Security

Per-folder visibility and need-to-know access in a data room

A CogniSuite data room sets access per folder rather than once for the whole room. Material can be shared with the counterparty, kept internal to the deal team and their client, or restricted to one named organization such as a clean team, and the room knows which side of the deal each participant is on. This piece explains how those settings resolve, what they do and do not prevent, and what the audit trail records.

By the CogniSuite team

What the three visibility settings mean

Access in a CogniSuite data room is set per folder, not once for the whole room. Every folder carries a visibility label that decides which organizations can see it at all, before any question of downloading. Most deals use three of them.

Shared material is labelled external, with an equivalent all-buyers label for a room with several bidders. This is what the counterparty side is meant to see: the diligence tree and the documents that answer a request list.

Internal material is labelled internal. It is visible to the advisory team and the client they represent, and not to the other side. Working files, valuation drafts, board material and internal correspondence sit here.

Restricted material is labelled specific, scoped to one named organisation. It is readable only by the org it names, not by every party on that side of the deal. This is the setting for clean team material, for one bidder's negotiated schedules, or for anything one party may see and the others may not.

Labels are inherited and they fail closed. A folder without its own label takes the nearest label set above it, and if nothing resolves it is treated as internal. Folder trees generated during deal setup are handled the same way, so anything unspecified is written as internal.

How access is resolved when several settings could apply

Visibility answers who a folder is for. A separate access grade answers what those people can do with it: full, watermark, view or none, plus a flag for whether that party can upload into the folder.

Grades resolve in a fixed order: a grant written for one user in one organization wins first, then a grant for that whole organization on the folder, then the same two questions asked at the parent folder, and finally the organization's room-wide default. In practice a grade set on a top-level folder is usually enough, and an exception written deeper stays an exception.

Two limits are worth noting. Roles on the advisory team resolve to full access without consulting folder grants, so the per-folder model scopes client and counterparty organizations rather than compartmenting your own team. And defaults are permissive: a room where nobody has written a folder grant runs on the organization default, which allows reading and clean download. You have to configure the restrictions; the room does not start with them.

How deal-side awareness changes who counts as the counterparty

A room stores which side the engagement is on. On a sell-side mandate the internal client is the seller and the buyers are the counterparty. On a buy-side mandate that flips: the client is the buyer, and the seller is external.

The internal room is therefore defined by side, not by label alone. Anyone neither on the advisory team nor with the internal client is treated as the counterparty, and their default grade on an internal folder is none. If the deal type is missing or unrecognised, the room falls back to sell-side behaviour rather than opening anything up.

Side awareness also decides which folders appear in the tree listing, not only which files open. A counterparty does not see the names of folders it cannot access, so the structure of your internal room is not itself a disclosure.

One qualification: this is a default rather than an absolute block. An explicit grant still opens a named internal folder to a counterparty, because explicit grants apply on top of the side-derived default. That is deliberate, but it means the internal room is only as closed as your grant list.

How restricted and clean team folders are set up

Clean team arrangements need a folder that one named organization can read and nobody else on that side can, which is what the specific label does. A specific folder under an internal parent stays scoped to the named org rather than inheriting the wider internal audience.

There is a sequencing point. The canonical M&A folder structure offered at deal setup ships restricted categories as internal rather than as specific, because a specific folder needs a target organization and none exists when the room is created. The wizard badges those categories as clean team material while you are setting up, but the badge is not stored on the folder afterwards, so note which ones it applied to. Those folders start closed and are re-pointed at the named party once it has been added. Starting closed is the safer failure mode, but the step is manual.

What view-only and watermarked access actually prevent

Files are stored as clean originals. A watermark is applied when a file is served, carrying the viewer's name, their organization, a UTC timestamp and a confidentiality marking. A folder-level setting overrides the organization-wide setting in both directions, so an explicit full grant yields a clean copy and an explicit watermark grant forces a marked one.

The view grade is enforced separately from read access. A folder set to view can be opened in the viewer, but the file cannot be exported. The single-file download is blocked, so is the native-format stream the viewer uses for spreadsheets and Word files, and the file is skipped inside a bulk zip rather than included.

Watermarking has two limits. It covers PDF, common image formats and Word documents. Spreadsheets and presentations pass through the download path unmarked and only the converted preview carries a mark, so view-only is the setting to use where an unmarked spreadsheet would be a problem. Watermarks are also a visible deterrent rather than forensic marking, and the Word implementation can be removed by a determined recipient.

How AI answers inherit the same permissions

Retrieval for the AI features runs through one shared function that applies a folder-read check before a document is admitted as a source, so results are built from what the asking user may read rather than filtered afterwards. When the AI drafts a response that will be shown to the other side, a document is eligible only if every counterparty organization that can see the relevant request list may read it, and the logic denies rather than falling back to the deal team's own access when it cannot resolve that.

The limit to know is that retrieval admits any folder the user has some access to, including the view and watermark grades, so an AI answer can quote text from a document that user may only view watermarked. If a document's text must not be reproducible by that party, the correct setting is none rather than view.

What the audit trail records

The per-deal log covers several dozen distinct action types. Document activity is recorded as views, detail views, downloads, copies and deletions, with bulk zip downloads marked so they are distinguishable from single-file exports. Permission activity is recorded when a folder grant is set, reset or bulk applied, and when organization or user permissions change. User and organization lifecycle events, request and Q&A workflow transitions, AI questions and filtered inputs land on the same trail, which can be filtered by action type, actor, organization and time range and exported as CSV.

The honest limits are these. Reading and exporting the trail is restricted to the advisory team, so it is an oversight tool rather than a mutual record a counterparty can inspect. Entries are written without blocking the underlying action, so logging is best effort. The log is not cryptographically tamper-evident, and source IP addresses are not recorded, so attribution is to an account rather than to a device.

How to check the settings before anyone is invited

The deal team can set a session to view the room as a specific counterparty organization. The permission resolver runs against that organization, so the folder list and access grades shown are the ones that party would get. It is the fastest way to confirm an internal folder is closed and a clean team folder scoped before invitations go out.

For the platform's wider security posture, see /security. The data room capabilities are summarised on /features.

This article is general information, not legal, tax, or financial advice. For how CogniSuite handles security and access, see Security.

← All articles