Skip to content

Admin controls

Decide who can connect AI apps, what they can do and how much they can spend.

Workspace owners and admins decide whether people can use Tahoe from AI apps, what those apps may do, and how much they may spend and send. You also see every member’s connections and a log of what the apps did. Everything is on one screen in the dashboard.

In the side panel, choose Settings, then the AI connectors tab. Everyone in the workspace can open it to read the settings, but only owners and admins can change them or see members’ connections and the activity log.

Settings and defaults

The first card, AI apps in this workspace, holds the settings. Change what you need, then click Save (or Discard to undo your edits). AI apps follow the new settings within 30 seconds.

SettingDefaultYou can set
The switch next to the title (allow AI apps in this workspace)On, on paid plansOff: nobody in the workspace can use AI apps with Tahoe
Who may connect appsEveryone in the workspaceOwners and admins only, or Nobody
Which appsAny appVerified apps only, or Only the apps listed below (one app identifier per line)
What AI apps may doAll on except Post on LinkedIn and BillingTurn each capability on or off (see below)
Most credits one action may spend1500 to 10,000
Credits per person per day3000 to 50,000
Credits for the workspace per day25% of your monthly credits, up to 3,0000 to 100,000
Recipients per campaign launch501 to 2,000
Recipients per person per day1001 to 5,000
Campaign launches per person per day31 to 100
People with contact details per answer251 to 25
Contact values per person per day5001 to 5,000

Daily limits start again at midnight UTC. A new connection is also held to at most 100 credits and 10 email recipients in its first 24 hours. Every action still has its own credit ceiling, set when it runs. Credits and limits

What AI apps may do

Each capability is a switch. When one is off, its tools disappear from every connection in the workspace, so apps cannot even try. This also frees room in apps that limit how many tools they show, such as Microsoft Copilot Studio.

CapabilityWhat it coversDefault
Run searchesNew search pages, X-ray and concierge requests, and starting GitHub searches. These spend credits.On
Reveal contact detailsWork emails, personal emails and phones, résumé unlocks and GitHub CSV exports. These spend credits.On
Send emailLaunching and resuming campaigns, messaging applicants and test emails from a person’s mailbox.On
Publish jobsPublishing, closing and reopening job postings.On
Export to your ATS or CRMCreating candidates in a connected ATS or CRM.On
Team and complianceInviting teammates, changing roles, updating workspace settings and erasing applicant data.On
Post on LinkedInPublishing posts to a person’s own LinkedIn feed.Off
BillingPayment links and plan changes.Off

These switches only ever narrow what people can do. Nobody gets more through an AI app than their own Tahoe role allows.

See and end members’ connections

The Members’ connections card lists every AI app connected to this workspace: the person, the app and its badge, how many permissions it has and when it was last used.

  • Disconnect on a row ends that one connection within 30 seconds.
  • Disconnect all ends every connection in the workspace within 30 seconds. People can connect again unless you also turn AI apps off, or set Who may connect apps to Nobody.

The activity log

The Activity card records every request an AI app made in the workspace (when, who, what and the result) and every person whose contact details, résumé or phone screen an AI app read. Entries are kept for 400 days. Click Show older to go further back.

Registered apps

Gemini Enterprise, Microsoft Copilot Studio and your company’s own agents connect through an app you register for this workspace only. Each person still signs in with their own Tahoe account.

Get the redirect URL

In the other product’s admin console, start adding Tahoe as an MCP server and copy the redirect URL it shows.

Register the app in Tahoe

In Settings → AI connectors → Registered apps, choose the App: Gemini Enterprise, Microsoft Copilot Studio or Internal agent. Add a name if you like, paste the redirect URL, and click Register app.

Copy the details back

Tahoe shows the client ID, the client secret, the server URL, the authorization URL and the token URL. Copy them into the other product’s console. Copy the secret now: Tahoe cannot show it again. Then click I’ve copied it.

To stop using a registered app, click Disable on its row. Nobody can sign in through it any more, and everyone connected through it is disconnected. App-by-app steps are in the Gemini and Microsoft Copilot guides.

Example

Example

Jordan Rivera, the owner at Kestrel Labs, wants the team to try AI apps but keep spending low and hold off on email for the first two weeks.

Jordan opens Settings → AI connectors, lowers Credits per person per day to 100, turns off Send email and clicks Save. Within 30 seconds, the email tools disappear from everyone’s apps, and nobody can spend more than 100 credits a day through them. Each Friday, Jordan reads the Activity log to see how the team uses them.