Briefi
Product12 June 2026 · 7 min read

Your workspace is not a flat trust zone

Briefi now ships meeting visibility levels, private mailboxes, teams, a database-enforced viewer role, and an audit log API. Here's why we rebuilt the access model before the team features, not after.

  • #security
  • #teams
  • #privacy
  • #enterprise
  • #access-control
Chidi Okechukwu — Founder, Briefi.sh
Chidi OkechukwuFounder · Briefi.sh
A team working at separate desks in a dim office, each screen its own pool of light

Most meeting tools treat a workspace as one big room: if you're in, you see everything. That's fine for a founder working alone, and it quietly becomes a liability the day the second, third, and tenth person join. A sales rep's pipeline review, a manager's 1:1 notes, a hiring debrief, a patient consult — the moment real teams arrive, 'everyone sees everything' stops being collaboration and starts being a privacy incident with a delay timer.

We just shipped the batch of changes that fixes this in Briefi, end to end. This post is the plain-language tour of what changed and why each piece exists.

By the time bolted-on controls arrive, a year of data has already been visible to the wrong people.

Meetings now have visibility levels

Every meeting is one of three things: visible to the workspace (the default — your team sells together, sees together), visible to a team you pick, or private to you. The control is a single pill on the Prepare page, and only the meeting's owner can change it.

Two design decisions matter here. First, sensitive meeting types — 1:1s, interviews, patient consults — default to private automatically. You shouldn't have to remember to hide a performance review; the system should assume it. Second, workspace admins get no override. A private meeting is invisible to everyone but its owner, including the people who manage the workspace. Anything less and 'private' is a label, not a promise.

Your inbox is yours unless you say otherwise

Briefi can pull a mailbox into a workspace so the whole loop — classification, reply drafts, follow-up sweeps — runs over it. Previously, connecting a mailbox meant your teammates could see its threads. Now a mailbox you connect is private to you by default. Sharing it with the workspace is a deliberate toggle in Settings, built for genuinely shared inboxes like sales@ — and only the person who connected the mailbox can flip it.

Teams, for sharing with just the right people

Workspaces now contain teams: lightweight groups you create on the Team page. Their first job is powering that middle visibility level — share a meeting with the AU sales team without broadcasting it to the whole company. Owners and admins also get a manager overview: per-member meeting, brief, follow-up, and pipeline counts over the last 30 days. Private meetings show up in those counts as numbers only; the content stays sealed.

A viewer role that actually means read-only

Lots of tools have a 'viewer' role that's enforced by hiding buttons. Ours is enforced by the database: a viewer physically cannot create or edit meetings, deals, or contacts, generate AI content, send replies, push to a CRM, or connect a mailbox. The same rule is checked again at the API layer. If you give an investor or a contractor viewer access, read-only is a guarantee, not a theme.

Offboarding that takes effect now, not at next login

If you provision Briefi from your identity provider, deprovisioning someone now revokes their data access in the same minute — not whenever their session happens to expire. And your IdP groups can drive Briefi roles: map 'Briefi Admins' to admin and 'Briefi Viewers' to viewer once, and provisioning gets the role right on the way in. The owner role is deliberately not mappable; ownership changes stay a human decision.

An audit trail you can ship to your SIEM

Workspace owners and admins already had an in-app audit feed. Enterprise plans can now pull the same trail programmatically — team and role changes, integration events, API keys, billing actions, and content access: share links opened, recordings played, visibility changes. It's built for ingestion into whatever your security team already watches.

Why this order

It would have been easy to ship team features first and bolt privacy on later. We did it the other way around because retrofitting access control is where most products go wrong — by the time the controls arrive, a year of data has already been visible to the wrong people. The boring sequencing is the trustworthy one: ownership first, visibility second, collaboration third.

If you're evaluating Briefi for a team, the security page has the full posture, the enterprise page covers SSO, SCIM and the audit API, and pricing shows where each capability lands. And if you're a workspace of one today — nothing changes for you, except that the day you hire, the locks are already on the doors.

Chidi Okechukwu — Founder, Briefi.sh
Chidi OkechukwuFounder · Briefi.sh

Founder of Briefi.sh. Works across five workspaces — a consultancy, a SaaS, and a handful of ventures and board roles. Builds Briefi for himself first; ships the meeting loop he wished existed across all the workspaces he works in.

Comments are coming. For now, reach out via hello@briefi.sh or share your reaction on LinkedIn.

Ready when you are

Your next meeting deserves a brief.

Connect Google Calendar, see your first brief in 90 seconds. No card on file. Cancel from Billing whenever.