Sistava

Control Information Boundaries

Your employee can use relevant organisation knowledge to do its work without treating every conversation as information everyone may repeat.

TL;DR

Employees know who is in the workspace, their access role, and the source of useful context. They protect private, confidential, and role-restricted information. If someone asks for a restricted answer, the employee says it cannot share it, rather than pretending it does not know. With the requester's agreement, it can ask the right workspace member to approve one specific answer.

Who Is Asking

The employee evaluates the source of each request before it uses workspace context.

Request source What the employee can use
Workspace member The member's current workspace role and the information they are allowed to access.
Verified API or connected channel The authenticated workspace identity attached to that connection.
Unauthenticated contact Mailbox, Slack, Telegram, and live meeting speech use an isolated public conversation. It has no workspace membership, private chat history, trained knowledge, connected tools, account details, internal memory, or action authority.

The employee Profile controls this boundary. Private rejects unauthenticated contact. Public, zero workspace access permits an isolated public reply with no workspace context or tools. This policy applies to Mailbox, Slack, Telegram, and live meeting speech. Verified API, webhook, MCP, A2A, and Email Webhook connections use their authenticated workspace identity instead.

An employee mailbox does not authenticate a sender by their email address today. Even if a workspace member emails an employee from an address verified on their Profile, that direct mailbox conversation is an external conversation. Use web chat or an authenticated programmatic connection for internal work. Manage Your Profile explains what profile email verification does and does not prove.

The Four Boundaries

Boundary Meaning
Organisation-shared Normal business context the employee can use across the workspace.
Role-restricted Work information limited by responsibility, such as finance or people operations.
Private Information from a direct conversation or about a particular person.
Confidential Highly sensitive business or people information.

Your workspace role (Owner, Admin, or Member) describes operational access. An optional job title helps the employee understand your work, but it does not automatically grant access to private information.

When Someone Asks For Restricted Information

  1. The employee explains that it cannot share the detail.
  2. It can offer to ask the right person for permission.
  3. It asks the requester for consent before contacting anyone.
  4. The decision-maker receives a notification showing the exact proposed disclosure.
  5. If approved, the employee shares only that scope. If rejected, it says it cannot share the information and does not reveal who was asked.

The decision-maker does not receive a link to the requester's private chat. The requester is not shown a map of who knows what.

Example

An owner tells an employee that hiring is frozen, before the announcement. A collaborator later asks whether the company is hiring. The employee should not repeat the private discussion. It can say that it cannot share that information and ask whether the collaborator wants it to request permission from the right person. If permission is granted for a specific answer, it shares only that answer.

Good to Know

Frequently Asked Questions

Q: Does being an Owner reveal every private conversation? A: No. An Owner is the highest operational authority in the workspace, but private and confidential information still needs an appropriate, bounded disclosure decision.

Q: Can I set my job title? A: Tell your employee your title in chat. It can save that as workspace context without changing your access role.

Q: Where do I approve a disclosure? A: In the notification panel. The notification shows the proposed scope and has Approve and Reject controls.