Research agent wants access
- Folder
- /research
- Access
- read only
- Duration
- 60 minutes
- Other folders
- not visible
Only /research is visible.
Software should come to it.
Groundware lets tools request access to the files, notes, folders and context you already control, without becoming the place that owns everything. Your notes stay where they are, and tools only see what you allow.
Your data stays yours
Groundware starts from the files and notes people already control. For Obsidian, that means your notes stay markdown and your vault stays recognisable.
A tool can ask for one folder without ever seeing the rest of the vault.
Read how a grant is scopedyour-data
notes stay markdown folders are shared by choice tools only see what you allow access can expire history stays visibleHow access works
Groundware shows what a tool is asking for, what it can reach, how long the grant lasts, and what it did afterwards.
Only /research is visible.
Routes
Routes are different ways for software to come to user-owned data. They are not separate places to put everything.
One place to see your data, the tools connected to it, every live grant, and the log of what they did.
for developersBuild apps, plugins, agents and integrations that request scoped access to user-owned context.
first routeStart with the vault people already use. Notes stay markdown, and tools ask before they read.
(Same ground either way — there is nothing to migrate.)
No card needed
From $6 a month
Principles
Everything else in the product is negotiable. These are the commitments the architecture is built around, and the reason it is built the way it is.
Nothing is copied to a server you cannot see. Payloads are encrypted on your device and the platform holds ciphertext, so there is no copy of your work that we could read, sell, train on, or be compelled to hand over. If Groundware disappears tomorrow, every file you have is still sitting where it was, in the format it was already in.
Every write creates a new version rather than overwriting the last one. Earlier states are kept, and any of them can be restored without asking a tool to undo what it did. A grant that turned out to be a mistake is recoverable, not just revocable.
Each version is content addressed and checksummed. A file that has been damaged in transit, truncated by a failed sync, or altered by something that should not have touched it is detected on read rather than quietly propagated over the good copy.
A grant covers a path, not a vault. It carries a level, read only or read and write, and nothing outside that path is readable or even enumerable. A tool that asks for one project folder cannot discover that the others exist.
Grants lapse on their own. A duration is part of the request, not a setting buried later, and when it runs out the tool has to ask again. Revoking takes effect on the next request rather than at the end of a session.
Every request, decision, read, write and expiry is written to your own storage in plain text. It is searchable, exportable and archivable with the rest of your files, and nothing is summarised away or retained on our side.
A context is a folder with a structure written down: the fields a tool can expect to find, and the ones it is allowed to add. That is enough for an agent to work in it without a bespoke integration for every product.
The same context serves an editor, an agent, a script and a colleague. Knowledge stops being re-entered once per application, and a tool you adopt next year reads what you wrote in one you dropped last year.
Underneath, a context is ordinary files in ordinary folders. You can move it, back it up, open it in something else, or walk away from the structure entirely without a migration.
Private beta
We are opening the first ground routes soon. Leave an address and we will tell you when private beta access is ready. One message, no list.
Get notified