HomeDocumentationPrivacy & Access Control

    Privacy & Access Control

    This guide explains how visibility, sharing, and privacy work across your account. It covers the rules that decide who can see which conversations, how settings cascade across your organization, and how to configure the most common scenarios.

    The one thing to remember: when in doubt, the system protects privacy. If two settings ever disagree, the more private rule always wins.


    1. Core concepts

    The hierarchy

    Settings are organized in four levels, from broadest to most specific:

    Account → Department → Team → User

    A setting placed higher up (e.g. Account) acts as the default for everything beneath it. A setting placed lower down (e.g. on a specific Team or User) can override the default for just that scope.

    The two golden rules

    Everything in this feature follows two rules:

    1. Lower beats higher (the waterfall). The more specific a rule is, the higher its priority. A rule set on a User overrides the Team, which overrides the Department, which overrides the Account default. Overrides always reference the level directly above — so settings can "zigzag" down the chain.

    Examples:

    • Simple inheritance. Account sets Department visibility = ON and the Sales department adds no rule of its own. Sales inherits the account default, so sharing is ON for Sales.
    • Department overrides account. Account = Department manager access OFF. The Customer Success department sets it ON. CS managers can now see all CS conversations — the department rule wins because it's more specific.
    • Team overrides department. Customer Success has sharing ON, but the Enterprise CS team sets sharing OFF. Members of Enterprise CS can no longer see each other's meetings, even though the rest of the department can.
    • User overrides everything above. The CEO sits in Management where members see each other's meetings, but a user-level rule sets the CEO to private by default. The CEO's meetings stay hidden no matter what Management or the account allow.
    • The zigzag (each level flips the one above it). Account → sharing OFF → Department → sharing ON → Team → sharing OFF. The system reads only the nearest rule above each scope: the department turned it on (override of the account), then the team turned it back off (override of the department). The team's members end up with sharing OFF.
    1. Privacy wins ties. If two rules genuinely conflict, the rule that restricts access is the one that applies. The system never errs toward exposing a conversation.

    If a level has no override, the system simply inherits the setting from the level above it.

    Visual: how the waterfall resolves

    The default cascades downward, and any level can override the level directly above it. The lowest level that has a rule wins. (Insert the "Settings Waterfall" diagram here — Account → Department → Team → User, priority USER > TEAM > DEPARTMENT > ACCOUNT, privacy wins on conflict.)

    Worked "zigzag" for a single Sharing setting — each level flips the one above it, and the system only ever reads the nearest rule above a given scope:

    LevelRule set hereEffective result
    ACCOUNTOFFOFF (the default)
    DEPARTMENTON — overrides AccountON
    TEAMOFF — overrides DepartmentOFF
    USER(none) — inherits TeamOFF

    Account defaults

    These settings are the account-wide baseline. Every Department and Team automatically inherits them, so they apply to all conversations across the organization by default. A setting here stays in effect for a given Department, Team, or User until a more specific override changes it for that scope (see "Department & team rules" below).


    2. Automatic Internal Participant Sharing

    When Automatic Internal Participant Sharing is ON, every internal participant from your organization automatically gets the meeting shared with them. They don't own the meeting, but they can find it under Shared with me.

    This works as a simple, automatic share: being an internal participant is treated exactly as if the owner had manually shared the meeting with each of them. There's no special, separate logic — it's just a share, so access stays predictable.

    • This behavior is governed by a single setting: do internal participants get access to the meeting? (yes/no).
    • When yes, the meeting is auto-shared with every identified internal participant, and it appears under their Shared with me.

    Note: A participant counts as someone who was invited and responded yes or maybe to the meeting. Someone who responded no is not counted as a participant and won't have the meeting shared with them.


    3. Department or Team Visibility

    Department visibility (and the equivalent Team visibility) lets people inside the same scope see each other's conversations.

    • When ON, users in the selected department or team can see other user's recordings/insights in that department.
    • Set at: account, department, or team.

    Including or excluding managers

    Sharing comes with a separate control for managers' own recordings:

    • By default, managers' recordings are NOT included in department/team visibility. The reasoning: regular team members usually shouldn't see their manager's conversations.
    • Turn on Include managers if you do want managers' recordings visible to the rest of the scope.

    So "department visibility ON" means everyone sees each other's meetings — but a manager's own meetings stay hidden unless you explicitly include them.


    4. Role permissions

    Role permissions control what managers are allowed to see. They can be set as an account default and overridden per Department or Team.

    PermissionWhat it does
    Department manager accessWhen ON, designated department managers can see all conversations in that department and the teams belonging to that department. When OFF, the role grants no extra visibility.
    Team manager accessWhen ON, team managers can see all conversations within the team they manage.

    A role only grants visibility if the corresponding permission is enabled. Assigning someone as "department manager" does nothing on its own until the access toggle is turned on for that scope.

    Example of an override: Account default = Department manager access OFF. On the B2B Customer Success department you turn it ON. Because the department setting contradicts the account default, it is flagged as an override (see §6).


    5. Private meetings

    Private meetings are meetings that cannot be viewed or seen by anyone other than the owner. A meeting marked as private overrides any sharing or visibility rules that are set in the account.

    Base Setting

    • Allow private conversations — controls whether users in this scope may mark a conversation as private (visible to no one but the owner). If OFF, users cannot mark meetings as private.
      • Set at: account, department, or team.

    Sources

    Requires Allow private conversations to be ON.

    Source classification controls which source types follow the shared ruleset and which are private by default:

    • Uses shared ruleset — these sources follow the shared account / department / team rules that apply to them (e.g. Meetings, Live recordings, Calls, Email).
    • Private by default — break a source out of the shared ruleset so that source is always private by default (e.g. exclude Email so all emails are private while the other sources keep sharing the same rules).
      • Set at: account, department, or team.

    Auto-private rules

    Auto-private rules automatically mark digital meetings as private when they match a rule. There are two types:

    • Domain — enter a domain (e.g. legal-counsel.com). If any participant's email is on that domain, the meeting is automatically marked private.
    • Title keyword — matched against the meeting title, either:
      • Exact match — the title equals the keyword (e.g. board, salary, offer).
      • Phrase match — the title contains the phrase (e.g. acquisition talks, performance review, severance discussion).
      • Set at: account (applies to everyone). Users can also add their own personal rules on top.

    Department & team rules

    Override the account defaults for a specific department, team, or user. Inherited values stay in sync automatically.


    6. Overrides and how they're shown

    Whenever a setting at a lower level contradicts the level above it, it is marked as an override with a clear badge/warning in the interface.

    • The badge exists so administrators don't silently break inherited behavior. Without a visible indicator, a user might change one level and not realize a higher level still appears to say something different.
    • The override always reflects a conflict with the level immediately above, not necessarily the account.
    • Where helpful, the override badge links you to the setting it is overriding so you can see the full picture.

    Worked example. Account: department manager access OFF. Department: department manager access ON. The department setting wins (lower beats higher), and the interface shows it as an override of the account default.


    7. Sharing with other departments, teams, or users

    Beyond sharing within a scope, you can share a department's or team's conversations outward to other parts of the organization. This works like a standard manual share; you simply pick who to share with.

    You can share with:

    • another department,
    • another team, or
    • a specific user.

    All active shares are listed (e.g. "shared with Finance", "shared with Anders", "shared with Support team") so you can review and manage them.

    Typical use cases

    • A Customer Success team needs to review Sales calls.
    • Support/Engineering staff who help with support cases need access to CS conversations.

    Tip for clarity: think of the screen in two sections. The top section (role permissions, sharing, privacy) configures this department/team. The bottom section configures outward sharing to other departments/teams/users.


    8. User-level overrides

    You can fine-tune visibility for a single user, overriding whatever their department or team says.

    • Hide a specific user's recordings from a department or team, even while broader sharing is on.
    • Make a user's meetings private by default, regardless of their team's settings.

    Worked example — protecting an executive. Your management Team has Team visibility ON so the members can see each other's meetings, but the CEO's meetings should be visible to no one. Set a user-level override that makes the CEO's meetings private by default. Everyone else's sharing stays unchanged.

    Worked example — a manager with sensitive meetings. A department has Department visibility ON and Include managers ON, so the managers(e.g. Amelia and Pierre) can view the departments recordings and the team can view theirs. But Amelia also runs sensitive 1:1s. Keep her access on, but turn on Private by default at the user level. She can see the deparments meetings; but her meetings stay private.


    9. Users in multiple departments

    A user can belong to more than one department, and those departments may have different rules. To keep behavior safe and fast, privacy is evaluated at the user level, not per conversation:

    If a user belongs to multiple departments and any of those departments restricts sharing, that user's conversations are hidden — regardless of conversation type or outcome.

    Why it works this way. Conversation-type classification is AI-assisted and not perfectly predictable. Imagine a manager whose Management meetings are private but who is also in Sales where meetings are shared. If a sensitive HR/salary discussion were ever misclassified as a sales call, it could leak. Because leaked sensitive meetings can create serious legal exposure, the system applies the most restrictive department's rule to the whole user. Privacy wins.

    This is a deliberate, necessary limitation rather than a bug — and in most cases you don't need a user in multiple departments at all. To give someone cross-team access, edit the department's sharing/privacy rules (§7) instead.


    Using conversations & reference

    How conversations are displayed, plus quick recipes and answers to common questions.


    10. Default conversation view

    When you open your conversations, the default view is limited to meetings you own ("owner = me"). You can always widen the filters to see everything you have access to.

    Benefits:

    • A cleaner starting point instead of a flood of every accessible meeting.
    • Better performance, since the default query is scoped to you.

    After migration, if you don't have access to other departments, you won't even see them in the filters — there's simply nothing extra to filter on.


    11. Quick configuration recipes

    GoalHow
    Let everyone in a department see each other's meetingsDepartment visibility ON
    ...but keep managers' own meetings hiddenLeave Include managers OFF (default)
    Give the CS team access to Sales recordingsOn the Sales department, share with the CS team (§7)
    Hide the CEO's meetings from everyoneUser-level override: private by default on the CEO (§8)
    Let a manager view the team but keep her own meetings privateManager access ON + turn off sharing of her recordings at user level (§8)
    Forbid private meetings in a departmentAllow private conversations OFF for that department (§5)
    Make every new meeting private until sharedPrivate by default ON (§5)

    12. Frequently Asked Questions

    Who can see my meetings by default? By default, you see the meetings you own, and your meetings are only visible to others if a sharing rule grants it. The system starts from a private position and opens up access only where you configure it.

    What happens if two settings disagree? Two rules decide it: (1) the more specific level wins (User > Team > Department > Account), and (2) if rules truly conflict, the rule that restricts access wins. Privacy always takes priority.

    What is an "override"? An override is any setting on a lower level that contradicts the level above it. It's clearly badged in the interface so you know inherited behavior has been changed for that scope, and it points to the setting it's overriding.

    If I attended a meeting someone else owns, will I see it? If Participant sharing is enabled, yes. Participating is treated like an automatic share — the meeting shows up under Shared with me, provided participant access is enabled and your email matches your user in the account.

    Can a team see their manager's meetings? Not by default. When department/team visibility is on, managers' own recordings are excluded unless you explicitly turn on Include managers.

    Can I hide one specific person's meetings (e.g. the CEO) while everyone else shares? Yes. Use a user-level override to make that person's meetings private by default. It doesn't affect anyone else's sharing.

    I'm in two departments with different rules — what applies to me? The most restrictive rule wins. If any department you belong to restricts sharing, your conversations are hidden everywhere, regardless of the meeting type. This protects sensitive meetings from accidentally leaking through a misclassification.

    Does the AI's conversation-type classification decide who sees what? No. Privacy is enforced at the user level, not per conversation type. This is intentional — it's both safer (a misclassified sensitive meeting can't leak) and faster.

    How do I give one team access to another team's recordings? Open the source department/team and use Share with to grant access to the other department, team, or specific user — similar to sharing a file in Google Drive.

    Can I share my own meetings with a specific colleague? Yes. As a user you can create an override that shares all your meetings with a specific person.

    Can I mark a single meeting as private? Yes, as long as Allow private conversations is enabled for your scope. A private meeting is visible to no one but you. You can also set Private by default so every new meeting starts private.

    Will turning on department visibility expose sensitive 1:1s or HR conversations? Not if they're protected. Managers' recordings are excluded by default, you can make specific users or meetings private, and any restrictive rule overrides broader sharing. The system always defaults to the more private outcome.

    What's the difference between "department visibility" and "sharing with other departments"?Department visibility controls visibility within the same department. Sharing with other departments sends access outward to a different department, team, or user.

    Why am I only seeing my own meetings when I open conversations? That's the default view ("owner = me") — it keeps things focused and fast. Widen the filters anytime to see everything you have access to.