Blog

Document-level confidentiality: why seeing a case should not mean seeing every file

Not every document in a dossier is equally sensitive. Document-level confidentiality lets a person follow the case without seeing every file — and never widens access to anyone who could not open the dossier.

Dossier with documents at different confidentiality levels and access filtered by user profile.

In a real document process, not every document is equally sensitive. A dossier can hold public data, internal notes, confidential documents and restricted attachments — and treating them all with one permission forces a choice between two risks: giving access to more than you should, or blocking the people who needed to work. Document-level confidentiality resolves that: each document carries its own level, and a person can follow the dossier without necessarily seeing every file in it.

The rule that makes this safe is restrictive: a document narrows access within the dossier and never widens it to someone who could not open the dossier.

The problem with whole-case access

Many systems start from a simple rule: if somebody can open the case, they can open the files. It is convenient, and it is fragile. Think of an employee onboarding dossier: the contract, the identity document and the medical fitness certificate live in the same case. The person coordinating the onboarding needs to know whether the certificate has arrived; they do not need to read it. The same goes for the medical report in an insurance claim.

When control exists only at folder level, teams solve it by hand: parallel folders — "Onboarding" and "Onboarding — confidential" — with a copy of each dossier in each, or the sensitive file emailed to whoever may see it, living outside the case from then on. Governance disappears precisely where it was most needed.

How it should work

A governed dossier combines several axes, and each one answers a different question:

Axis Question it answers Effect on access
Organisation Whose data this is Bounds everything else
Organisation unit Which part of the company the case belongs to Grants, by scope
Role What the person may do Grants actions
Dossier team Who is on this particular case Grants, by name
Dossier confidentiality Which level is needed to open the case Narrows
Document confidentiality Which level is needed to open this document Narrows, only within the dossier

The first four axes grant; the last two narrow. The healthy rule is the restrictive one: a document can limit access within the dossier, but it cannot grant access to anyone who could not open the dossier. It is an additional layer of protection, never a side door. If a document could be more open than its dossier, "who can see this?" would stop having a computable answer — it would depend on every exception created on every document, and access would become impossible to audit. With the restrictive rule the answer is always the same: whoever can open the dossier and holds the level the document requires.

What the person sees

When somebody lacks access to a restricted document, the interface has to be clear without revealing content. It should show that the document exists, what status it is in — missing, uploaded, validated — and that it is protected. It should not show files, thumbnails, previews, extracted text or assistant sources that belong to it.

That avoids two symmetrical mistakes. The first is hiding the existence of an operational pending item: if the onboarding coordinator cannot even see that the certificate is missing, the dossier looks complete when it is not. The second is exposing sensitive information just to explain that it is protected — a revealing file name, a legible thumbnail, an excerpt in a search result. "There is a restricted document here, and it is validated" is all the information needed.

The same standard holds beyond the dossier screen: search cannot return what the person could not open, and an assistant cannot quote a restricted document to someone who cannot see it. The filter has to be applied when the passages are selected, not to the final answer.

The role of DOK Genius

Today, access to a dossier in DOK Genius is already decided by the layers above, down to each dossier's team, with collaborators and watchers. Every dossier has a confidentiality level — public, internal, confidential or restricted — inherited by default from the process, and Genius answers only from documents the asker may open. The manual chapter Teams, units and who sees what walks through those layers, and the security page describes the four levels.

Document-level confidentiality is on the roadmap: each document will be able to hold its own level, inherited from the process or adjusted in the dossier, and that level follows attachments, previews, downloads, search and Genius. A document can narrow access within the dossier; it never widens it to anyone who could not open the dossier. The chapter Working a dossier describes how that behaves on screen; the features page and the roadmap separate what exists today from what comes next.

The promise is simple: govern a dossier without flattening the sensitivity of the documents that make it up.

FAQ

Can a document be more open than the dossier it belongs to?

No. A document's level can only demand more than the dossier demands, never less, and anyone who cannot open the dossier sees none of its documents. If someone outside the case genuinely has to read a document, the answer is to place it in a dossier that person can reach, not to open an exception on the file.

Does someone without access know the document exists?

Yes. They see that the document is expected, what status it is in and that it is protected — enough to understand what is missing and not to submit an incomplete dossier. They do not see files, thumbnails, previews, extracted text or assistant sources. Existence is operational; content is sensitive.

How is this different from per-file permissions in SharePoint?

SharePoint knows how to restrict permissions on an individual item, and does it well. The difference is the form: a per-file permission is a list of names added to an item, which nobody can reconstruct a year later; a confidentiality level is a classification, set on the process, inherited by each dossier and always compared against the person's profile and the dossier's level. "Who can see this?" gets a computable answer.

Does this exist in DOK Genius today?

Dossier-level confidentiality and the dossier team exist today. Document-level confidentiality is on the roadmap. Until then, a case that needs to share less is a case with less in it.

All articles

Get started

See it on your own documents

Open a free account, or tell us what your files look like today.