File Access Policies
Every file request passes through three independent layers before the AI receives anything. A block at any layer returns a "permission denied" response - the AI never sees the file contents.
Certain file types and paths are always blocked regardless of any setting. This includes credential files, private keys, and secrets folders.
.env.pem.key.p12.pfxid_rsasecrets/Admins can restrict which file types and paths are accessible within their org or workspace. Workspace settings override org settings, org settings override system defaults.
Works like a .gitignore file. Place a .devicelinkignore file in any shared directory to exclude specific files or folders from AI access.
.DS_Store*.logdist/node_modules/Configurable policy settings
Organization and workspace admins can configure Tier 2 policies from org settings or the workspace settings page. Settings at the workspace level override the org, which overrides system defaults.
.exe, .dll, .binFile types that are always denied, e.g. .exe or .dll
.ts, .js, .mdWhen set, only these file types are permitted. Everything else is denied.
vendor/**, *.min.jsGlob patterns for paths to deny, evaluated against the relative path inside the shared folder.
5242880 (5 MB)Files larger than this limit are not returned. Default is 10 MB.
Using .devicelinkignore
Place a .devicelinkignore file in any shared folder to exclude files or directories from AI access. The format is identical to .gitignore.
# .devicelinkignore example
*.log
*.tmp
dist/
.env.local
secrets/The ignore file is read by your local agent, so it works even without any org-level policies configured. See How Sharing Works for more on what the AI can and cannot access.