PaperThread

Trust-first AI for sensitive people work.

PaperThread is designed around permissions, approval controls, source-backed answers and a clear Thread for every action.

Security principles

Permission-aware reads

If PaperThread is not sure a user can see or do something, it does not show or do it.

Approval by default

Sensitive actions require human approval.

Recorded actions

Every action becomes part of a Thread.

Capability-aware connectors

We use what each API actually supports, no fake actions.

AI plans are validated

Deterministic services enforce permissions before any action runs.

No hidden actions

Nothing happens that isn’t in the Thread.

Role-based access

HR
Manager
Finance
Employee
Executive
Integration admin
Auditor

Sensitive action controls

Approval required by default for: payroll changes · bank detail changes · salary changes · contract changes · termination/leaver actions · employee relations · legal/tax/immigration · wellbeing-sensitive actions.

Every answer cites the source, the policy version and its freshness. Knowledge gaps are surfaced, not guessed.

Who asked · what was asked · what was checked · source used · systems touched · action plan · approval required · approver · before/after values · risk level · timestamp · export option.

AI drafts plans; deterministic services enforce permissions. No direct sensitive actions without approval. Prompt-injection protection. No employee surveillance labels.

Least-privilege scopes. Token handling per provider best practice. Permissions are visible, you always know what PaperThread can do in each system.

Enterprise readiness

  • · SSO/SCIM available for qualified customers
  • · DPA available on request
  • · Security questionnaire support
  • · Audit export
  • · Data retention settings

Security controls are being designed with SOC 2 readiness in mind. Enterprise security review available for qualified customers.

Talk to security.

Bring your questionnaire. We’ll meet you where you are.