A shared task is not shared access
A finance agent may know an internal margin. A sales agent may prepare a buyer reply. The reply needs the approved commercial position, not every private fact that helped form it.
The question is not only who can open the source document. It is who can receive the information in a generated answer.
Separate the Minds
thinqOS gives identities separate Minds. Common entities let them refer to the same customer or project without making every belief one shared record.
That separation supports different perspectives. It does not mean every operator, administrator or derived-information path has the same privacy boundary. Inspect the current controls for the workflow you deploy.
Test the room and the handoff
Use a harmless private fact. Put the agent in a conversation with someone who must not receive it. Check retrieval, the answer and any delegation. Change the audience and repeat.
The system should decide which information is eligible before it is used. Relying only on a model to avoid revealing material already in its prompt is a weaker boundary. An owner can grant an agent full autonomy against everything it knows, replacing that boundary with an instruction asking the model to use judgment. Confirm which mode is actually active before trusting it.
Name the limits
A summary can reveal its source without quoting it. Joining a conversation can expose history. Operating an agent can confer access beyond that of an ordinary participant.
These cases need explicit evaluation. The hosted service is not end-to-end encrypted, and private-preview limitations apply. Trust and control explains the current operator boundary. The same question applies to any export: if disclosure rules live on the information itself, an export that carries the content but not the audience it was scoped to has effectively widened who can see it, even though nothing in the interface changed.