You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: apps/docs/content/docs/knowledgebase/connectors.mdx
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -78,7 +78,7 @@ Each connector has source-specific fields that control what gets synced. Example
78
78
79
79
-**Notion** — sync an entire workspace, a specific database, or a single page tree
80
80
-**GitHub** — specify a repository, branch, and optional file extension filter
81
-
-**Confluence** — enter your Atlassian domain and optionally filter by space key or content type
81
+
-**Confluence** — enter your Atlassian domain and choose spaces, or **All** for all spaces accessible at each sync. Optionally filter by content type or label. PDF and Word (`.docx`, Word 97–2003 `.doc`) attachments on matching pages and blog posts are included as separate documents.
82
82
-**Azure DevOps** — choose what to sync (wiki pages, work items, repository files, or all), with optional work item type/state filters, a custom WIQL query, and repository/branch/path filters
83
83
-**Amazon S3** — point at a bucket with an optional key prefix and a customizable file extension allowlist; S3-compatible stores (Cloudflare R2, MinIO) are supported via a custom endpoint
84
84
-**YouTube** — sync a channel (by `@handle` or ID) or playlist, with an optional published-after date filter and the option to exclude Shorts
@@ -88,6 +88,8 @@ Each connector has source-specific fields that control what gets synced. Example
88
88
89
89
Configuration is validated on save — if a repository doesn't exist or a domain is unreachable, you'll see an error immediately.
90
90
91
+
Confluence attachment indexing requires `read:attachment:confluence`. For a service account, include it when creating the scoped API token; see the [Confluence scope list](/search/confluence#using-a-service-account). Attachments are checked even when the parent page has not changed. Files over 100 MB appear as skipped; convert Word 6/95 files to `.docx` before attaching them.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/platform/self-hosting/environment-variables.mdx
+2-1Lines changed: 2 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -234,9 +234,10 @@ width. Check what you pick there, or upgrade Ollama.
234
234
|`COPILOT_API_KEY`| API key for Chat. Without it the Sim Chat block, scheduled prompt jobs, and Inbox cannot run |
235
235
|`NEXT_PUBLIC_CHAT_DISABLED`| Set to `true` to hide the Chat module: the workspace lands on your first workflow, with no chats list, scheduled tasks, or editor Chat panel. Chat is shown when unset; `npx sim-setup` sets it for you if you skip the chat key |
236
236
|`PII_URL`| Base URL of the Presidio service backing PII detection and redaction. The Helm chart wires it to its own `pii` Service when `pii.enabled`; on Compose point it at the PII service on your network. The default `http://localhost:5001` exists only in local development, and leaving it makes redaction fail |
237
-
|`DURABLE_SECRET_PROVENANCE_ENFORCED_SURFACES`| Durable stores where a value whose secret provenance was never recorded fails the run instead of logging a warning. `all`, or a comma-separated subset of `memory`, `table-row`, `knowledge`, `workspace-file`. Unset (nothing enforced) by default |
238
237
|`ADMIN_API_KEY`| Admin API key for GitOps operations and organization provisioning |
239
238
239
+
Tracked memory, table rows, knowledge content, and workspace files require valid secret provenance before entering a model or a trusted runtime. Records with a null provenance tracking marker retain legacy compatibility.
240
+
240
241
## Enterprise Features
241
242
242
243
Enterprise features are unlocked by configuration rather than billing on self-hosted deployments. One switch turns on the full set; per-feature flags below it override the switch either way.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/search/coda.mdx
+28-6Lines changed: 28 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,14 +19,27 @@ Sign in to Coda with a dedicated integration account that can read the documents
19
19
20
20
Use a standard REST API token. Do not select the MCP restriction.
21
21
22
-
<ImageclassName="mx-auto h-auto w-full max-w-2xl"src="/static/search/coda-api-token.jpg"alt="Coda API connections with the Generate new token dialog"width={1280}height={720} />
22
+
<ImageclassName="mx-auto h-auto w-full max-w-xl"loading="eager"src="/static/search/coda-token-creation.jpg"alt="Coda Generate new token dialog with a name and no restriction selected"width={600}height={281} />
23
23
24
24
</Step>
25
25
<Step>
26
26
27
-
### Add the source
27
+
### Add the credential
28
28
29
-
In Sim, open **Settings → Sources → Add source → Coda**. Add or select a Coda service account credential and enter the token when prompted.
29
+
In Sim, open **Settings → Sources → Add source → Coda**. If Coda is already listed, open it and select **Add connection**.
30
+
31
+
Open **Service account → Add API token**. Paste the token, give it a recognizable display name, then select **Add API token**. You can also choose an existing Coda credential.
32
+
33
+
<ImageclassName="mx-auto h-auto w-full max-w-md"src="/static/search/coda-credential.jpg"alt="Add Coda API token form with token, display name, and optional description fields"width={516}height={435} />
34
+
35
+
</Step>
36
+
<Step>
37
+
38
+
### Choose documents
39
+
40
+
Select the documents to index, or leave the selection empty for discovery.
41
+
42
+
<ImageclassName="mx-auto h-auto w-full max-w-md"src="/static/search/coda-setup.jpg"alt="Coda connection setup with a saved credential, Documents selector, and optional Enterprise organization ID"width={516}height={458} />
30
43
31
44
| Field | What to enter |
32
45
|---|---|
@@ -40,7 +53,7 @@ The picker shows accessible documents the token owner has opened. Use IDs for ot
40
53
41
54
### Sync and verify
42
55
43
-
Select **Connect & Sync**. Open the source's **Documents** and **Sync history** to check indexing. Content and permission changes appear after synchronization.
56
+
Select **Connect & Sync**. Open the source's **Documents** and **Sync history** to check indexing. Content and permission changes appear after synchronization. Have a teammate with a matching verified email search for a shared document, and confirm that an unshared teammate cannot find it.
44
57
45
58
To rotate the token, add the replacement credential, update the source, and verify a sync before revoking the old token.
46
59
@@ -59,8 +72,17 @@ Ordinary connections index visible canvas text and base-table rows. Enterprise c
59
72
60
73
Enterprise mode excludes deactivated and deleted users. Direct-share guests absent from the organization directory are excluded; guests explicitly listed in a group or workspace may receive that membership's access. Ordinary connections cannot check Coda organization deactivation, so manage departing users' Sim membership too.
61
74
62
-
Sim refreshes permissions even when content is unchanged. Unverified permissions never become broad access, and Sim admin status does not override Coda sharing. For setup failures or missing results, check the token's access, Enterprise admin role if applicable, the teammate's verified email, and **Sync history**.
75
+
Sim refreshes permissions even when content is unchanged. Unverified permissions never become broad access, and Sim admin status does not override Coda sharing.
76
+
77
+
These access rules apply to organization Search and **Admin access** sources. In a regular knowledge base, **Workspace access** shares all indexed content with that Sim workspace and ignores the Enterprise organization ID.
63
78
64
-
In a regular knowledge base, **Workspace access** intentionally shares all indexed content with that Sim workspace and does not use the Enterprise organization ID. The permissions above apply to organization Search and **Admin access** sources.
79
+
## Troubleshooting
80
+
81
+
| Problem | Next step |
82
+
|---|---|
83
+
| Document missing from the picker | Open it in Coda with the token owner, or enter its document ID. |
84
+
| Enterprise setup fails | Confirm the organization ID and Enterprise org-admin role. A workspace admin token is insufficient. |
85
+
| Teammate sees no results | Check organization membership, their verified Sim email, the Coda share, and **Sync history**. |
86
+
| Token expired or revoked | Replace the credential in the connection's **Settings**, then verify a sync. |
65
87
66
88
See Coda's [public API](https://coda.io/developers/apis/v1) and [Enterprise Admin API](https://coda.io/developers/apis/admin/v1).
Search pages and blog posts from selected Confluence Cloud spaces. A Sim organization admin enables Confluence; **each teammate connects their own account**.
10
+
Search pages, blog posts, and their PDF and Word attachments from selected Confluence Cloud spaces. A Sim organization admin enables Confluence; **each teammate connects their own account**.
11
11
12
12
| Method | How it works |
13
13
| --- | --- |
@@ -38,7 +38,9 @@ Open **Settings → Sources → Add source** and select **Confluence**. This ope
38
38
39
39
### Choose the account and spaces
40
40
41
-
Under **Service account**, select a service account or [add one](#using-a-service-account). Enter the same **Confluence site** as the credential, then choose **Spaces**. **All** in the dropdown selects every space the account can currently browse; newly created spaces are not added automatically. Clear the picker search before selecting all.
41
+
Under **Service account**, select a service account or [add one](#using-a-service-account). Enter the same **Confluence site** as the credential, then choose **Spaces**. **All** in the dropdown includes every space the syncing account can access at each sync, including newly accessible spaces. Clear the picker search before selecting all.
42
+
43
+
If you selected all spaces before this behavior was introduced, reselect **All** and save. Previously saved selections remain a fixed list of spaces.
42
44
43
45
To enter comma-separated keys such as `ENG, PRODUCT`, use the switch beside **Spaces**. Switching between the picker and manual entry keeps your selection.
44
46
@@ -63,7 +65,7 @@ After an admin configures Confluence, open **Integrations** and select **Connect
63
65
If Confluence is allowed but no source exists, select **Connect** beside Confluence. To add another site later, open the Confluence row’s actions menu (**…**) and select **Add Confluence site**:
64
66
65
67
1. Open **Your account** and select a saved account or **Connect Confluence account**. Authorize using the Atlassian email matching your verified Sim email.
66
-
2. Enter the hostname under **Atlassian site**, then choose **Spaces**. Use **All** in the dropdown for the complete current list, or the arrows beside **Spaces** to enter comma-separated keys. You can select up to 1,000 spaces in this form.
68
+
2. Enter the hostname under **Atlassian site**, then choose **Spaces**. Use **All** in the dropdown for all spaces accessible at each sync, or the arrows beside **Spaces** to enter comma-separated keys. You can select up to 1,000 individual spaces in this form.
67
69
3. Select **Connect & Sync**. Sim saves the selected scope and starts indexing with your account.
68
70
69
71
<ImageclassName="mx-auto h-auto w-full max-w-md"
@@ -87,6 +89,7 @@ Use a **scoped API token** from an Atlassian service account:
87
89
read:confluence-content.all
88
90
read:page:confluence
89
91
read:blogpost:confluence
92
+
read:attachment:confluence
90
93
read:space:confluence
91
94
read:label:confluence
92
95
search:confluence
@@ -98,7 +101,7 @@ read:user:confluence
98
101
read:group:confluence
99
102
```
100
103
101
-
Use all 12 scopes for account validation, pickers, content, permissions, and directory reads. Central indexing does not need write scopes.
104
+
Use all 13 scopes for account validation, pickers, content, attachments, permissions, and directory reads. Central indexing does not need write scopes.
102
105
103
106
4. Review and create the token, then copy it. Atlassian shows it only once.
104
107
5. In Sim's source form, open **Service account → Add service account**. Paste the **API token**, enter **Site domain** (hostname only), and select **Add service account**. Continue in the source form with the same domain.
@@ -122,7 +125,9 @@ See Atlassian's [account setup](https://support.atlassian.com/user-management/do
122
125
|**Filter by Label**| Optional comma-separated labels; content can match any listed label. |
123
126
|**Metadata tags**| Labels, version, and last-modified tags. |
124
127
125
-
Search manages the schedule and hides item limits. It indexes published/current content and each page's own text, including supported local callouts and code blocks. Archived content, comments, attachment contents, and expanded Include Page, Excerpt Include, or third-party macro output are excluded. Referenced pages can be indexed separately with their own permissions.
128
+
Search manages the schedule and hides item limits. It indexes published/current content and each page's own text, including supported local callouts and code blocks. PDF, Word `.docx`, and Word 97–2003 `.doc` attachments on the selected pages and blog posts are indexed as separate documents with their parent content's permissions. Space, content-type, and label filters apply to the parent content. Attachment changes are checked on each sync, even when the parent text has not changed.
129
+
130
+
Archived content, comments, other attachment formats, and expanded Include Page, Excerpt Include, or third-party macro output are excluded. Referenced pages can be indexed separately with their own permissions. Attachments over 100 MB are shown as skipped; convert older Word 6/95 files to `.docx` before attaching them.
126
131
127
132
## Manage access and sync
128
133
@@ -146,6 +151,7 @@ In **Sync history**, **Continuing** means a healthy listing needs another batch.
146
151
| A new page, blog post, or label is missing | Confluence search can take time to update. Once the content appears in Confluence search with the selected label, sync again. |
147
152
| A restricted page is missing | Both your account and the crawling account need access to the page and its ancestors. |
148
153
| Embedded content is missing | Index the referenced page separately; remote macro output is excluded. |
154
+
| PDF or Word attachments are missing | Check `read:attachment:confluence` and access to the parent page. Existing service-account tokens may need to be replaced with one that includes this scope. Attachment access failures are reported as a partial sync. |
149
155
|**Reconnect** or email mismatch | Authorize with the Atlassian account matching your verified Sim email and grant all requested permissions. |
150
156
151
157
Open a missing page as the affected teammate, check its space and page restrictions, then sync again after correcting access. See Atlassian's [content access](https://support.atlassian.com/confluence-cloud/docs/add-or-remove-page-restrictions/) and [permission inspection](https://support.atlassian.com/confluence-cloud/docs/inspect-a-users-permissions/) guides.
Copy file name to clipboardExpand all lines: apps/docs/content/docs/search/gmail.mdx
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -133,7 +133,7 @@ Search schedules syncs hourly. The first sync lists every thread in scope and ca
133
133
134
134
**Member accounts:** later syncs use each mailbox's Gmail change history, unless the configuration has a search filter. A full relisting runs about weekly, or sooner if Gmail no longer retains the saved history.
135
135
136
-
**Service account:** each sync revisits the selected active mailboxes and resumes unfinished listings. If Google reports that a user's mailbox is not set up or returns a mailbox `failedPrecondition`, Sim records a warning and continues with the remaining users. The crawl stays incomplete and retries affected users on the next scheduled crawl; existing indexed mail is not deleted because a mailbox could not be read. Credential, delegation, and Directory failures still stop the crawl.
136
+
**Service account:** each user's progress is saved separately, so a large mailbox or an account-specific access failure does not hold up other users. Temporary failures retry automatically. Unavailable mailboxes are revisited without deleting indexed mail solely because the mailbox could not be read. Sim continues discovering users and refreshing existing mail and permissions while unfinished work resumes. Results with stale or unverified permissions remain hidden. Credential, delegation, Directory, and scope failures still require attention.
137
137
138
138
Updates, removals, and access refresh in the background. Empty mailboxes and filters with no matches complete normally with zero documents. Threads exceeding indexing size limits are skipped and reconsidered when they change.
0 commit comments