Skip to content
Service status

Type to search

Using AI Safely and Responsibly · 2 min read

Which assistants can handle personal data?

Security classifications signal what kind of data an assistant is approved to process. Know how to read them — and what to do when you're not sure.

Learning goals

  • Understand what security classification means and how to read it
  • Know which classification level is appropriate for different types of data
  • Know what to do when you’re unsure whether an assistant is cleared for a task

Not all assistants in your organization’s Intric environment are set up the same way. Assistants can be configured with different security classifications, reflecting the type of data they are approved to process.

A security classification on an assistant signals what kind of information is appropriate to bring into it. Think of it like the physical spaces in your office: some rooms are open to everyone, some require an access card, and some are for authorized personnel only. The same logic applies here.

Your organization’s IT or security team sets these classifications when the assistants are built. Typical levels might look like:

  • Open / Public — Intended for tasks that don’t involve personal data or internal sensitive information. Suitable for general drafting, public information, or research tasks.
  • Internal — For internal documents and discussions, but not for personal data about citizens or employees.
  • Confidential — Approved for working with personal data within the bounds of your normal work tasks. The underlying model and infrastructure must support this.
  • Strictly confidential — For sensitive personal data (special categories) or particularly sensitive organizational information. Requires extra steps such as a DPIA, and will often run on a private or on-prem deployment.
Deep dive: classification and deployment

The classification doesn’t just reflect what data you put in — it also reflects how the assistant is deployed. Intric supports EU cloud, private cloud, and on-prem installations. A strictly confidential assistant will typically run on infrastructure that doesn’t connect to external systems. See Intric’s security documentation for specifics on deployment and data handling.

Check the assistant description or ask your administrator. If you’re not sure whether an assistant is cleared for the data you want to work with, assume it isn’t and check first. It is always better to ask than to retroactively discover a mismatch.

Example: You work in social services. A colleague has set up an assistant to help draft internal memos. The assistant is marked as “internal use.” You want to use it to summarize a case involving a client’s health status. You shouldn’t — this type of assistant isn’t configured for special category health data. You would need a “confidential” or “strictly confidential” assistant that has been specifically approved for that purpose.

Test your knowledge

Question 1 of 5

Question 1 of 5

An assistant is labeled 'open/public' in your organization's Intric environment. A citizen has sent in a query and you want to use the assistant to draft a reply that includes their name and address. Is this OK?

An assistant is labeled 'open/public' in your organization's Intric environment. A citizen has sent in a query and you want to use the assistant to draft a reply that includes their name and address. Is this OK?