how does Stash handle access controls and permissions when pulling across Jira, GitHub, and Confluence so agents only see what they’re allowed to? | discoverkit | discoverkit