# Manage company knowledge and memory

Canonical HTML: [https://collty.com/help/security/manage-company-memory](https://collty.com/help/security/manage-company-memory)
Audience: Company owners
Reading time: 9 min
Updated: 2026-10-08T00:00:00.000Z

Open Collty Intelligence Core, follow the source-to-use map and understand the company’s saved knowledge, versions and access boundaries.

## Open the company’s knowledge console

1. **Open My Account:** Use Account in the site header and open My Account.
2. **Choose Privacy & data:** Open Privacy & data, then Manage company knowledge. The console is called Collty Intelligence Core.
3. **Choose the company:** Select the company in the console header. Only its owner can open this console. Owning or participating in another company does not merge their knowledge.
4. **Start with Memory map:** Inspect the source groups and recorded uses. Use Refresh when you need to read the latest saved state. Opening this console does not itself run AI.

## Live work and saved memory are different layers

Projects, tasks, people, process definitions and responsibilities provide operating context. Source-linked memory records retain knowledge from work, together with its version, state and origin. Enabled connection actions can supply dated external observations. AI runs may record which memory versions they actually used.

An existing project can have no saved memory events. A connected application is not automatically copied into memory, and a saved document link is not the document’s complete text. Do not infer that every task, file or message has been ingested.

Stable company and work identities keep these layers connected. The console reports recorded relationships; it does not manufacture missing historical sources, references or decisions.

## Read the four counters

| Counter | What it means |
| --- | --- |
| Current memory entries | The latest saved version of each source-linked entry. Current means latest, not automatically approved or confirmed. |
| Versions in history | All saved versions, including older versions replaced by later knowledge. One entry can have several versions. |
| Drafts & observations | Current Draft or Observed entries. These are preliminary evidence, not approved company decisions. |
| Projects without memory | Company-owned projects without saved memory events. Their tasks, files and other working records can still exist. |

> **Good to know:** Use the question button beside each counter for its definition. On a touch screen, tap it.

## Follow what is saved and how it has been used

1. **Select a source group:** Select a source node on the interactive map to see its description, current entries and history. The map groups sources instead of loading every task or process into one list.
2. **Inspect the selected scope:** Use the detail panel to explore the relevant saved records or operating context. Inspect the recorded origin, version, state and date before treating a record as current guidance.
3. **Select a recorded use:** Select a use node to inspect the AI operations associated with it. A connection represents recorded memory use, not proof that every operation in that feature retrieved knowledge.
4. **Check exact evidence:** Where a run recorded memory references, inspect those versions. An operation with zero recorded entries does not establish that the model used company memory. Missing older references are not reconstructed.

> **Good to know:** An AI output is a recommendation or result of a run. It does not prove that a proposed change was applied, approved or accepted in the underlying project.

## Inspect connections under Sources

Sources shows connections explicitly granted to the company’s projects and the actions they can use. Read actions supply evidence; write actions can change an external resource and retain their own permission and approval requirements.

Inspect the project, connection and allowed actions before enabling access. Manage a project’s source grant through its connection controls. Selecting a company or writing an AI instruction cannot grant access to another company’s information.

A source grant and collection policy are different controls. Pausing collection does not revoke connection credentials. Revoking an external connection does not erase observations that were already stored; review the company’s erasure controls separately.

## Understand Access

Access explains the company boundary, work scope, connected source controls and owner controls. The server checks the current actor and the requested resource when knowledge is read, composed for AI or exported.

The owner’s portable company archive excludes other companies’ knowledge, client-shared supplier memory, connection secrets and private learner fields. Ordinary project participation does not grant export or erasure rights.

For a participant, knowledge remains limited to their authorized work and enabled source actions. Role guidance explains responsibilities; it is not a substitute for application permissions.

## Pause or resume collection

1. **Open Controls:** Check the selected company before changing its collection policy.
2. **Use Pause collection:** New source-linked company memory, scoped AI traces and cached external observations are stopped. Stored company memory is excluded from retrieval while collection is paused. Existing operational work remains available.
3. **Resume deliberately:** Use Resume collection when you want permitted collection and retrieval to continue. Resume does not recreate erased records or revoke and recreate connection grants.

> **Good to know:** Pause collection is not a general stop button for every business application or every agent action. Disable or pause an agent separately when you need to stop its workflow.

## Know what the protection covers

Sensitive stored payloads use application-level AES-256-GCM encryption and HMAC-SHA256 lookup indexes. Structural fields needed for ownership, ordering and access checks—such as identifiers, timestamps, types, states and scope—are not all encrypted.

Access checks, company boundaries and source permissions apply in addition to encryption. The downloadable archive is readable JSON and JSONL; exporting does not preserve the database’s at-rest encryption. Review it before sharing it with a provider or another person.

A deployment’s key configuration, backups and incident procedures remain operational controls. This console does not rotate encryption keys or erase provider-held copies and backups.

### Official references

- [Collty Intelligence Core](/intelligence-core) - Read the architecture, provenance and control model behind company knowledge.

## Related guides

- [Export Company Knowledge](https://collty.com/help/security/export-company-knowledge)
- [Erase Company Memory](https://collty.com/help/security/erase-company-memory)
- [Connect Apps And Map Data](https://collty.com/help/ai-agents/connect-apps-and-map-data)
- [Prepare And Complete Onboarding](https://collty.com/help/teams/prepare-and-complete-onboarding)
- [Private Workspaces And Access](https://collty.com/help/security/private-workspaces-and-access)
