Knowledge Base Clearance
Classification-aware clearance for Knowledge Base documents (commercial default, NATO/EU-compatible label sets) — controlling read visibility, clearance-capped labeling, search filtering, and structured-field extraction.
Scrydon controls who can see what in a Knowledge Base with classification-aware access control. Every document carries a classification label drawn from your organization's active classification scheme, and users can only read — and only apply — labels at or below their own clearance.
The active scheme is configurable. Scrydon ships a commercial 4-tier default (PUBLIC · INTERNAL · CONFIDENTIAL · RESTRICTED) and selectable NATO and EU label sets compatible with those taxonomies. Switching the active scheme changes the labels the pickers show.
A new upload that you don't explicitly label lands at the scheme's baseline rank (INTERNAL on the default scheme), not the maximum. You can pick a higher label only up to your own clearance — the picker hides labels above it and the server rejects an over-clearance label.
"Compatible with NATO / EU taxonomies" means the label/rank ladder and policy-driven access control — not an accreditation to store or handle real classified material. Accreditation, hosting, personnel, and handling controls are out of scope.
Classification levels
Labels and ranks come from the org's active classification scheme. The default scheme is a 4-tier commercial ladder, ordered from least to most restrictive:
| Level | Rank | Description |
|---|---|---|
| PUBLIC | 0 | Approved for external release |
| INTERNAL | 1 | Internal use only; baseline for unlabelled uploads |
| CONFIDENTIAL | 2 | Limited distribution; clearance required |
| RESTRICTED | 3 | Narrow need-to-know; highest sensitivity |
Selecting the NATO scheme switches the picker to UNCLASSIFIED · RESTRICTED · CONFIDENTIAL · SECRET · COSMIC TOP SECRET (ranks 0–4); the EU scheme to RESTREINT UE · CONFIDENTIEL UE · SECRET UE · TRÈS SECRET UE (ranks 1–4). A document is always ranked against the single active scheme — schemes do not coexist within one organization.
Ranks are comparable only within the active scheme. Switching the active scheme is a governed, migrated event handled by an org admin, not a per-document choice.
Your clearance
Each user has a clearance rank in the active scheme. It defaults to the scheme's baseline when no grant exists, and is set in one of two ways:
- Baseline clearance — an org admin sets a member's durable clearance under Settings → Organization → Members: open a member's row and use the Clearance section. When your identity provider supplies clearance claims this baseline is provisioned from those claims; when Scrydon is your own IdP, the admin sets it directly here. The baseline can be raised or lowered at any time.
- Temporary override — under Settings → Governance → Clearance → User Clearance, an admin can grant a time-boxed (≤90-day) elevation above the baseline. It requires a second admin to approve (four-eyes) and only ever raises clearance, never lowers it.
Your clearance determines two things:
- What you can read — documents at or below your clearance rank.
- What you can label — you cannot classify or reclassify a document above your own clearance. The upload and reclassify pickers only offer labels at or below your clearance.
Labeling above your clearance is blocked server-side, not just hidden in the UI. A Confidential-cleared user who tries to mark a document Secret (e.g. via the API) is rejected with an explained error — you cannot create data you would not be allowed to read.
How Clearance Works
Clearance filtering is enforced at three points in the system:
Chunk Inheritance
When a document is processed into chunks for embedding, each chunk inherits the parent document's clearance level. Changing a document's clearance automatically applies to all of its chunks — there is no per-chunk clearance override.
Clearance Changes
Raising a document's clearance immediately hides it (and its chunks) from users who no longer meet the threshold. Lowering the clearance makes it visible to a broader audience. Changes take effect on the next page load or search query.
Company Context clearance
Company Context uses the same active classification scheme and no-read-up rule as workspace knowledge bases. Its pages and sources are not automatically promoted or extracted from workspace documents: organization owners and administrators maintain them deliberately in the dedicated editor.
- Readers see only Company Context material at or below their clearance.
- Owners and administrators can edit only from the Company Context page and cannot apply a label above their own clearance.
- Process Flow actions and shared Cortex conversations retain a fixed action classification ceiling; a higher-cleared participant cannot make the shared result reveal higher-classified Company Context.
Reclassifying or deleting a source takes effect when a reference is next opened. A now-inaccessible source is shown as unavailable rather than exposing its title, path, or content.
Setting and changing classification
You can change a document's classification from the Knowledge Base, up to your own clearance.
Raising a document's classification immediately hides it from anyone whose clearance no longer meets the new rank. The change (old rank → new rank, who made it, and the active scheme) is written to the audit trail.