Flipper
Governance & access

Sensitivity & classification

Every fact carries a sensitivity. Classification needs no company-specific training: a source floor plus a narrow rubric plus human approval does the work.

The three levels

  • Public — every member of the workspace can read it.

  • Confidential — owners and admins only. Compensation, fundraising, legal.

  • Personal — visible only to the person whose capture produced it.

How a fact gets its level

The source sets a floor (a private capture can never come out public), an LLM rubric classifies the content within that floor, and anything that would widen access waits for a human. set_sensitivity lets an agent or a person move a fact deliberately, and the change is audited.

The workspace settings that move these lines

Four switches in Settings govern everyone, so only an owner or admin can change them, and every change is written to the audit log.

SettingWhat turning it off does
Restrict sensitive facts to adminsConfidential facts become readable by every member, subject to groups. On by default.
Private capturesSession captures stop landing private to their author.
Require approvalAgents may act on playbooks nobody has approved.
Connector failure alertsAdmins stop being told when a source stops syncing.