Sensitivity levels

Sensitivity is a second, independent layer of access control on top of folder permissions. A folder’s permissions decide who can browse into it; a file’s sensitivity level decides who — among people who can browse there — is actually allowed to open it.

LevelWho can see it
PublicAnyone in the company, including in cross-app search results and AI answers, without any special permission
InternalAny employee with baseline document access — the default for most day-to-day files
ConfidentialOnly users whose role grants the documents:confidential permission
RestrictedOnly users whose role grants the documents:restricted permission — the tightest level, intended for legal, executive, or highly sensitive HR files
  1. When uploading (or editing an existing file’s metadata), set Sensitivity in the file details panel. It defaults to Internal unless the folder or app has a different default configured.

  2. Files above your permission level simply don’t appear — in Browse, in search results, in AI Copilot answers, or in entity-attachment lists. This is a hide, not an “access denied” message, so sensitive filenames and even their existence stay private.

  3. A subfolder can be set to enforce a minimum sensitivity for anything uploaded into it (e.g. an HR/Compensation folder that forces every file to at least Confidential) — useful for making sure sensitive folders can’t accidentally receive a Public-level file.

  4. Changing a file’s sensitivity level takes effect immediately across every surface: Browse, search, AI answers, and entity-attachment panels.

⚠️

Sensitivity level is evaluated in addition to folder permissions and entity-level access — a user needs both the folder access and the sensitivity permission to open a file. If either is missing, the file is not visible.