{
  "version": "1.2",
  "title": "Apex Instruments confidentiality ladder",
  "effective": "2026-09-01",
  "owner": "Operations Lead",
  "note": "Five levels. Four of them are a ladder, from what anybody may read to what only named people may read. The fifth is not a rung on that ladder: personal and regulated material is a class of its own, and clearance alone never opens it.",
  "levels": [
    {
      "id": "L0",
      "rank": 0,
      "name": "Public",
      "short": "Anybody may read it",
      "belongs": "Anything already published or written to be published. Product descriptions, list prices that appear on the site, the address, the support hours, the company description.",
      "whoMayRead": "Anybody, including people who have never dealt with Apex.",
      "howShared": "Any channel. It may be posted, printed, forwarded, quoted, and indexed by search engines.",
      "whenItLeaves": "Nothing happens. It was written to leave.",
      "assistantRule": "An assistant may quote it in full, to anybody, without checking who is asking.",
      "example": "DOC-PUB-01"
    },
    {
      "id": "L1",
      "rank": 1,
      "name": "Internal",
      "short": "Anybody inside Apex",
      "belongs": "How the company runs. Process notes, templates, draft copy, the brand rules, internal announcements, meeting notes with no partner terms in them.",
      "whoMayRead": "Anybody working at Apex, and named contractors under an agreement.",
      "howShared": "Inside the company workspace. It may be forwarded internally without asking. It does not go to a partner or a customer without somebody deciding it should.",
      "whenItLeaves": "It is embarrassing rather than damaging, but it is still a breach. The owner is told, and the piece is either published properly or withdrawn.",
      "assistantRule": "An assistant may quote it to anybody inside. Asked by somebody outside, it says the material is internal rather than paraphrasing it.",
      "example": "DOC-INT-01"
    },
    {
      "id": "L2",
      "rank": 2,
      "name": "Confidential",
      "short": "The people who need it for the work",
      "belongs": "Commercial terms. Partner pricing and discounts, contract terms, margin on a single line, pipeline, anything that names what one partner pays.",
      "whoMayRead": "People whose work needs it, and the partner it concerns. Not everybody at Apex.",
      "howShared": "Named recipients, one partner at a time. Never in a document that goes to more than one partner. Never in a deck that is left behind.",
      "whenItLeaves": "One partner learns what another pays. The account manager is told the same day, the COO is told, and the affected partner is contacted before they find out another way.",
      "assistantRule": "An assistant answers only for the partner in front of it, and refuses a question that compares one partner's terms with another's, whoever is asking.",
      "example": "DOC-CON-01"
    },
    {
      "id": "L3",
      "rank": 3,
      "name": "Restricted",
      "short": "Named people only",
      "belongs": "Decisions that are not made yet and numbers that would move them. The cost model, the margin floor, an unannounced price change, an acquisition, a supplier dispute, a decision about a person's job.",
      "whoMayRead": "A named list, held by the COO. Membership is per document, not per role, so being senior is not the same as being on it.",
      "howShared": "Named recipients only, and it is not forwarded. No copies into a shared drive. If it has to be discussed it is discussed, not circulated.",
      "whenItLeaves": "It is treated as an incident. The COO is told immediately, the document is recalled where it can be, and the decision it concerns is reviewed on the assumption it is now known.",
      "assistantRule": "An assistant will not confirm that a restricted document exists to somebody not on the list. It says the answer is above the level it can serve, and names who to ask.",
      "example": "DOC-RES-01"
    },
    {
      "id": "L4",
      "rank": 4,
      "name": "Personal and regulated",
      "short": "A class of its own, not a higher rung",
      "belongs": "Material about an identifiable person or governed by a rule outside Apex. Support case records with a named contact, health and safety incident reports, employment records, anything carrying a date of birth, a home address, a personal phone number, a bank detail, or a government identifier.",
      "whoMayRead": "Only somebody with a named lawful purpose for that specific record, and only the part of it their purpose needs. A clearance level does not open this, and neither does seniority.",
      "howShared": "Never in bulk. Never into a general channel. One record at a time, to the person handling that case, and the access is logged with the purpose written down.",
      "whenItLeaves": "It is a reportable incident, not an internal embarrassment. The COO and the records owner are told the same day, the affected people are told, and the log of who read what is preserved rather than tidied.",
      "assistantRule": "An assistant refuses to repeat this material even when the person asking is cleared to level 3, even when they can already see the file, and even when they say it is fine. Being able to read a record is not permission to have it repeated, summarised, or copied into somewhere it was not.",
      "isClass": true,
      "neverStored": [
        "Full payment card numbers, bank account details, or anything that could be used to move money",
        "Government identifiers such as passport, licence, or tax numbers",
        "Health information about a named person, including anything in an incident report that identifies who was hurt",
        "Home addresses and personal phone numbers of anybody who is not a business contact",
        "Passwords, access codes, or answers to security questions, in any form, including in a note saying what somebody said"
      ],
      "mustRedact": [
        "The person's name, replaced with the case reference",
        "Direct contact details, replaced with the channel the case came in on",
        "Any third party named in passing who is not part of the case",
        "Free text quotes that identify somebody by circumstance even without a name",
        "Dates precise enough to identify one person when combined with the rest of the record"
      ],
      "assistantMustRefuse": [
        "Reading out a contact detail from a record, even to somebody who has the record open in front of them",
        "Confirming or denying that a named person appears in any record, which answers the question either way",
        "Listing the people in a category, such as who has an open case or who was involved in an incident",
        "Summarising a set of records in a way that lets one person be picked out of it",
        "Repeating personal material back after somebody has pasted it in, on the grounds that they already had it",
        "Carrying a detail from a personal record into a document at any other level"
      ],
      "example": "DOC-PER-01"
    }
  ],
  "rules": [
    {
      "id": "R1",
      "name": "Personal material is not opened by clearance",
      "text": "Personal and regulated material is level 4. Clearance to level 3, or any other level, does not open it. It is opened only by a named lawful purpose that matches the record, and only for the part of the record that purpose needs."
    },
    {
      "id": "R2",
      "name": "Read up to your clearance and no further",
      "text": "A person may read anything at or below the level they are cleared to. Anything above it is refused, and the refusal names the level rather than pretending the material is not there."
    },
    {
      "id": "R3",
      "name": "A limited role reads only what it was let in for",
      "text": "Some roles are cleared to a level but only for material marked for them. A partner contact reads partner facing material at their level and nothing else at that level, because clearance was granted for a purpose, not as a rank."
    },
    {
      "id": "R4",
      "name": "Operator only means a person runs it",
      "text": "A command marked operator only is run by a person who holds the operator role, never by an agent on its own and never by somebody who is merely cleared high enough. The clearance says what may be read. The operator flag says who may act."
    },
    {
      "id": "R5",
      "name": "Staged means defined, not running",
      "text": "A command marked staged is written and reviewed but is not run unattended. It waits on something named. Until that thing is true it refuses, and the refusal says what it is waiting for, so staged is a state with an exit rather than a shelf."
    },
    {
      "id": "R6",
      "name": "Every command stops for something",
      "text": "A command that cannot stop is not allowed to run. Every command declares the condition it halts on and hands back to a person, and that condition is part of its definition rather than a setting."
    },
    {
      "id": "R7",
      "name": "A refusal says what to do instead",
      "text": "A refusal that only says no moves the problem rather than solving it. Every refusal names the level, the rule, and the person or the route that gets the asker what they need."
    }
  ],
  "documents": [
    {
      "id": "DOC-PUB-01",
      "title": "Meridian line overview, published page",
      "level": "L0",
      "tags": [
        "published"
      ],
      "owner": "Marketing Lead",
      "line": "The product page on apexinstruments.example. Meridian Bench at $4,850, Pro at $7,900, Field Kit at $1,240, with the list prices that appear publicly.",
      "whyThisLevel": "Every figure on it is already published. Treating it as internal would mean the site was leaking, which it is not."
    },
    {
      "id": "DOC-PUB-02",
      "title": "Atlas Care plan comparison, public sheet",
      "level": "L0",
      "tags": [
        "published",
        "partner-visible"
      ],
      "owner": "Marketing Lead",
      "line": "Atlas Care at $89 per month beside Atlas Care Plus at $149 per month, with what each one covers.",
      "whyThisLevel": "Written to be handed to anybody who asks what the plans are."
    },
    {
      "id": "DOC-INT-01",
      "title": "Price change announcement, internal draft",
      "level": "L1",
      "tags": [
        "draft"
      ],
      "owner": "Marketing Lead",
      "line": "The draft of the October 1 announcement, with the two sentences about the reason still marked as unresolved.",
      "whyThisLevel": "It is a draft of something that will be public. Until it is approved, what it says is not yet what Apex says."
    },
    {
      "id": "DOC-INT-02",
      "title": "Partner onboarding process notes",
      "level": "L1",
      "tags": [
        "process",
        "partner-visible"
      ],
      "owner": "Customer Success Lead",
      "line": "How a new partner is set up, in order, with who does each step and how long it takes.",
      "whyThisLevel": "It describes how the company works and names no terms. Dull rather than sensitive."
    },
    {
      "id": "DOC-INT-03",
      "title": "Brand rules, Evergreen system",
      "level": "L1",
      "tags": [
        "process"
      ],
      "owner": "Marketing Lead",
      "line": "The colour, type, and wordmark rules every piece is checked against.",
      "whyThisLevel": "Internal because it is unfinished in public and because the checker reads it, not because anything in it is a secret."
    },
    {
      "id": "DOC-CON-01",
      "title": "Northlight Group terms, current",
      "level": "L2",
      "tags": [
        "partner-visible",
        "partner:northlight"
      ],
      "owner": "Account Manager",
      "line": "What Northlight Group pays across the Meridian line and the Atlas plans, their volume tiers, and the calibration rate they hold.",
      "whyThisLevel": "It names what one partner pays. Another partner reading it learns their own position, which is the harm."
    },
    {
      "id": "DOC-CON-02",
      "title": "Partner discount schedule, all partners",
      "level": "L2",
      "tags": [
        "commercial"
      ],
      "owner": "Account Manager",
      "line": "Every partner's tier and discount in one table, which is what makes it more sensitive than any single row in it.",
      "whyThisLevel": "It is confidential to more than one party at once. It may never go to a partner, including the ones in it."
    },
    {
      "id": "DOC-CON-03",
      "title": "Pipeline review, current quarter",
      "level": "L2",
      "tags": [
        "commercial"
      ],
      "owner": "Account Manager",
      "line": "Open opportunities by stage and value, with the named accounts.",
      "whyThisLevel": "It names what other companies are considering, which is theirs and not ours to circulate."
    },
    {
      "id": "DOC-RES-01",
      "title": "Margin model and floor, Meridian line",
      "level": "L3",
      "tags": [
        "decision"
      ],
      "owner": "COO",
      "line": "Cost per unit, the margin at each tier, and the floor below which a discount is refused.",
      "whyThisLevel": "It is the number every negotiation is decided by. A partner who reads it knows exactly how far to push."
    },
    {
      "id": "DOC-RES-02",
      "title": "October price change, unannounced decision",
      "level": "L3",
      "tags": [
        "decision"
      ],
      "owner": "COO",
      "line": "What is moving on October 1, by how much, and the two lines where the decision is not final.",
      "whyThisLevel": "It is a decision that is not made yet. Reading it early is not the same as being told it later."
    },
    {
      "id": "DOC-PER-01",
      "title": "Support case SC-4471, Northlight site",
      "level": "L4",
      "tags": [
        "support-case",
        "personal",
        "partner:northlight"
      ],
      "opensWith": [
        "support-case"
      ],
      "owner": "Customer Success Lead",
      "line": "A calibration fault reported from a Northlight Group site, with the reporter named, their direct line, and what was said on the call.",
      "whyThisLevel": "It is about an identifiable person. The fault is a business fact, the person reporting it is not."
    },
    {
      "id": "DOC-PER-02",
      "title": "Incident report IR-118, workshop",
      "level": "L4",
      "tags": [
        "incident",
        "personal",
        "regulated"
      ],
      "opensWith": [
        "incident"
      ],
      "owner": "Operations Lead",
      "line": "A workshop injury, who was hurt, what was done, and what was reported onward.",
      "whyThisLevel": "Health information about a named person, and a report Apex is obliged to keep and to hand over correctly."
    },
    {
      "id": "DOC-PER-03",
      "title": "Contact list export, partner sites",
      "level": "L4",
      "tags": [
        "personal",
        "bulk"
      ],
      "opensWith": [],
      "owner": "Customer Success Lead",
      "line": "Names, direct lines, and personal mobiles for the contacts at every partner site.",
      "whyThisLevel": "Each row is a business contact. The file is a bulk personal export, which is a different thing from any row in it."
    }
  ],
  "purposeNote": "A personal record names the purposes that open it in opensWith. An empty list means no role purpose opens it at all, which is the correct answer for a bulk export: it is reached through a written request and the records export command, not through a person's clearance."
}
