Docs · Setup
Connect what a task needs. Nothing else.
Cedric starts with access to nothing. Every tool is connected deliberately, scoped to what it needs, and revocable in one click.
- Nothing is connected until you connect it. There is no default access to anything.
- Connect the first tool when a task needs it, not in advance, and start read-only wherever the tool supports it.
- Access is scoped per tool and revocable from the dashboard at any time, immediately.
- Connections are workspace-level, so your team shares them and nobody re-authorises the same tool five times.
- Read access never implies permission to act: writing, sending, and spending are gated separately by approvals.
Start from zero, on purpose
A fresh Cedric can do a surprising amount with no connections at all: summarize a thread, answer a question from what is in the channel, draft something, explain a concept, take notes in a meeting. That is a deliberate starting point, because it means you can evaluate how it thinks before deciding what it should see.
The first connection should be driven by a real task. Someone asks for something, Cedric says it needs access to a particular system to answer properly, and you decide whether that is reasonable. Connecting eleven tools on day one, in advance of any need, is the pattern that makes people uncomfortable later and it is not necessary.
Read-only is a destination, not a phase. Plenty of teams get most of their value from a Cedric that can read their systems and write nothing back to them. Reporting, reconciliation, triage, and research are all read operations.
Connecting a tool
The flow is the same for every system.
- 01
Ask for something that needs it
When a task needs a system Cedric cannot reach, it says so and hands you the connection link.
- 02
Authorise with the narrowest scope that works
You authorise through the tool's own permission screen, so the tool decides what it is willing to grant and you decide what to allow. Choose read-only when the task only reads.
If the permission screen asks for more than the task needs, that is the tool's granularity, not Cedric's request. Where a tool only offers broad scopes, weigh that before connecting.
- 03
Confirm what it can see
The dashboard lists every connection and what it covers. Look at it once the tool is on, while you still care.
- 04
Use it for the task that prompted it
Verify against something you already know the answer to. A first result you can check is worth more than an impressive one you cannot.
- 05
Revoke when it is no longer needed
One click in the dashboard, effective immediately. Ending a client engagement or a trial should include this step.
What connected actually means
A connection lets Cedric reach a system on your workspace's behalf, within the scope the tool granted. Three properties matter and are worth stating plainly.
It reads what the task needs. A question about last month's invoices means reading invoice records, not a sweep of everything the connection technically permits.
Access is logged. What was read, when, and for which task all show up in the activity view, so "what did it look at" is a question with an answer.
Reading is not acting. A connection with write permission does not mean Cedric will write. Changing a record still stops for approval, every time, regardless of what the token allows. The connection is the reach; approvals are the gate.
What to connect first, by team
The pattern is the same everywhere: the one system that holds the thing you are asked about most.
| Team | Connect first | Why this one | Read-only is enough for |
|---|---|---|---|
| Support | The helpdesk | It holds the queue, which is what everything else refers to | Triage, drafting, the weekly digest |
| Finance | Billing or the payment processor | Most reconciliation questions start here | Reconciliation and reporting |
| Engineering | The repository | Failures are only explainable against the code | Explaining failures, summarizing changes |
| Sales | The CRM | Pipeline questions are unanswerable without it | Pipeline questions, stalled-deal checks |
| Marketing | Analytics | It answers more channel questions than ad platforms do | Reporting and explaining movements |
| Operations | The two systems you compare most | Ops value comes from crossing sources | Almost everything ops needs |
In practice
It asks for access when it needs it, not before.
Grace Adeyemi9:14 AM
@Cedric how much did we invoice last month?
CedricAPP9:15 AM
I do not have access to your billing system yet, so I cannot answer that from records. Connect it and I will pull the exact figure with the invoices behind it. Read access is enough for this; I do not need permission to issue or change anything to answer it.
Things worth deciding before you connect
Who in your team should be able to reach what. Cedric works at the level of the channel it is in. A connection is workspace-wide, so think about which channels Cedric sits in as much as which tools it holds.
Tools with coarse permissions. Some systems only offer broad access. That is their design, not Cedric's request, and it is a fair reason to delay connecting one until you actually need it.
Regulated and client data. Contracts and regulations may constrain which systems can be processed this way. Check before you connect.
Offboarding is a real step. When an engagement, a trial, or a project ends, revoke the connections. It takes a click and it is the difference between tidy and forgotten.
FAQ
None. A new workspace can read the channel it was added to and nothing else. Every system connection is an explicit, deliberate act.
Where the tool offers a read-only scope, yes, and it is the recommended start. Many teams stay read-only permanently for their most sensitive systems.
One click in the dashboard, effective immediately. You can also revoke from the tool's own side, and Cedric will tell you it has lost access next time it needs it.
Connections are workspace-level, so the team shares them and one person authorising is enough. That is also why it is worth being deliberate about who is in the channel.
Yes. The activity view shows what was accessed, when, and for which task, so questions about what it looked at have a checkable answer.
If it exposes an interface Cedric can reach, it can generally be connected. If it does not, say what you need and you will get a straight answer about whether it is possible.
Only if you granted write access, and even then every change waits for an approval. See [how approvals work](/docs/how-approvals-work).
Ready when you are
Start with one connection.
Install Cedric, ask it something real, and connect the first tool when it asks for it.
$50 in free credits, no card needed.