Skip to main content

Decide what information your agents may share

Define information-sharing boundaries by data, recipient, and purpose, including summaries, private conversations, and collaboration between Agents.

An Agent can read a calendar to find a meeting time. Does that mean it may tell everyone why a particular hour is blocked? Reading and sharing are separate decisions.

Ask one of your Octavus Agents to help turn that distinction into Handbook guidance for its job. Use the hypothetical examples to discuss sharing choices with the appropriate approver. Record the approved rules in your Handbook.

Start beyond the built-in practices

Agents are instructed not to expose passwords, keys, or one-time codes in replies, even to authorized users. Authorized users can view credentials in Settings. A more open collaboration policy does not change that boundary.

Agents are also generally forthcoming with internal coworkers and instructed to protect confidential information externally unless authorized. Your additional policy should explain which internal recipients, external recipients, and other Agents may receive which information for their work. “Internal” is often too broad for personnel or commercially sensitive information.

Describe a sharing decision in one sentence

A useful pattern is: this role may share these details with these recipients for this purpose. Add when approval is needed and who can give it.

A hypothetical scheduling Agent may share available meeting slots with confirmed attendees to arrange a meeting. It may not share event titles, notes, or attendee lists from unrelated appointments.

Ask your Agent to map the information it encounters. Possible company choices include:

  • Customer records: Should account-specific details stay with the assigned account team, while an approved aggregate service report is available more broadly?
  • Employee information: Who needs individual compensation or case details, and when would an approved staffing total be enough?
  • Financial data: Which budget summaries may teams use routinely, and who may receive transaction-level details?

Read access supports doing the job. It does not automatically authorize forwarding the source, quoting it, or answering questions about everything in it.

Allow openness where it helps

A hypothetical project-coordination Agent could share an approved milestone schedule with any coworker. This saves the project lead from repeating routine answers, but allows wider reuse of those details. Keep unreleased commercial plans out of that approved schedule.

Limiting individual case details to the assigned case owner, for handling that case, reduces circulation but adds routing and approval work.

These choices can coexist. Avoid turning the most sensitive task into the rule for every Agent, or treating one openly shared document as permission to share everything nearby.

Keep the boundary when the format changes

A summary can still reveal sensitive information. Removing names may leave enough context to identify a person or expose a decision.

Suppose someone privately discusses a proposed team change. A later request for “just the main points” does not authorize a summary to the wider team. The Agent should apply the sharing rule and ask the designated decision-maker if the audience or purpose is unclear.

This applies across channels and DMs. Octavus does not guarantee that information from a channel stays out of later DMs. Write recipient and purpose rules that apply across conversations, and use appropriate service permissions to limit access.

Apply those rules to Agent collaboration too. Another Agent may receive information when its role and task are authorized to use it. Asking an Agent to relay restricted information does not create new disclosure authority.

Check the rule with small examples

Ask for hypothetical responses without real disclosure: a coworker requests an approved schedule; an attendee asks why a calendar slot is blocked; another Agent requests a private discussion summary. Review both what would be shared and what would be withheld.

Approve focused Handbook updates. Make the rules readable by the affected Agents without putting sensitive source material into a broadly visible policy page. Changing page visibility does not erase context an Agent has already encountered. Record one-off exceptions with the request and specify their scope. Changes to the standing policy require separate approval.

Ask your Agent to help

Read https://octavus.ai/support/agent-policies/decide-what-information-agents-may-share and help define our information-sharing rules. Search existing Handbook guidance first. Ask about customer records, employee information, financial data, and other data we handle: who may receive which details, for what purpose, and who approves exceptions, including sharing with other Agents. Propose focused updates and test hypothetical disclosures without sharing real information. Wait for the appropriate human's approval before saving. After approved changes, return the changed Handbook links and any unresolved permissions or actions.