Folders and sensitivity labels
Making, moving and colouring folders, and how sensitivity labels decide which AI models may read a document.
Making a folder
Press New folder above the folder tree. Give it a Name, choose where to Put it in (the top of the project, or inside another folder), and optionally say What it is for. Then press Create folder.
The folder's ⋯ tray
Each open folder has a banner showing its name, its label and its purpose. The ⋯ button in the banner opens a tray of everything you can do with the folder:
- Rename: its name and purpose.
- Move: into another folder. Folders inside it move with it. Moving a folder into a more protected folder raises its protection; moving it out never lowers it.
- Colour and icon: a folder takes both from its name until you choose otherwise. The colours are Green, Blue, Amber, Plum, Teal, Rust and Slate. The icons are Folder, Book, Notes, Data, Analysis, Ethics, People, Paper, Milestone and Experiment.
- Mark as human-subject data: for recordings, transcripts, field notes and consent forms.
- Delete: it asks first, and says how many folders inside it will go too.
Sensitivity labels
Every document carries a label. The labels, from lowest to highest, are:
| Label | What it means for AI |
|---|---|
| Public | Any model you choose may read it. |
| Internal | Any model you choose may read it. This is the usual label. |
| Personal data | Only a model on this computer reads it, unless you allow hosted models for its folder. |
| Special category data | Only a model on this computer reads it, unless you allow hosted models for its folder. |
A folder's label is a floor: everything filed in it, or in folders inside it, is labelled at least that high.
- Raise label… lifts a folder's label. Labels can only be raised here; lowering one is a decision the workbench does not offer as an edit. Raising a label also withdraws any permission you gave hosted models.
- Mark as human-subject data makes the folder special category. Everything in it, in folders inside it, and filed in it later is treated as special category data. Documents in it show the notice: This document holds human-subject data. Treat what you copy out of it as special category data.
Letting hosted models read a folder
Sometimes participants consent to their data being processed by a hosted service. In that case, open the folder's tray and choose Allow hosted models…:
- Write why this is allowed, for example what the participants consented to. You cannot allow it without a reason.
- Press Allow hosted models.
The permission covers that folder only; folders inside it keep their own. Every AI call that relies on it names the folder in its record. Withdraw takes it back at any time.
If a hosted call would include a document whose label is not known, nothing is sent. A refused call is still recorded in the evidence. On a document's page, a button the label blocks is greyed out, with a note offering two ways forward: choose a local model in Settings, or allow hosted models for the folder.
Privacy is enforced where the model is called, not in the screen. A label stops a document reaching a hosted model however the request was made, whether by a summary, an answer, a claim check or an experiment.