Skip to content

Commit 73f6b88

Browse files
committed
fix(search): harden organization setup and document access
1 parent 73c6cad commit 73f6b88

35 files changed

Lines changed: 1179 additions & 440 deletions

apps/docs/content/docs/search/confluence.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ Search pages and blog posts from selected Confluence Cloud spaces. A Sim organiz
1111

1212
Search indexes each page's own text, including supported local callouts and code blocks. It does not expand Include Page, Excerpt Include, or third-party macros into that page. Referenced pages can be indexed separately with their own access rules.
1313

14-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
14+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1515

1616
## Choose a connection method
1717

@@ -40,7 +40,7 @@ On hosted Sim, personal connections authorize the existing Sim app. Teammates do
4040

4141
### Choose Confluence
4242

43-
Open **Integrations**, click **Add source**, and choose **Confluence**. Click **Set up** or **Continue setup** if prompted. Select your **Connection method**.
43+
Open **Settings → Integrations → Providers**, approve **Confluence**, then select **Set up**. Select your **Connection method**.
4444

4545
</Step>
4646
<Step>

apps/docs/content/docs/search/connect-your-account.mdx

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ import { Callout } from 'fumadocs-ui/components/callout'
77
import { Step, Steps } from 'fumadocs-ui/components/steps'
88
import { Image } from '@/components/ui/image'
99

10-
Your admin configures the source once. You connect your own account so Sim can establish what you are allowed to search.
10+
Your admin approves the provider and can configure shared source filters. You connect your own account so Sim can establish what you are allowed to search.
1111

1212
<Steps>
1313
<Step>
@@ -21,7 +21,7 @@ Accept your Sim organization invitation or sign in through your organization's S
2121

2222
### Open Integrations
2323

24-
Open **Integrations**, find the source, and select **Connect account**. If it is missing, ask an organization admin to add it.
24+
Open **Integrations**, find the provider or source, and select **Connect account**. Your first connection may ask for required source settings, such as repository or project names. If the provider is missing, ask an organization admin to approve it.
2525

2626
<Image src="/static/search/connect-account.png" alt="Google Drive source row with Connect account" width={1280} height={720} />
2727

@@ -32,14 +32,14 @@ Open **Integrations**, find the source, and select **Connect account**. If it is
3232

3333
In the new tab, select **Connect** and complete the provider's authorization. Choose the account associated with your verified Sim email. The provider may require your organization's SSO or app approval.
3434

35-
Return to Integrations when the connection completes. Keep the original tab open; **Open again** resumes the connection if a popup was blocked or closed.
35+
Return to Integrations when the connection completes. If the popup was blocked or closed, allow popups and select **Connect account** again. While authorization is pending, use **Open again**.
3636

3737
</Step>
3838
<Step>
3939

4040
### Start searching
4141

42-
The source row shows indexing status and how many documents are available to you. Open **Home → Search** and search for something you can already open in the source. Use **Assistant** to ask a question about your connected documents. The first sync may take time, especially for large accounts.
42+
The source row shows indexing status and how many documents are available to you. Open **Search** in the organization sidebar and search for something you can already open in the source. Use **Home** to ask the assistant about your connected documents. The first sync may take time, especially for large accounts.
4343

4444
</Step>
4545
</Steps>

apps/docs/content/docs/search/github.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import { Image } from '@/components/ui/image'
99

1010
GitHub Search indexes text files from a repository on `github.com`. An organization admin chooses the repository, then each person connects their GitHub account. Installing the GitHub App alone does not connect your teammates.
1111

12-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
12+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1313

1414
## Before you start
1515

@@ -102,7 +102,7 @@ In the App's sidebar, choose **Install App**, select the target account, and gra
102102

103103
### Open GitHub setup
104104

105-
As a Sim organization admin, open **Integrations**, choose **Add source**, then **GitHub**.
105+
As a Sim organization admin, open **Settings → Integrations → Providers**, approve **GitHub**, then select **Set up**.
106106

107107
</Step>
108108
<Step>

apps/docs/content/docs/search/gitlab.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ GitLab Search uses an administrator connection to sync a project's content and p
1111

1212
<Image src="/static/search/gitlab-setup.jpg" alt="GitLab source setup in Sim Search" width={1280} height={720} />
1313

14-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead.
14+
Admin setup uses your organization's **Settings → Integrations** page. Teammates do not need a personal GitLab connection. For workspace Search, use **Search → Add source** instead.
1515

1616
## Before you start
1717

@@ -49,7 +49,7 @@ The token must read the project, users, inherited project membership, instance s
4949

5050
### Configure the source in Sim
5151

52-
Open **IntegrationsAdd source → GitLab**. Paste the token and enter your instance host explicitly.
52+
Open **SettingsIntegrations → Providers**, approve **GitLab**, then select **Set up**. Paste the token and enter your instance host explicitly.
5353

5454
| Field | What to enter |
5555
|---|---|

apps/docs/content/docs/search/gmail.mdx

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import { Image } from '@/components/ui/image'
99

1010
Search email threads from your own Gmail account. An organization admin enables the source; each teammate connects their own account. An admin's connection does not make their mailbox available to the team.
1111

12-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
12+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1313

1414
## Set up the source
1515

@@ -20,7 +20,7 @@ These steps require a Sim organization admin.
2020

2121
### Add Gmail
2222

23-
Open **IntegrationsAdd source → Gmail**. Gmail uses **Member accounts**; there is no domain-wide or service-account crawl in Search.
23+
Open **SettingsIntegrations → Providers**, approve **Gmail**, then select **Set up**. Gmail uses **Member accounts**; there is no domain-wide or service-account crawl in Search.
2424

2525
</Step>
2626
<Step>
@@ -47,7 +47,7 @@ Click **Add source**. Gmail appears in the **Sources** list. Each person, includ
4747
2. Complete the connection in the tab that opens. Choose the Google account whose verified email matches your Sim email, and grant the requested permissions.
4848
3. Return to Integrations. The source shows its indexing status and the number of documents you can search.
4949

50-
Teammates follow these same steps after joining the organization. They do not configure the source again. If Gmail has not been added yet, ask an organization admin to add it.
50+
Teammates follow these same steps after joining the organization. Once an admin approves Gmail, the first connection can create its source with default filters. Admins can configure shared filters beforehand.
5151

5252
## Source options
5353

@@ -76,7 +76,7 @@ Search schedules syncs hourly. The first sync and large mailboxes can take longe
7676
| --- | --- |
7777
| A different email is requested | Use the Google account matching your verified Sim email. A separate personal account or alias does not satisfy the match. |
7878
| No searchable documents | Check the source's labels, date range, category exclusions, and search filter. Allow the first sync to finish. |
79-
| Finish connecting in the other tab | Complete the Google flow. If the tab was blocked or closed, allow pop-ups and click **Open again**. |
79+
| Finish connecting in the other tab | Complete the Google flow, or use **Open again** while authorization is pending. If the popup was blocked or closed, allow popups and select **Connect account** again. |
8080
| Reconnect | Click **Reconnect** and authorize the same account again. |
8181
| Unavailable or needs admin attention | Ask your Sim admin to check source status and the deployment's Google OAuth configuration. |
8282

apps/docs/content/docs/search/google-calendar.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import { Image } from '@/components/ui/image'
99

1010
Search meetings and event details available to your Google account. An organization admin enables the source; every teammate connects their own account. Google controls which calendar and event details each person can read.
1111

12-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
12+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1313

1414
## Set up the source
1515

@@ -20,7 +20,7 @@ These steps require a Sim organization admin.
2020

2121
### Add Google Calendar
2222

23-
Open **IntegrationsAdd source → Google Calendar**. Search uses **Member accounts**; an admin or service account cannot connect on behalf of everyone.
23+
Open **SettingsIntegrations → Providers**, approve **Google Calendar**, then select **Set up**. Search uses **Member accounts**; an admin or service account cannot connect on behalf of everyone.
2424

2525
</Step>
2626
<Step>

apps/docs/content/docs/search/google-drive.mdx

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@ import { Image } from '@/components/ui/image'
99

1010
Search Google Docs, Sheets, Slides, and supported files in Drive. A Sim organization admin chooses the folders and connection method once.
1111

12-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
12+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1313

1414
## Choose your setup
1515

@@ -29,7 +29,7 @@ These steps use your organization's **Integrations** page. For workspace Search,
2929

3030
### Add Google Drive
3131

32-
Open **IntegrationsAdd source → Google Drive** and choose **Member accounts**.
32+
Open **SettingsIntegrations → Providers**, approve **Google Drive**, then select **Set up** and choose **Member accounts**.
3333

3434
</Step>
3535
<Step>

apps/docs/content/docs/search/index.mdx

Lines changed: 8 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,9 @@ Search brings your connected sources into one place. An organization admin adds
1616

1717
### Choose a source
1818

19-
As an organization admin, open **Integrations → Add source** and select **Set up** beside a source. Use its **Setup guide** for the provider's prerequisites.
19+
As an organization admin, open **Settings → Integrations → Providers**. Approve the provider for Sim Search, then select **Set up** beside it. Use its **Setup guide** for the provider's prerequisites.
20+
21+
Approval lets members connect; it does not connect an account or start indexing. Slack also requires an admin to configure the organization's Slack app first.
2022

2123
</Step>
2224
<Step>
@@ -32,7 +34,7 @@ Select **Connect & Sync** for an administrator connection, or **Add source** for
3234

3335
### Connect and search
3436

35-
In **Integrations**, select **Connect account** if prompted—even if you created the source. Complete authorization in the new tab, then return to the source list. Open **Home → Search** to find documents or use **Assistant** to ask questions about them. Documents become available as background indexing progresses.
37+
In **Integrations**, select **Connect account** if prompted—even if you created the source. Complete authorization in the new tab, then return to the source list. Open **Search** in the organization sidebar to find documents, or **Home** to ask the assistant about them. Documents become available as background indexing progresses.
3638

3739
</Step>
3840
</Steps>
@@ -43,12 +45,13 @@ Source availability depends on the deployment and organization policy. An unavai
4345

4446
## Choose the right connection method
4547

46-
Most sources have one method. Google Drive and Confluence also offer an administrator connection when enabled for the organization.
48+
Most sources use member accounts. Google Drive and Confluence also support a central administrator connection; GitLab requires an administrator token for a self-managed instance.
4749

4850
| Method | What the admin does | What teammates do |
4951
| --- | --- | --- |
5052
| **Member accounts** | Sets the source's filters once. | Connect their own accounts. Sim lists documents using each member's access. |
5153
| **Service account** (Drive) / **Admin or service account** (Confluence) | Connects an account that can read the content and the source's permissions or directory. | Join the organization with a matching verified identity. Confluence also requires each person to connect their account. |
54+
| **Administrator token** (GitLab) | Connects a self-managed instance administrator token and selects projects to index. | Join the organization with a verified Sim email matching GitLab. No personal connection is needed. |
5255

5356
Some member sources offer **Sync documents with**. **Connected members** uses members' accounts for both content and access checks. Selecting a dedicated account uses it to fetch content; members still connect to establish which documents they may search. **Browse with** only helps an admin pick source options—it does not enroll that account for Search.
5457

@@ -73,11 +76,11 @@ Some member sources offer **Sync documents with**. **Connected members** uses me
7376

7477
Invite people through the organization's **Settings → Members**, or use your organization's [SSO provisioning](/platform/enterprise/sso). Share the organization's **Home** or **Integrations** URL. People need their own Sim account and organization membership; they do not need access to a workspace. Connecting an external account alone does not grant organization membership.
7578

76-
Organization admins manage source configuration and sync status through the source's **Manage** action. Other members connect or reconnect their own accounts. See [Connect your account](/search/connect-your-account) for the teammate walkthrough.
79+
Organization admins manage source configuration and sync status through **Manage** under **Settings → Integrations → Providers**. Other members connect or reconnect their own accounts. See [Connect your account](/search/connect-your-account) for the teammate walkthrough.
7780

7881
## Search, Assistant, and MCP
7982

80-
**Home → Search** finds documents directly. **Assistant** can search and read the same sources to answer questions with citations. Conversations are private to their author, including when another organization member is an admin.
83+
**Search** in the organization sidebar finds documents directly. The assistant on **Home** can search and read the same sources to answer questions with citations. Conversations are private to their author, including when another organization member is an admin.
8184

8285
To search from an MCP-compatible app, open **Settings → Search MCP**. Generate a personal Sim API key there, or use an existing personal key with the displayed connection details. MCP applies your current organization membership and document access.
8386

apps/docs/content/docs/search/jira.mdx

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,11 +11,11 @@ Search issue titles, descriptions, and metadata from selected Jira Cloud project
1111

1212
This Search connector uses **Member accounts**. It does not offer a central admin crawl. Comments, attachment contents, dashboards, and saved filters are not indexed.
1313

14-
These steps use your organization's **Integrations** page. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
14+
Admin setup uses your organization's **Settings → Integrations** page. Teammates connect from **Integrations** in the main sidebar. For workspace Search, use **Search → Add source** instead; **Create & Invite** is the workspace equivalent of **Add source**.
1515

1616
## Before you start
1717

18-
- You must be a **Sim organization admin** to add the source. Teammates can connect after it exists.
18+
- A **Sim organization admin** must approve Jira. An admin can configure the source beforehand, or the first member connection can supply the required site and project settings.
1919
- Use an Atlassian Cloud site such as `your-team.atlassian.net`. Jira Server and Data Center are not supported by this connector.
2020
- Each person needs a verified Sim email matching the email on their active Atlassian account, plus access to the selected Jira site and projects. Jira's **Browse Projects** and issue security permissions still determine which issues they can search.
2121

@@ -32,7 +32,7 @@ Sim uses its existing Jira OAuth integration. Search uses `read:jira-work` to re
3232

3333
### Choose Jira
3434

35-
Open **Integrations** in your organization, click **Add source**, and choose **Jira**. Click **Set up** or **Continue setup** if prompted. The connection method is **Member accounts**.
35+
Open **Settings → Integrations → Providers**, approve **Jira**, then select **Set up**. The connection method is **Member accounts**.
3636

3737
</Step>
3838
<Step>
@@ -94,7 +94,7 @@ Sim checks Jira separately using each connected person's account. Issue content
9494

9595
| What you see | What to do |
9696
| --- | --- |
97-
| No **Add source** button | Ask a Sim organization admin to add Jira. |
97+
| No provider setup controls | Ask a Sim organization admin to approve and set up Jira. |
9898
| Projects are empty or disabled | Enter the domain and connect a browsing account, or switch to manual project keys. Check that the account can browse those projects. |
9999
| Connected, but no issues | Confirm the authorized site matches the configured domain. Check project access, issue security, and the JQL filter. An admin's Jira access does not grant access to other members. |
100100
| Email mismatch | Sign in to Atlassian with the email shown by Sim's connection flow. |

0 commit comments

Comments
 (0)