Sensitivity levels
Sensitivity is a second, independent layer of access control on top of folder permissions. A folder’s permissions decide who can browse into it; a file’s sensitivity level decides who — among people who can browse there — is actually allowed to open it.
| Level | Who can see it |
|---|---|
| Public | Anyone in the company, including in cross-app search results and AI answers, without any special permission |
| Internal | Any employee with baseline document access — the default for most day-to-day files |
| Confidential | Only users whose role grants the documents:confidential permission |
| Restricted | Only users whose role grants the documents:restricted permission — the tightest level, intended for legal, executive, or highly sensitive HR files |
-
When uploading (or editing an existing file’s metadata), set Sensitivity in the file details panel. It defaults to Internal unless the folder or app has a different default configured.
-
Files above your permission level simply don’t appear — in Browse, in search results, in AI Copilot answers, or in entity-attachment lists. This is a hide, not an “access denied” message, so sensitive filenames and even their existence stay private.
-
A subfolder can be set to enforce a minimum sensitivity for anything uploaded into it (e.g. an
HR/Compensationfolder that forces every file to at least Confidential) — useful for making sure sensitive folders can’t accidentally receive a Public-level file. -
Changing a file’s sensitivity level takes effect immediately across every surface: Browse, search, AI answers, and entity-attachment panels.
Sensitivity level is evaluated in addition to folder permissions and entity-level access — a user needs both the folder access and the sensitivity permission to open a file. If either is missing, the file is not visible.