Personal mail, privacy, and the Visibility Review

A promo shop runs on personal mailboxes, and a personal mailbox contains things that are nobody else's business. Scout's answer is a rule and a queue: mail from a personal mailbox stays with the person who owns it, and when something in it genuinely belongs to a colleague, an Owner or Admin decides — on facts, not on the message.

The Visibility review queue listing items that want to cross an employee boundary.

Screenshot: the Visibility review queue.

The rule

When you connect your own mailbox, the work Scout finds in it is yours. It appears in your Inbox, assigned to you. It does not appear in anyone else's, and it is not visible to the Owner because they are the Owner. Role grants capability; it does not make anybody a universal reader of other people's email.

If nothing in your mail matches anything anyone else is working on, nothing is ever shared. No match, nothing shared.

The three evidence tiers

Every point carries evidence — the rows of proof underneath it. Each row sits at one of three tiers, and the tier decides who can open it.

Tier Who sees it What it contains
Review metadata The Owner or Admin doing a review The linked customer and work, who the participants are, the destination Scout proposes, its reasoning and its confidence. No message text. No attachment.
Operational The people the point was approved for Scout's conclusion plus the minimum fact or dated excerpt needed to act on it.
Original Only people entitled to the source itself The full message, the attachment, the raw record, the link into the provider.

Being assigned a point never grants the original tier. To open the actual message you have to have access to the mailbox it came from. That is why a colleague can be accountable for following up on a thread and still not be able to read it.

The review queue

When a point derived from someone's personal mailbox matters to someone else, Scout does not route it and then apologise. It holds it and queues a visibility review. The Inbox shows a Visibility review count in its housekeeping row, the header bell flags it, and the queue lives at its own page.

Only an Owner or an Admin can open it. For anyone else the page simply does not exist.

The queue's own note sets the boundary: nothing here is a message. This tier carries participants, source, linked work and Scout's reasoning — the body and any attachment stay where they are, whatever you decide.

Each row shows

  • The account it concerns — Barks & Rec, Whisker Creek Vet — and a confidence figure such as 0.86.
  • PARTICIPANTS — who was talking, for example "Meghan Doyle ↔ Dylan Foss (Barks & Rec)".
  • SOURCE — which mailbox and on what basis, for example "Meghan's Gmail · personal grant", and whether an attachment is involved.
  • LINKED WORK — the quote, order or account it attaches to, or "No linked work yet".

How to decide one

  1. Open the Visibility review page, or click the count in the Inbox housekeeping row.
  2. Pick a row. The panel on the right opens with the header OWNER REVIEW · POLICY v1.
  3. Read WHY SCOUT THINKS IT CROSSES. This is Scout's reasoning in sentences — what the thread is about, why that is another team's work, who owns the account, and what the evidence actually is. It restates the limit as it does: message body and attachments are not available at this tier — and would not be, whatever you decide.
  4. Read SCOUT RECOMMENDS: one team, one person, and the reason that destination was chosen — for example "Exact upstream owner matched to an active membership — precedence step 1."
  5. Choose one of three:
    • Approve and assign — the primary action. In one transaction it grants the operational tier and makes that person accountable. Scout tells you what changes: "Approval makes Ray Alvarez accountable at the operational tier. The source owner keeps the thread — the original message moves nowhere."
    • Edit destination — a secondary action, for when Scout picked the wrong team or person. You are not asked to choose a destination from scratch on every row.
    • Deny — nothing is shared. The point stays private to the source owner, and your call is stored as routing feedback with the policy version that asked, so Scout proposes better next time. Denying does not delete the evidence.
A decided review row showing who is now accountable and the Undo control.

Screenshot: a decided row, with Undo.

After a decision

The row keeps its answer on it: APPROVED · RAY ALVAREZ IS ACCOUNTABLE, APPROVED · YOU ARE ACCOUNTABLE, or DENIED · STAYS WITH THE SOURCE OWNER. Undo reverses your own decision while the undo is still available. Load earlier decisions pages back through the history until Scout says every visibility decision is now available.

Two things the queue handles

  • A personal-source crossing — the case above: work found in one person's mailbox that belongs to another person or team.
  • Admin triage — a narrower row, marked ADMIN TRIAGE with an ASK, that appears when a seat is deactivated and someone must own the work that person was carrying. It shows the account and the question only, with CHOOSE A NEW DESTINATION, Assign point and Grant no new audience. No private source context is added to this kind of review at all.

Attachments

A row involving an attachment is flagged ATTACHMENT · ALWAYS HUMAN. Approving it assigns the point at the operational tier and the attachment stays exactly where it is, at the original tier, with the source owner. Approval never hands over a file.

Doing several at once

Select rows and use Approve N and assign. Each one is approved independently, on its own recommendation, so a batch is not one blanket permission — it is several separate decisions taken in one sitting.

Shared mailboxes do not need this

A named shared mailbox is a team-owned source. Work from it routes inside the owning team with no personal-mail review, because no employee's private mail is in play. If your team wants a queue like orders@ read without an approval step on every item, connect it as a shared mailbox — see Team-owned versus personal sources.

Covered addresses: one conversation, one item

When a shared or company source is the authoritative reader of an address, a point derived from someone's personal mailbox for that same address stays private and Scout records why, rather than raising a second copy of the same conversation from a personal grant. The item you work is the one the team source owns. This is also what keeps two connected mailboxes from turning one email thread into two competing action items.

Good to know

  • An empty queue is the normal state. Scout's own wording: "Every crossing has an answer. New ones land here as Scout reads personal mailboxes — it never expands one on its own under policy v1."
  • Every decision is one transaction and one audit row, with the policy version attached. There is no quiet widening of access.
  • Scout's analyzers cannot reach into a personal mailbox for a company-wide calculation. Evidence that mixes personal and company sources fails before a conclusion is ever saved, rather than being shared and corrected later.
  • Supplier evidence is workspace evidence and may be shared inside the workspace. It never makes a colleague's private mailbox visible to you.
  • If two sources disagree, Scout keeps the disagreement and both pieces of evidence instead of quietly choosing the more convenient story.
  • The full privacy commitments, including how Scout handles your data with model providers, are in the Privacy Policy at https://scout-hq.io/privacy.
Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us