Linked folders
A linked folder attaches an external directory (a code repository, a docs export, a data dump) to a collection as read-only context for Intabula's agent. The agent can read and search the linked folder, and it has no operation that writes to it.
What the agent can do with a linked folder
How the agent reads files depends on the provider:
- With Claude, the agent uses Claude Code's built-in Read, Glob, and Grep tools. These tools are switched on only while at least one linked folder exists, and Intabula checks every call before allowing it.
- With Codex and OpenRouter, the agent uses
list_linked_files,read_linked_file, andsearch_linked_files, which Intabula provides. The providers' own file access is switched off.
For every provider, git_log, git_show, and git_diff read a repository's history and leave the working tree untouched. There is no write operation for linked folders.
The boundary
Every path the agent asks for is resolved to its real path and checked against the linked folders, so a symlink inside a linked folder can't reach outside it. Relative paths are refused.
A sensitive-file blocklist sits on top of that check. It matches .env files and their variants, .pem and .key files, anything under a secrets/ or .ssh/ directory, and .git/config. Reading a matching file is refused, and list_linked_files and search_linked_files skip matching files. In the Git tools, a matching path is refused, and matching files are removed from git_show and git_diff output. The blocklist is a safeguard for common secret files. The boundary you control is which folders you link.
With Claude, Read refuses a blocklisted file, but a Grep across a directory can still return matching lines from one. Don't link a folder that holds secrets you wouldn't send to the model.
Notes that can see your code
The main use is to give each repository its own collection with the repo linked. Asking the agent to "write up why we switched the queue implementation, and check the actual diff" produces a decision record based on the commit itself. Ticket notes carry real file references; architecture notes cite the code they describe. See the engineering decisions use case.
Linked folders vs. external collections
A linked folder is read-only context: the agent can read it and cannot write to it. An external collection is a normal writable collection whose folder happens to live outside the vault (iCloud, an external disk, a shared drive). See Sync, sharing, and iOS.