Public discovery and private work are separate
Public pages, published Insights, public Signals metadata, public team pages and approved public profile information can be discoverable. Private workspaces, tasks, files, billing records, non-public profiles and all chats remain outside public indexing and AI discovery resources.
A public object and an authenticated destination can coexist. Search engines may understand that a public Signal or team page exists without receiving private conversations, participant-only details or cabinet data.
Know which surface you are using
| Surface | Typical visibility | Examples |
|---|---|---|
| Public discovery | Public and indexable where explicitly published | Home, About, Partnership, Insights, approved public team/profile pages and public Signal discovery metadata |
| Authenticated account | Signed-in account only | Cabinet overview, personal settings and private workspace navigation |
| Team-scoped | Authorized team members and managers | Private team composition, owned team settings and internal collaboration context |
| Project-scoped | Authorized client, partner and confirmed project participants according to role | Tasks, project files, Work Graph, project analytics and commercial records |
| Conversation-scoped | Conversation participants only | Team chat, project chat and direct messages |
| Owner-private | The account that created the private record | Private collaboration notes and protected personal account data |
How private data is protected
Access follows the real role and object relationship
- Being signed in is not enough to read an arbitrary private project; the account must have an authorized relationship with that project.
- A saved team member is not automatically an active project participant.
- Pending specialists cannot receive project tasks until the required confirmation is complete.
- Client, partner and specialist cabinets can show different actions for the same project because each role owns different decisions.
- Opening another workspace does not bypass a project, team, billing or chat permission check.
Chats are always private
Team chats, project chats and direct messages are private participant data. They are not placed in sitemaps, RSS or Atom feeds, llms resources, public profile payloads or public search APIs.
An authorized project agent may read only the conversation context permitted for its project responsibility. This does not convert the chat into public content and does not allow another user or crawler to retrieve it.
Public indexing is intentionally limited
| Resource | Purpose | Private data included? |
|---|---|---|
| Sitemap | Lists canonical public pages that should be discovered | No |
| RSS / Atom | Publishes approved public Insights or Signal discovery content | No private chats, tasks or workspaces |
| llms.txt and Markdown pages | Explain Collty and public documentation to AI systems | No authenticated records |
| Structured data | Describes public Organization, WebApplication, article or other supported public objects | No private project or account detail |
| Authenticated API | Serves account and workspace workflows after access checks | Only data permitted for the authenticated role |
Share deliberately
- 1Check the object
Confirm whether you are sharing a public profile, a team preview or a private project object.
- 2Check access
Add only the people who need the workspace or project.
- 3Use project communication
Keep confidential decisions inside authorized project tools rather than public Signals.
Protect your own access
- Use a unique password or the configured identity-provider flow and sign out on shared devices.
- Do not forward project links as a substitute for adding the correct authorized participant.
- Review team and project membership when somebody leaves a collaboration.
- Use public Visibility only for information intended to support professional discovery.
- Contact Collty Support with the affected workspace and object if access appears broader or narrower than expected; do not include passwords or credentials.