The account review includes your team, a new agency partner, and the customer. Someone asks why the delivery date moved. The answer exists in a manager's private notes: a specialist was reassigned after raising a health concern.
The fact is current. It is relevant. The meeting host is allowed to see it. It still should not be brought into this room.
That distinction is becoming more important as workplace AI gets better at connecting information across applications. Google announced new agentic Workspace capabilities on September 9, 2026, that can gather context from selected files, emails, and chat threads, then use it to create documents, spreadsheets, presentations, and messages. The product promise is compelling: less hunting through tabs, more work completed in place. Google Workspace announcement
But meetings create a special context problem. The set of information one person may access can be much larger than the set that belongs in front of every attendee. Permission answers, "Can this user retrieve the source?" A meeting also needs to ask, "Should this information enter this conversation, for this purpose, with these people?"
That second question deserves an explicit context boundary.
More context is not automatically better context
Connected AI is often evaluated by retrieval quality. Did it find the right project plan? Did it notice the customer email that contradicted the forecast? Did it bring the useful fact into view before the decision?
Those are good tests, but they are incomplete. A source can be accurate, timely, and semantically relevant while being socially or operationally out of bounds.
Consider a few ordinary mismatches:
- A hiring discussion pulls from interview feedback while a candidate is present.
- A customer call surfaces an internal discount ceiling before negotiation is complete.
- A vendor review includes candid performance notes written for the internal team.
- A project meeting retrieves an old legal discussion that is privileged or restricted.
- A broad status call exposes an individual's medical, compensation, or performance information to people who do not need it.
AI changes the speed and scale. A polished answer can combine fragments from several sources before anyone pauses to inspect what crossed the boundary.
Google's administrator guidance for Workspace Intelligence says the system respects user-level content access and allows administrators to enable or disable searchable services such as Gmail, Drive, Calendar, and Chat. Those controls matter. They define what the system may search for a user. They do not eliminate the need for meeting-level judgment about the intended audience of an answer. Google Workspace administrator guidance
Set five fields before the meeting starts
A context boundary can fit beside the agenda. It does not need to become a policy document. For meetings where connected context may affect a consequential decision, define five fields.
Purpose: What decision, diagnosis, or outcome is this meeting meant to produce?
Audience: Who is present, which organizations do they represent, and could anyone join late or receive the recording afterward?
Included sources: Which systems or folders are appropriate to search for this purpose? Name the narrowest useful set, such as the customer project folder, approved CRM record, and current support tickets.
Excluded categories: What must stay out even if it appears relevant? Common examples include personnel matters, legal advice, unrelated customer data, credentials, private messages, compensation, and unannounced strategy.
Disclosure rule: When a useful source falls outside the shared boundary, what should happen? The copilot might give the facilitator a private prompt, identify an approved owner to answer, or state that a restricted dependency needs separate verification.

For the account review, the boundary could say: "Use the signed scope, current project plan, customer emails in the account folder, and open delivery tickets. Exclude personnel, health, compensation, and internal performance notes. If a restricted staffing issue affects the timeline, privately prompt the delivery lead to provide an audience-safe explanation."
That instruction does not hide the operational truth. The customer still needs an honest answer about the schedule. It separates the decision-relevant fact, specialist capacity changed, from personal detail the audience does not need.
Use audience labels, not one giant context switch
Turning all connected sources on or off is a crude solution. Meetings usually need several levels of visibility.
Use four simple labels:
Shared: The source and its relevant content can be shown to everyone in the meeting and included in the recap.
Facilitator-only: The source may support a private nudge, but its contents should not be displayed, quoted, or summarized to the room without human judgment.
Restricted: The source requires a designated owner, such as HR, legal, security, or the account lead, to decide what can be disclosed.
Out of scope: The source may be accessible but has no legitimate role in this meeting.
These labels are not a replacement for access controls, data-loss prevention, retention rules, or professional obligations. They are a conversational layer on top of them. The model comes from a familiar security principle. NIST defines least privilege as restricting users or processes to the minimum access necessary to complete assigned tasks. A meeting can apply the same idea to retrieval: use the minimum context necessary to reach the purpose. NIST glossary
The benefit is not only protection. Narrower context can make assistance more useful. The copilot has fewer irrelevant sources to reconcile, participants can understand where an answer came from, and the recap is less likely to carry unrelated detail into a persistent record.
When the audience changes, reset the boundary
Meeting invitations are not stable containers. A customer forwards the link to a consultant. An executive joins for the last ten minutes. The internal debrief starts before the external guest has disconnected. The recording is later shared with a wider group.
Treat a material audience change as a context reset.
The facilitator can say, "We have an external participant joining, so we are switching to the shared customer sources." If the meeting moves into an internal segment, confirm that guests have left before expanding the source set. When the recording or recap will have a broader audience than the live call, apply the broader boundary to what gets preserved.
This is especially important for persistent meeting memory. A sensitive detail mentioned once can become searchable context for later conversations. The useful question is not merely whether the original disclosure was permitted. It is whether the detail should keep traveling.
Give a bounded answer instead of a silent refusal
A tight context boundary should not make the copilot useless. When it finds something important outside the shared set, the system can still help without exposing the source.
Useful responses include:
- "A restricted staffing dependency may affect this date. Ask the delivery lead to confirm an audience-safe status."
- "The available shared sources do not explain the change. I can search the approved project folder more narrowly."
- "This question depends on legal guidance that is not in the meeting's shared context. Record it for the legal owner."
- "I found a newer source, but it is marked facilitator-only. Review privately before using it."
Each response preserves momentum. It tells the room what kind of gap exists and who can resolve it, without converting private information into public meeting content.
The same discipline should shape the recap. Record the operational conclusion and next step, not the sensitive path used to reach them. "Delivery lead will confirm the revised staffing plan by Tuesday" may be enough. The private note does not need to become part of the meeting's permanent memory.
Put the boundary where people can challenge it
The context boundary should be visible to the facilitator and easy to revise. Participants should know when connected AI is in use, what kinds of sources it can draw from, and how to flag a source or statement that does not belong.
Do not ask people to trust a vague promise that the system will use "relevant context." Relevance is the very thing being negotiated. A finance leader, customer, recruiter, engineer, and lawyer may all draw the line differently because they carry different duties and understand different consequences.
The useful habit is a brief check before retrieval becomes conversation: What are we here to decide? Who is in the room? Which sources belong? What must stay out? What should the copilot do when a restricted fact matters?
Caspi supports live recap, suggested questions, contextual chat, proactive flags from connected tools, post-call action items, and persistent meeting memory. A clear context boundary gives those capabilities a meeting-specific rule for relevance: surface what helps this audience do the work, and keep everything else on the correct side of the door.