Spaces · 2 min read
Security classification
How a Space's classification restricts which models and tools can be used in it.
Every Space carries a security classification, and it works as a filter: models and tools classified below the Space’s level simply aren’t offered there. That’s what stops sensitive material reaching a model your organization hasn’t approved for it.
What the classification controls
Section titled “What the classification controls”A Space’s classification determines which language models, embedding models, transcription models, and tools appear when you or anyone else builds an assistant in it. Anything classified too low for the Space is grayed out or missing entirely — not merely discouraged.
Setting a Space’s classification
Section titled “Setting a Space’s classification”A Space admin sets its classification from the Space’s settings. New assistants created in the Space automatically inherit it.
Changing it on an existing Space
Section titled “Changing it on an existing Space”Changing an existing Space’s classification can immediately affect resources that were relying on a model or tool the new classification no longer allows. Before confirming, review the list of affected resources the interface shows you — some changes have no effect on functionality, while others remove access to something currently in use.
What happens to resources that no longer qualify
Section titled “What happens to resources that no longer qualify”An assistant using a model or tool that falls below the new classification loses access to it. The assistant isn’t deleted, but that specific model or tool stops being usable there until reconfigured.
Where a classification’s data may be processed
Section titled “Where a classification’s data may be processed”A classification can also carry the regions its data may be processed in. These are set per classification by an administrator, under Policies, and they apply to completion, embedding, transcription and image models alike.
A model hosted outside those regions is not offered in Spaces with that classification, and saving or asking with one is refused with the region given as the reason. This is separate from the classification level itself — a model can be approved for the classification and still be unavailable because of where it runs.
For how regions, models and sub-processors fit together, see Processing regions.
Why a model or tool is missing
Section titled “Why a model or tool is missing”If a model or tool you expect to see doesn’t appear when configuring an assistant, the most likely reason is that it isn’t approved for the Space’s current security classification. The second most likely is that it runs outside the regions the classification permits.
Where an action is blocked rather than merely hidden — moving an assistant into a Space, or choosing a model or embedding model the classification doesn’t allow — Intric now tells you which model is blocking it, instead of returning a generic error with an error ID.
Classification hints for users
Section titled “Classification hints for users”Where your organization has configured one, a short hint appears when you interact with a resource carrying a particular classification. It tells you what kind of data the classification is appropriate for, without having to ask an administrator.