Permissions and your workspace
What the connection is bound to, what Claude Code may read, what it may never change, and how to revoke it.
One workspace, chosen once
When you authorise Claude Code you pick a workspace on the consent screen, and the connection is bound to it permanently. Switching workspace in the browser afterwards does not move the connection — Claude Code keeps working in the one you chose.
To point it somewhere else, revoke and authorise again. There is no setting that retargets an existing connection, which is deliberate: a background agent should not follow a tab you happen to have open.
The authorisation is yours, not your organisation's. A colleague who wants the same thing authorises separately, and revoking yours does not touch theirs.
What it may never change
Claude Code writes documents. That is the whole list.
It cannot edit your Knowledge Base, and it never will. Everything unpitch judges a message against comes from what you have written down about your business, so an agent that could edit it could move the ground under its own evaluation — and you would have no way to see it happen. The same reasoning covers personas: Claude Code can read them to pick a reader, and cannot create or alter one.
It also cannot change billing, plans, members, or anything in Settings.
What it can see
Only the workspace you chose. The searches it runs return excerpts with their sources attached rather than whole files, and the reads are bounded — one request cannot pull your entire workspace into a model's context.
It never receives your password, your session, or any credential. The connection uses a browser authorisation that hands Claude Code a token scoped to this one purpose.
Revoking
Open Settings → Integrations and press Revoke. The next request from Claude Code fails; there is nothing to wait for and nothing cached that keeps working.
Two things end a connection without you doing anything. Losing access to the organisation ends it, and authorising again replaces the old connection rather than adding a second one. In both cases every token from the old connection stays dead permanently, including after you reconnect.
Revoking does not delete anything Claude Code created. Those documents are yours and stay where they are.