and the web:
- Files in linked folders. With Claude, the agent uses Claude Code's own Read, Glob, and Grep tools, and Intabula checks every call against the linked folders before allowing it. With Codex and OpenRouter, it uses
read_linked_file,list_linked_files, andsearch_linked_files. git_log,git_show,git_diff: the Git history of a linked repository, for every provider. These leave the working tree untouched.- The web. Claude uses its WebSearch tool, which runs on Anthropic's servers, and WebFetch, which fetches from your Mac and refuses private and local network addresses. Codex and OpenRouter use their provider's web search plus Intabula's
fetch_url, which applies the same address check.
What the agent does not have
The agent has no Bash or other shell, and no tool that writes, edits, or deletes files directly. Its file reads are limited to linked folders. Your files leave your machine only as context sent to the model provider.
Collections marked as encrypted are refused by every vault operation, for every provider, whether or not they are unlocked, so their fields and bodies don't reach the model. The agent can still see that the collection exists and the names of its records. See Encrypted collections.
Approval mode
The panel has two modes, auto and manual. Auto is the default. In manual mode, every write in the table above waits for your approval. The diff you review comes from dry-running the actual write without applying it, so it shows the exact bytes that would land on disk. An approval left unanswered for 5 minutes is denied, and the agent is told you rejected the change.
Conversations
Conversations with the agent are stored on this Mac, in ~/.intabula/agent/, outside the vault, so a synced or shared vault does not carry them. You can browse them on the Conversations page in the sidebar, find them from the ⌘K palette, and continue any of them. The agent can find past conversations through search_vault.
A conversation enters the vault only when you save it as a record: with the Save as record… button on the Conversations page, or by asking the agent, which uses save_conversation. The exchange becomes the record's body, and the provider, model, and dates become fields.
The activity feed
Every agent write is logged to an activity feed with a before-and-after snapshot of the affected file. You can open any entry as a diff to see what changed.