Trust-first AI for sensitive people work.
PaperThread is designed around permissions, approval controls, source-backed answers and a clear Thread for every action.
Security principles
If PaperThread is not sure a user can see or do something, it does not show or do it.
Sensitive actions require human approval.
Every action becomes part of a Thread.
We use what each API actually supports, no fake actions.
Deterministic services enforce permissions before any action runs.
Nothing happens that isn’t in the Thread.
Role-based access
Sensitive action controls
Approval required by default for: payroll changes · bank detail changes · salary changes · contract changes · termination/leaver actions · employee relations · legal/tax/immigration · wellbeing-sensitive actions.
Every answer cites the source, the policy version and its freshness. Knowledge gaps are surfaced, not guessed.
Who asked · what was asked · what was checked · source used · systems touched · action plan · approval required · approver · before/after values · risk level · timestamp · export option.
AI drafts plans; deterministic services enforce permissions. No direct sensitive actions without approval. Prompt-injection protection. No employee surveillance labels.
Least-privilege scopes. Token handling per provider best practice. Permissions are visible, you always know what PaperThread can do in each system.
Enterprise readiness
- · SSO/SCIM available for qualified customers
- · DPA available on request
- · Security questionnaire support
- · Audit export
- · Data retention settings
Security controls are being designed with SOC 2 readiness in mind. Enterprise security review available for qualified customers.
Continue your security review
Visit the Trust Centre
Review security, privacy, AI governance and operational practices.
Explore this page →See the audit trail in action
Follow checks, permissions, approvals and outcomes in one Thread.
Explore this page →Explore Enterprise controls
See PaperThread for complex systems, roles and approval paths.
Explore this page →