Choose access for attended Sessions
Use the shield menu beside the composer to choose the Session access level.
On first use, a Session starts with Auto in workspace unless the Machine maximum is lower. After you choose another level, Cogno remembers that choice for the same Machine in this browser. If the Machine maximum is lower the next time you open a Session, Cogno starts at the maximum instead of restoring a higher choice.
A Machine maximum is a ceiling, not a default. Raising the maximum to Full access does not automatically raise a new Session from Auto in workspace.
Set access limits for a Machine
1
Open the Machine settings
Open Settings → Machines. Find the Machine whose limits you want to change.
2
Set the attended maximum
Under User-initiated maximum, choose the highest level a person may select for Sessions started or continued on that Machine.
3
Set autonomous access
Under Cogno autonomous access, choose the level for unattended queue turns on that Machine.
Confirm Full access once per Machine
The first time you choose Full access for a Machine in this browser, review and accept the warning. Cogno remembers the confirmation for that Machine, so changing a Session or Machine setting to Full access later does not open the same dialog again. Clearing browser storage or enrolling the computer as a new Machine removes the remembered confirmation. Cogno then asks again the next time you choose Full access. Full access requires Engine protocol 3 or later. On an older Engine, the option is disabled and the Machine settings explain that Engine must be updated.Understand what can stop tool access
Cogno checks tool access against the current Workspace, Project, Machine, and run. A token issued earlier does not preserve access after those relationships change.
Tool access also depends on the member’s current permission for the requested operation. A tool’s presence in the catalog is not permission to execute it. External integrations still require their own connection and provider permission checks.
Discover available Project sources
Source discovery separates connections even when they contain the same resource ID. It returns only selected targets still present in that connection’s current catalog. Personal connections are visible only to the trusted actor who owns them; without an actor, discovery returns shared connections only. Discovery does not replace the permission check performed when a tool reads the source.Keep the execution components updated
Queue claims and attended-run token requests require an explicit execution-policy acknowledgement. A Machine running an older Engine receivesexecution_policy_upgrade_required before a new queue run is claimed or a token is issued. Update the execution components together with the web and desktop application; do not disable the access checks to restore compatibility.