Skip to content

Connect file server / NAS (SMB)

A file server in your company network can be connected as a data source: 9brains indexes the files of a share, and everyone in the workspace can search that content in the chat. This works for Windows file servers, NAS systems such as Synology or QNAP, and any other SMB share.

On top of that, the AI can open the share directly: browse folders, find new or changed files and pull individual files into the chat. By default this is read-only. Only once you switch on “Allow the AI to change files” does the AI also save, rename, move or delete files on the file server when you ask it to.

  • Your workspace needs a Business or Max license
  • You are an administrator in the workspace
  • A configured on-premises connector with the file server set up as a service (protocol SMB, usually port 445)
  • A service account (username and password) with read access to the share. If the AI is to change files, it also needs write access
  • The name of the share to be indexed (e.g. Sales)

Is the share reachable directly from the internet? Then it works without the connector, for example with Azure Files or a Hetzner Storage Box. In the connection dialog choose “Server is directly reachable (without connector)” and enter the address yourself. The connector is the normal case, because a file server almost always sits inside the internal network.

Step 1: Create a service in the on-premises connector

Section titled “Step 1: Create a service in the on-premises connector”
  1. Go to Settings, On-premises connector
  2. In the appropriate tunnel, create a service pointing at the file server: internal IP or hostname, port 445, protocol SMB. If the connector runs directly on the file server or NAS, the port is enough
  3. Use “Test connection” to confirm the service is reachable. For a new connector this is also the starting signal: only after it does the connector check its services regularly on its own, and until then a service counts as “not checked yet”

Details are on the on-premises connector page.

  1. Go to Settings, Data sources
  2. Click “+ Data source” and then “Connect file server / NAS (SMB)”
  3. Fill in the fields:
Field Description
Name Display name of the data source (e.g. “Sales department drive”)
File server The service from the on-premises connector. Server and port come from there, no typing needed
Share Name of the SMB share to be indexed (e.g. Sales)
Domain Optional, the Windows domain of the service account
Username The service account with read access to the share
Password The password of the service account, stored encrypted
  1. Click “Connect file server”. Initial indexing starts automatically, provided “Make contents searchable” is switched on

Step 3: Set access, folders and search (optional)

Section titled “Step 3: Set access, folders and search (optional)”

Before saving, you decide what the AI may do on the share and what 9brains reads in.

In the “Access” section:

  • Enable permission filtering: Every user only sees what they may read according to the Windows file permissions, see Permissions
  • Allow the AI to change files: Off by default. When switched on, the AI may save files to the file server, create folders, rename, move and delete, see Direct access. The service account needs write access to the share for this

Under “Select folders (optional)”, click “Test connection & select folders”. 9brains connects to the share and shows the folder structure. If you select nothing, the whole share applies. The selection covers both search and direct access: whatever is not selected, the AI can neither find nor open nor change.

A selected folder brings its subfolders along. Untick a subfolder to exclude it, at any level. The parent folder then shows a dash instead of a tick (partially selected), and the exclusion appears below the tree as “without …”. Use its cross or tick the folder again to take the exclusion back. An excluded folder counts as not selected: files already read in from it disappear from search with the next sync, and direct access does not open it.

In the “Search” section:

  • Make contents searchable: On by default. 9brains reads in the files so the AI finds their content through search. If you switch it off, 9brains reads in nothing: no synchronization, no storage used, and the data source does not show up in search. The AI then reaches the files through direct access only. This suits large archives where folders and incoming files matter rather than content, such as an incoming receipts folder with tens of thousands of files
  • File types: Documents, spreadsheets, presentations, web pages and images can each be switched on or off. Images are captured through AI image descriptions, the most expensive part of indexing
  • Maximum file size: The default is 300 MB, larger files are skipped
  • Only files modified after: Useful for old drives that have grown over the years, when only recent content matters

File types, file size and modification date only affect reading in. When “Make contents searchable” is off, they are hidden.

You can change the folder selection and the search settings later at any time via “Edit” on the Filters card in the detail view, and the “Allow the AI to change files” tick box via “Edit” on the Connection card. A filter change triggers a new sync; files that no longer match the filters are removed from the index. If you switch off “Make contents searchable” for an existing data source, 9brains deletes the existing index after asking you to confirm. If you switch it back on, 9brains reads everything in again.

  • All files in the share, or in the selected folders
  • Subfolders are searched recursively
  • Only the file types 9brains can process and that you allowed in the filters
  • Nothing at all if “Make contents searchable” is switched off. Direct access still works

Permissions: everyone sees only their own files

Section titled “Permissions: everyone sees only their own files”

On a department drive, rarely does everyone have access to everything. So that the AI respects this, you can switch on permission filtering in the connection dialog. Then a user only gets results from files they are also entitled to on the file server according to Active Directory. The Windows file permissions carry over one to one.

Without permission filtering every user in the workspace sees all indexed files. That is intentional and the simplest option for a drive that is open to everyone anyway.

Permission filtering applies to direct access in exactly the same way. When it is on, every user only sees what they may read according to the Windows file permissions when listing, finding and opening files, following the same rule as search. When changing something, 9brains additionally checks the user’s matching permission, that is changing a file, creating files or folders inside a folder, or deleting, and refuses if it is missing. When it is off, everyone with access to the data source sees the whole share, or the selected folders.

To resolve permissions, 9brains needs a look into your directory. There are two ways:

Connection When it fits What you need
Microsoft Entra ID (hybrid) Your local AD is synchronized to Microsoft 365 via Entra Connect The Microsoft tenant ID and the consent of a Microsoft administrator
On-premises AD (LDAP) A purely local Active Directory without Microsoft 365 synchronization A second connector service for the LDAP server, the search base and a service account

Important: Users are found in the directory through the “mail” attribute. It has to match the address the person signs in to 9brains with. If those do not line up, 9brains cannot find the person and their search stays empty.

LDAP tip: Use LDAPS where possible (encrypted, port 636). The port of the connector service and the setting in the dialog have to match, otherwise the directory sign-in hangs instead of failing.

What about agents? An agent, too, always searches and opens files with one particular human’s permissions: in chat with those of the person operating it, on a scheduled run with those of the Microsoft account on its list or of its owner. Details under Agents.

Once the data source exists, it offers a “Check access” function. It walks through what works and what does not, step by step:

  1. Connection to the file server: Is the share reachable, are the credentials accepted?
  2. Directory service: Does Active Directory or Entra ID respond?
  3. Your user account: Was your person found in the directory, which permission groups came out of it?
  4. Actual document access: How many of the sampled documents are you really allowed to read?

This is the first tool to reach for when a user reports they find “nothing” from the drive. Usually it is either an account that cannot be found in the directory, or a permission that genuinely is missing on the file server.

File servers are always workspace data sources:

  • Only administrators can create, edit and delete them
  • The data source appears under “Workspace data sources” on the data sources page
  • Which files an individual user finds in the chat depends on permission filtering (see above)

After initial indexing, syncing continues automatically:

  • New files are indexed
  • Changed files are re-indexed, detected via modification date and file size
  • Deleted files disappear from the index

Unlike OneDrive and SharePoint, a file server does not report changes on its own. 9brains therefore compares the share against the index every hour. A file you just saved is not searchable instantly, but usually within an hour. If you do not want to wait, open the data source and start synchronization manually.

If “Make contents searchable” is switched off, there is no synchronization at all. Direct access does not need it, it always sees the current state on the file server.

After indexing, the content is available in the chat:

“What is in the quote for Müller GmbH?”

“Summarize the minutes of the last sales meetings.”

“Which price list currently applies to key accounts?”

Answers include source references with the network path of the file, for example \\fileserver\Sales\Quotes\Mueller.docx. That way anyone can find the original on the drive again.

Besides search, the AI can also open any file server data source directly, in the chat as well as in agents. This needs no setup and also works when “Make contents searchable” is off. It is not a new permission: anyone who can use the data source could already reach the same content through search.

The AI can always read:

  • List folders, with name, size, creation and modification date of every file
  • Find new and changed files across the whole folder tree since a given date, optionally only with a certain file name pattern (all PDFs, for example) and leaving out individual folders such as “internal”
  • Pull a file into the chat to read it in full or edit it, up to 50 MB

With the “Allow the AI to change files” tick box, it can also:

  • Save files: upload a file from the chat workspace to the file server, up to 50 MB. The AI only overwrites an existing file when you explicitly ask it to
  • Create folders
  • Rename and move files and folders, never on top of an existing file
  • Delete files and empty folders. The AI does not delete a folder together with its contents

In the chat, the AI is instructed to name the exact paths and wait for your confirmation before it deletes, moves or overwrites anything. An agent running on a schedule has nobody to ask and acts on its instructions, so only switch the option on where that is intended.

The folder selection applies here too: whatever is not selected or is excluded, the AI can neither open nor change. It cannot delete, rename or move the selected folders themselves, only what is inside them. Direct access hides NAS helper folders such as @eaDir or #recycle, recycle bins, and hidden and system files such as Thumbs.db or desktop.ini, and does not let them be reached through a named path either.

Links on the server: Direct access leaves out Windows links (junctions). Symlinks on a NAS, however, are handed out by the server like ordinary folders, which no application can tell apart. If such a symlink in a selected folder points somewhere else, the AI reaches its target too. The folder selection therefore narrows things down, it does not lock anything. If a folder must be out of reach for certain, remove the service account’s permissions there.

“Which clients have filed new receipts since yesterday?”

“What is in the folder Sales/Quotes?”

“Save the report in the folder Archive/2026.” (only with “Allow the AI to change files”)

What counts as “new”? The creation date on the file server decides, that is when the file was placed there. A file copied in keeps its old modification date and would otherwise not show up as new.

This lets an agent, for example, check every morning which clients have filed new receipts in the incoming folder, without 9brains having to read in tens of thousands of receipts first.

  • By default the AI may only read. It can change files only once an administrator switches on “Allow the AI to change files”. In the chat it is instructed to ask before deleting, moving or overwriting
  • Every change is logged: who, when, which path. On the file server itself the service account appears as the author, because 9brains always writes with it
  • The connection runs through the encrypted tunnel of the on-premises connector, your file server stays unreachable from the internet
  • The credentials of the service account are stored encrypted
  • With permission filtering switched on, the Windows file permissions stay effective in search and in direct access as well
  • Other workspaces have no access to your tunnels, shares or indexed content

“The file server is unreachable or rejects the credentials”

Section titled ““The file server is unreachable or rejects the credentials””
  • Check the connector service: Is the SMB service reported as reachable in the on-premises connector?
  • Share name: This means the name of the share, not the full network path
  • Service account: Check username including domain, plus password and read access to the share
  • The file server’s answer: It appears below the message; use “Copy details” to paste it, including the error ID, into a support request

Almost always permission filtering. Have that person run “Check access”. If the account is not found in the directory, the sign-in address does not match the “mail” attribute in Active Directory. If the check reaches the last step and reports that none of the documents are accessible, the permissions really are missing on the file server.

After several failed directory sign-ins, 9brains pauses so the service account does not get locked out in Active Directory. Once the credentials are corrected, checking resumes immediately.

The connection works, but no subfolders appear under “Select folders”. The service account may then open the share but not the folders inside it. Many NAS systems, Synology for example, hide folders without permission entirely instead of reporting an error.

Give the service account read access to the subfolders. The simplest way is to add it to the group through which your staff access those folders. Resetting the permissions of all subfolders is usually not a good idea, because any permissions that differ on individual folders get lost.

  • Check the filters: Deselected file types, the size limit or a modification date deliberately leave files out
  • Check the folder selection: Is the data source narrowed down to individual folders?
  • Storage quota: If the workspace quota is exhausted, the rest waits for free space. Usage is shown at the top of the data sources page
  • Check the tick box: Is “Allow the AI to change files” switched on for the data source?
  • Service account: Does it have write access to the share and the folder in question? Read access is only enough for viewing and opening
  • User permissions: With permission filtering, the person in the chat also needs the matching permission on the file server
  • Folder selection: Is the path outside the selected folders, or is a selected folder itself supposed to be renamed, moved or deleted?