Integrity
AdministrationPermissions

Restricted Access

Control which workspace members can open specific sources and folders, while keeping references display-safe elsewhere.

Restricted access lets a workspace keep most content visible to the team while limiting sensitive sources or folders to explicit members. A restricted item can still appear as a locked or redacted reference when that helps people understand the workspace without exposing its contents.

Restricted access is an app permission model. It is not a confidential-data, CUI, ITAR, classified, special-access, or deployment-accreditation control.

How restricted items appear

StateWhat it meansWhat a non-member sees
AccessibleYou have workspace, folder, source, or direct-share access.Full detail allowed by your role.
LockedYou may know a restricted source or folder exists, but you cannot open it.The allowed title/path, lock state, request status, and no children or artefacts.
Redacted referenceA restricted item affects a result, but naming it would leak detail.Generic copy such as Restricted source or an aggregate count.
Direct-shared sourceYou have explicit source access even though the parent folder is not browsable.The shared source opens; parent folders stay muted and non-clickable.
HiddenThis surface should not reveal the item exists.Nothing.

Restricted detail is removed before it reaches docs-facing views, Integrity findings, traceability references, baseline rows, import reports, notifications, and agent proposal previews.

Feature Phase surfaces follow the same rule. Hidden private-Team Issues do not contribute visible Phase progress/counts, Feature aggregate Activity stores no Issue title, and a Phase link or assignment never grants access to the Feature or Issue.

Restrict a source or folder Admin

Use a source or folder's Settings to change its visibility to Restricted. Restricted items are visible only to explicitly added members, inherited parent-folder members, plus workspace owners/admins where the workflow allows governance or recovery.

When you restrict a folder, its children are not browsable by non-members. A source inside a restricted folder can still be shared directly with a workspace member; that person can open the source without browsing the parent folder.

Add or remove members Admin

Use the source or folder Members tab to add workspace members as Viewer, Editor, or Manager. A parent-folder role inherits to child folders and sources; child scopes can add local access, but they cannot remove the inherited parent role in this release. Removing a local member removes their access immediately and keeps the access-change history in logs.

Operational member lists show current access. Old approved, denied, revoked, or replaced states belong in logs/history surfaces.

Request access Admin Editor Viewer

When a restricted source or folder is locked but discoverable, you can request access from the locked page or entry point. The request shows as pending until a Manager or workspace governance actor approves or denies it.

If approved, the item becomes accessible at the granted role. If denied, the locked page can show the decision state and let you request again when appropriate.

Approve or deny requests Admin

Admins review requests from the source or folder Requests tab or from request notifications. Approval adds the requester as a member at the selected role. Denial records the decision without granting access.

Request notifications are safe to act on: they show request context and action state, but unrelated restricted artefact identifiers, link detail, import evidence, and baseline evidence stay hidden.

Work with redacted references Admin Editor Viewer

Restricted references appear across traceability, baselines, source history, activity, import reports, Integrity health, and Integrity findings. If you cannot access the underlying source or artefact, Integrity uses generic labels, locked states, or aggregate counts.

For baselines, aggregate counts can remain visible even when some included modules are restricted for you. The Baselines table may show module and artefact count hover breakdowns; modules can show visible and restricted totals, while restricted artefact detail stays display-safe. Locked baselines may show captured artefact totals, while restricted artefact names, identifiers, fields, links, and diffs stay redacted.

Redacted references do not include:

  • source names you cannot access
  • artefact identifiers or field values
  • link details
  • import evidence or archive URLs
  • baseline evidence
  • agent-ready repair summaries

FAQ

Can a restricted folder be completely invisible? Some surfaces hide restricted items entirely. Search and recent entry points may show locked source/folder metadata when the product needs discoverability and request access.

Can someone open a source inside a restricted folder? Yes, if they have explicit source access. The source opens as a direct share, but the parent folder remains non-browsable.

Do restricted sources protect regulated data by themselves? They protect app access inside Integrity. They are not a substitute for controlled-data compartments, environment accreditation, export-control handling, or legal data-classification controls.

Why can I see a count but not the item name? Counts can explain that a hidden item affects a finding, baseline, or workflow without revealing what the item is.

On this page