Docs

Documentation

Guardrails: what Jaha will and won’t say

An AI that speaks in meetings needs judgment, not just knowledge. Jaha asks two independent questions before a word leaves its mouth: who is listening, and who asked. This page explains both, and what happens when the answer is “no”.

Two questions, not one

Most tools treat meeting privacy as one dial. Jaha treats it as two, because the people involved are different: the AUDIENCE is everyone who will hear the answer; the ASKER is the one voice that requested it. A colleague allowed to hear an answer is not automatically allowed to invoke the document behind it — and a client meeting can be safe for one question and wrong for the next.

Who is listening — discretion

Every meeting has a discretion policy: open, guarded, or private — set by the host or chosen automatically from who is in the room. Every source carries a sharing class: for the room, internal, or restricted. When guests are present, internal material stops being spoken aloud; restricted material never is.

Some answers are not refused but redirected: a whisper delivers the answer privately to the person entitled to it, instead of broadcasting it to the room.

Who asked — answer scopes

Every document and connector also carries an answer scope — who may draw on it at all: anyone in the meeting, your organisation, the owner’s team, or only the owner. “Only answer from my document when I ask” is a rule Jaha enforces on the spoken word, live, per question.

“Team” means something real: the owner, their manager, their reports, and anyone sharing a team in your directory — resolved from the same org data the rest of the product runs on.

Sources that predate ownership tracking cannot silently enforce owner or team scope — the product asks someone to claim the source first, rather than letting an unenforceable rule pretend to protect it.

How Jaha knows who spoke

In a Teams call, speech is attributed through Microsoft’s own identity — the same Azure AD identity your directory runs on. Chat questions carry it too. Only when no identity is available does Jaha fall back to an exact, unique directory name match — and if two people share the name, it matches neither.

Unknown fails closed. A voice Jaha cannot attribute gets unrestricted material only — nobody borrows a scope by being unrecognisable.

When it says no

A refusal never leaks what it is refusing. In the room, Jaha says it has nothing it can share — it does not name the document it is protecting or hint at the answer. The question is still answered from whatever sources the asker is entitled to.

The audit trail

Everything held back is recorded with its reason — which source, which rule, which asker — and shown to the host in the meeting’s discretion panel. Scope changes, ownership claims and deliveries are all audit-logged. A silent filter is indistinguishable from a broken product; Jaha’s guardrails leave receipts.

Beneath all of this: every organisation is isolated, sessions are hashed, retention is configurable per plan, and consent can be revoked in your Microsoft admin centre at any time.

Did this page help?