This chapter is for you, not your administrator#
Your device shows every folder the agent on your machine indexes, who chose each one, what has left the machine and in what form, and the controls you hold. It is gated on local_agent.use, the permission every member has, and deliberately not on any administrator permission. Putting your own transparency page behind an admin’s permission is the failure this page exists to correct.
The five readings at the top#
| Reading | What it counts |
|---|---|
| Folders indexed | How many locations the agent reads, and how many of those you chose yourself. |
| Files seen | How many files the agent has looked at, and how many it actually indexed. |
| Files blocked | Refused by policy: secrets, blocked patterns, unlisted types. |
| Sent to the workspace | Knowledge packs that left this device. Not files, packs. |
| Last scanned | When the agent last ran. A report over a day old says so. |
Above them sits the device itself: its name, its lifecycle state, its operating system and agent version, the deployment profile it is on, and when it was last heard from. A revoked device says so explicitly It no longer syncs anything, and the record below is kept so you can still see what it reported before that happened.
Folders, and who chose each one#
The folder list is filterable by who chose it, and this is the most important control on the page.
- You added it
- You approved this folder yourself. You can remove it yourself.
- Suggested · you agreed
- Your administrator suggested it and you said yes. You can withdraw that.
- Added by your admin
- Indexed by policy. You were not asked about it, and you cannot remove it yourself. You can ask for it to be excluded, or tell an administrator what is in it.
Managed folders are visible, always
A folder indexed without your consent is still shown to you, labelled as such, with a route to object. That is the design: an administrator can decide what is read, and cannot decide that you do not get to know.
What has left this device#
Every batch of knowledge this device sent to the workspace, and how much of the original document went with it. Nothing here is a copy of your files. The agent extracts on the machine and sends only what the sync mode allows.
Beside it, This device’s own log is what the agent recorded itself doing: scans, files it refused to read, secrets it detected, packs it sent. It never records file contents or paths.
The controls you hold#
Pause the device
Stops the agent working on this machine. The page states plainly when a device is paused, so it is never a silent state you forget you set.
Object to a folder
Find the folder in the list
Search or filter by who chose it.
Say it should not be read
Against that folder. You are asked what the problem is: a category and a note. You do not have to say what is in it.
It goes to an administrator
It lands in the Source requests lane of the review queue, where answering it needs a permission specifically about widening or narrowing what Evodira may read.
Watch for the answer
Under What you have raised at the foot of the page: every request and notice you have sent about folders on your devices, and what came back.
From the machine itself
evodira-local status # lifecycle, policy revision and age, identity
evodira-local sources # every approved folder and who chose it
evodira-local policy show # the rules in force, read from cache, no network
evodira-local packs list # what is prepared and waiting on youMy contributions#
My contributions is what you have sent in, and what became of each. It counts your captures and how many were published.
- A capture you approved on your device appears here once it has left the machine.
- Its state tracks the review queue: in review, verified, published, or rejected, with the rationale where one was written.
- Manage local agent takes you back to your device page.
What Evodira does not do on your machine#
Stated once, plainly, because it is the question people actually have.
- It does not scan browser history, screenshots, microphones or keystrokes.
- It does not index a folder nobody approved: either you, or an administrator on a deployment profile, and in the second case you are told.
- It does not open a file type the policy has not named, and it does not open blocked patterns like .env or private keys.
- It does not upload raw file content unless an administrator has explicitly enabled that on your deployment profile. It is blocked by default.
- On macOS, it does not read Documents, Desktop or Downloads until the system permission prompt has been answered.
You are done when
You can name every folder on your machine that Evodira reads and who chose each, you know how to pause it, and you know that objecting to a folder is a request that lands in a human queue with an answer that comes back to you.
Something here wrong, missing, or no longer true of the product? Write to hello@evodira.com. Documentation that has drifted from the console is a bug and we treat it as one.