Who can see project reports?

Project reporting follows the permission domains an administrator grants, and the domains are separate: projects and boards, project health, and meetings are distinct grants. The AI risk signals on a meeting are labelled admin only in the product itself. Reporting access is assembled from several grants rather than given as one.

Splitting project access into several domains rather than one is what makes a delivery lead workable as a role.

Somebody running projects needs boards, tasks and the project record. Whether they should read an automatically generated risk assessment of a client call is a separate decision, and a single grant would decide both at once.

So the signals carry their own label. The product marks them as an admin-only surface, and they are stamped with the prompt version and model that produced them.

That stamp is a form of honesty worth noticing. A risk verdict is a model's output, not a finding, and the record says which prompt version generated it.

There is one guard here that goes beyond permissions, and it is the most interesting thing on this page. Meeting digests can post to a Slack channel chosen in the settings, and the setting refuses a channel name ending in a client's name.

The reason is specific. A confidential risk assessment posted into a shared client channel would be a serious disclosure, and a permission model does not catch that mistake. A refused channel name does.

Utilisation reporting works differently again. Hours by project and department can be sent to Slack from the reports screen, and anything sent to a channel is visible to everyone in that channel regardless of any role.

Access rules are enforced in the database, not only on the screen, and every grant or removal is written to the activity log with its old and new value.

Check where a report is being posted before worrying about who holds which permission. A Slack channel has its own membership, and that membership is what decides who reads the report.

Related questions

Are the AI risk signals visible to a project team?

No. The product labels them an admin-only surface. They carry the prompt version and model that generated them, because a verdict from a model is not a finding.

Can utilisation reports go to Slack?

Yes, from the reports screen. Anything posted to a channel is readable by everyone in that channel, whatever their role carries.

Why would a Slack channel name be refused?

A guard refuses a channel named after a client for meeting digests, so confidential signals cannot be posted into a shared client channel by mistake.