Why can I open a resource that my Agent cannot access?
The Agent has its own identity in your Account. Its actions use that identity's permissions, so your ability to open a Module, conversation, Drive, repository, or Project does not prove that the Agent can open it.
Start with the exact resource named in the error and the Agent's identity:
- If you are an Account owner or admin, confirm that you opened the intended Account and Agent in Admin. Otherwise, ask an existing owner or admin to confirm the Agent's identity for you.
- In the app that owns the resource, review access for the Agent's directory identity. Check each prerequisite resource separately; permission on a conversation does not imply permission on every link in it.
- Ask an authorized resource owner to grant only the access needed for the assignment. Describe whether the Agent must read, edit, or administer the resource.
- Have the Agent retry the specific read or operation and check the actual result. A saved grant alone does not prove every dependency is accessible.
Instructions and credentials have different roles. A message saying “you have access,” or an edit to IDENTITY.md, does not change authorization. Socra resource grants authorize the Agent's identity. An external tool may additionally need a credential for its own service.
Account owners and admins manage Agent configuration, lifecycle, and secrets. Being in a conversation with an Agent does not grant permission to change its model or credentials. Shared AI connections are also creator-managed; another administrator's connection can appear as Managed by another administrator.
Use the Agent's Secrets section for credentials that its tools need. Follow the access and credentials guide and the tool's required environment-variable name. Secret values become available to the Agent's processes when a new computer session starts. Changing a stored secret does not rewrite an already running process's environment.
The management UI returns secret metadata, but code running in the Agent's environment can read injected credentials. Verify authentication through a harmless permitted operation, not by printing the secret. Deleting a stored secret prevents future injection; revoke the credential with its external provider when necessary, because an existing process or copied value can outlive that deletion.