Skip to content

Commit 5d5ab7d

Browse files
committed
docs(search): document Generic Secrets and clarify source setup
1 parent 32233bd commit 5d5ab7d

5 files changed

Lines changed: 36 additions & 10 deletions

File tree

‎apps/docs/content/docs/platform/connected-accounts.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -111,7 +111,7 @@ For administrators, the controls have different scopes:
111111
- **One pool per organization:** there are no additional groups, per-workflow grants, or per-account workspace allowlists.
112112
- **One Databricks configuration:** multiple tenant endpoints cannot be added as separate Databricks providers in the same pool.
113113
- **Organization operations are missing:** confirm the feature is enabled for the organization and the workflow's workspace is allowed.
114-
- **An invitation rejects your sign-in:** use the verified Sim account matching the invitation email. For OAuth providers, connect the provider account with that same email.
114+
- **An invitation rejects your sign-in:** use the verified Sim account matching the invitation email. The provider account can have a different email; the invitation stays bound to the verified Sim user.
115115
- **A Find operation fails:** it requires exactly one active matching connection. Check the invitation email, provider, connection status, and workspace access. It never chooses an arbitrary account when there are zero or multiple matches.
116116
- **A list seems incomplete:** organization list operations return up to 100 connections per page. Follow `nextCursor` while `hasMore` is true.
117117
- **A legacy Credential Group block fails:** replace it with the appropriate Credential block operation or trigger, update its output references, and redeploy the workflow.

‎apps/docs/content/docs/search/connect-your-account.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ You do not select repositories, channels, labels, or an indexing method while co
2626
| Confluence service account | Connect your own Confluence account. Both connections must be able to read the selected content. |
2727
| Coda | Connect your personal Coda MCP account. In service mode, the source token also verifies the parent document. |
2828
| GitLab | No personal connection. Your verified Sim email must match current GitLab identity and permissions, or the administrator's CSV mapping and project grant. |
29-
| Generic Secrets in Member mode | Open the source in Integrations and save your own secrets. These are available to Build mode, not document search. |
29+
| [Generic Secrets in Member mode](/search/generic-secrets) | Open the source in Integrations and save your own secrets. These are available to Build and Plan, not document search. |
3030

3131
Gmail, Calendar, and Drive are separate connections. Connecting one does not authorize the others. A service account is a resource boundary, not a replacement for your personal connection, except for GitLab's explicit permission model.
3232

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,25 @@
1+
---
2+
title: Generic Secrets
3+
description: Share organization secrets or let each member keep their own for Build and Plan
4+
---
5+
6+
Generic Secrets is a source for values that Build and Plan can use in code and requests. It does not add documents to Search, connect an external account, or start an indexing job. The editor is the same [secrets editor used in workspaces](/platform/credentials).
7+
8+
## Add the source
9+
10+
An organization admin opens **Settings → Sources → Add source → Generic Secrets** and chooses one mode:
11+
12+
| Mode | Who manages the values | Who can use them in Build and Plan |
13+
| --- | --- | --- |
14+
| **Organization** | Organization admins open **Secrets** from the source in Settings. | Organization members with Build access use the shared values. Members cannot open the editor to view them. |
15+
| **Member** | Each person opens **Integrations → Generic Secrets → Manage secrets**. | That person uses only their own values in the organization. |
16+
17+
Only the selected mode is active. The admin can change it through **Configure** on the source. Removing the source deletes its organization and member secrets, so review the confirmation before doing so.
18+
19+
## Use a secret in Build or Plan
20+
21+
Save a name and value in the editor, then ask Build or Plan to run code that needs it. These modes can see available **names** and mount only the names needed by `run_code` or `run_function`. The values become environment variables for that code, so it can use them in a request such as `curl` without putting the value in the prompt.
22+
23+
In an organization Build or Plan conversation targeting a workspace, an organization secret with the same name takes precedence over a workspace secret. In Member mode, the source resolves the current member's values; it does not read another member's secrets.
24+
25+
Generic Secrets are available **only in Build and Plan modes**. Search, the Search assistant, Search MCP, and Sim Search in Slack cannot mount them. Workspace secrets remain a separate resource.

‎apps/docs/content/docs/search/index.mdx‎

Lines changed: 8 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -5,17 +5,17 @@ description: Search connected sources live with each person's current access
55

66
Search queries your connected providers when you ask a question. It does not copy their documents into a Sim vector index or wait for a background sync.
77

8-
An organization admin adds integrations under **Settings → Sources**. Teammates connect their accounts under **Integrations** in the main sidebar. Credential Groups remain a separate feature for sharing account connections with workflows.
8+
An organization admin adds sources under **Settings → Sources**. Teammates connect their provider accounts under **Integrations** in the main sidebar. Credential Groups remain a separate feature for sharing account connections with workflows.
99

1010
## Add your first source
1111

12-
1. Open **Settings → Sources → Add source** and choose an integration.
13-
2. Choose **Member accounts** or, when supported, **Service account**. GitHub calls the second mode **GitHub App**. Slack and Jira use member accounts; GitLab uses a service account.
14-
3. For member mode, save the source. For service mode, add or select a connection and configure its resources. GitHub uses **Add repository** for each repository; GitLab uses **Add project** for each project.
15-
4. Open **Integrations** and connect your personal account, including when you are the admin. GitLab is the exception: its configured project permissions identify readers without a personal connection.
16-
5. Open **Search**, or ask the assistant on **Home** about a document you can access.
12+
1. Open **Settings → Sources → Add source** and choose a provider or Generic Secrets.
13+
2. For a searchable provider, choose **Member accounts** or, when supported, **Service account**. GitHub calls the second mode **GitHub App**. Slack and Jira use member accounts; GitLab uses a service account. [Generic Secrets](/search/generic-secrets) instead offers **Organization** and **Member**.
14+
3. For provider member mode, save the source. For service mode, add or select a connection and configure its resources. GitHub uses **Add repository** for each repository; GitLab uses **Add project** for each project.
15+
4. For provider sources, open **Integrations** and connect your personal account, including when you are the admin. GitLab is the exception: its configured project permissions identify readers without a personal connection. Generic Secrets uses its built-in editor and needs no provider authorization.
16+
5. For a provider source, open **Search** or ask the assistant on **Home** about a document you can access. For Generic Secrets, use [Build or Plan](/search/generic-secrets).
1717

18-
Adding a source makes that integration available for members to connect. A provider that needs deployment or app configuration must have that configuration completed before account authorization can succeed.
18+
Adding a member-account provider source makes that integration available for members to connect. A provider that needs deployment or app configuration must have that configuration completed before account authorization can succeed.
1919

2020
## Choose the right connection method
2121

@@ -46,7 +46,7 @@ These nine providers support live Search. Google Docs, Sheets, and Slides are ac
4646
| [Jira](/search/jira) | Jira Cloud JQL and issue APIs | Member only |
4747
| [Slack](/search/slack) | Slack real-time search with the member's user token | Member only |
4848

49-
**Generic Secrets** is also available as a source, but does not add searchable documents. Organization mode makes its secrets available across the organization; Member mode lets each person manage their own secrets in Integrations. The Build assistant can use these secrets for requests. Search mode cannot use them to run arbitrary integration calls.
49+
[Generic Secrets](/search/generic-secrets) is also available as a source, but does not add searchable documents. Organization mode makes its secrets available across the organization; Member mode lets each person manage their own secrets in Integrations. Build and Plan can use these secrets for requests; Search cannot mount them.
5050

5151
## Access and freshness
5252

‎apps/docs/content/docs/search/meta.json‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"title": "Search",
33
"pages": [
44
"connect-your-account",
5+
"generic-secrets",
56
"mcp",
67
"coda",
78
"confluence",

0 commit comments

Comments
 (0)