C1.3Not started

Data tiers — public, internal, confidential, restricted

Reading depth

What you'll learn

  • Four tiers: Public · Internal · Confidential · Restricted.
  • Tier determines storage + sharing — match the rule to the tier.
  • When unsure, ask before sending. Asking is cheap; rework is not.

Most companies classify data into four tiers. Public: anyone can see it (marketing material). Internal: anyone employed can see it (handbook, org chart). Confidential: limited audience (financials before earnings, customer lists). Restricted: smallest necessary audience (PII at scale, credentials, secrets, source code for some companies).

The tier determines where the data is allowed to live. Public + Internal can usually go in shared drives, public docs, Slack. Confidential needs access-controlled folders + named recipients. Restricted needs encrypted-at-rest storage, named-recipient access logs, and a default 'no copy' rule.

When in doubt, ask. The cost of asking is a five-minute conversation; the cost of mis-classifying restricted data is a compliance incident your manager + security + legal all have to spend hours on.

Key points

  • Four tiers: Public · Internal · Confidential · Restricted.
  • Tier determines storage + sharing — match the rule to the tier.
  • When unsure, ask before sending. Asking is cheap; rework is not.

Examples

Tier examples

Public: company logo. Internal: handbook. Confidential: pre-earnings revenue. Restricted: customer PII, prod credentials.

Pitfalls

  • Putting customer PII in a personal Drive folder to 'work on it later'.
  • Pasting Restricted data into a chat with an external partner.

Ask your security team

In a real Adept rollout this routes to your company's security Claude project; in the demo it opens a fresh Claude chat.