A copilot is only as safe as the corpus behind it. We classify every content source before a single document is indexed, with your records and legal teams in the room. The default posture is restrictive. Adding a source is a decision; leaving one out is the starting point.
| Content type | Indexed by default | Why |
|---|---|---|
| SOPs and runbooks | Yes | The canonical how-we-do-things content. Highest-value, lowest-risk material in the business. |
| Product and service documentation | Yes | Customer-facing answers, internal product specs, and the history of why features work the way they do. |
| Historical correspondence (with access controls) | Yes, scoped by permission | The "why we decided that" trail. Indexed behind the same access controls as the source inbox or channel. |
| Policies | Yes | Current-version policies only. Superseded versions are flagged so the copilot never cites a retired policy as current. |
| Training material and onboarding content | Yes | The content a new starter would otherwise ask a senior colleague to explain. |
| Past project reports | Yes | The richest source of precedent in professional services firms. Scoped by client confidentiality rules. |
| Personal employee files | No | HR content stays in HR systems. Out of scope regardless of who asks. |
| Anything legally privileged | No, without explicit review | Privileged material is reviewed document by document before any indexing decision. Default is exclusion. |
| Client data containing PII | No | PII is not indexed into the copilot. Where a use case requires it, we design a separate, tightly scoped pattern with your privacy team. |
| Anything marked confidential without classification review | No | If it hasn't been classified, it isn't indexed. No exceptions, no "we'll sort it later". |
Cookie preferences
We use essential cookies to run the site. With your permission, we also use analytics cookies to understand what content helps visitors make better data and AI decisions.