Stored Documents as AI Input
A stored document can be handed to an AI model as input: a custom feature might ask a model to check a submission pack against a checklist, and an MCP client can search documents and read their text. Sending a document to a model is treated as an export, not a read, so the same rules that stop a document leaving the system in other ways apply here too, and every hand-over is logged.
Where to find it
Architect Panel → Security:
- Classification Levels — Allow Export: whether documents at that level may be sent out at all
- Document Access — who was given a document, who was refused, and why
Architect Panel → Automation:
- Tasks — Document Text Extraction, which produces the text most providers need
Architect Panel → Configuration:
- AI Settings — Largest PDF sent as a document (bytes), in Prices, limits and retries
Who uses it
- A custom app's AI features, which name a document and let the platform fetch and check it.
- MCP clients, through the documents tools' search and get-text, which apply the same gate.
No standard platform screen sends stored documents to a model today. The rules below are what protects you when a custom feature or a connected assistant does.
The rules a document must pass
- The person may read it, through record links, grants, ownership and their clearance.
- Not only through a read-only grant. A document someone can reach only by a read-only grant is never sent.
- Its classification allows export. A level with Allow Export off means its documents never go to a model.
- Same tenant. Another tenant's document is treated as if it did not exist.
- Redactions are honoured. A version with a live redaction never sends its file; it goes as text with every redacted wording removed, and is refused if the platform cannot show the wording is gone.
A refusal stops the request and names the reason, never the content. Each document sent, and each refused, is a row in the document access log for exactly the version concerned.
PDF or text
- Claude receives a PDF as the PDF, up to Largest PDF sent as a document (bytes) (14 MB by default). A larger PDF goes as its extracted text, with a note.
- GPT-6 on Bedrock and the prompt-mode providers receive the extracted text only, without citations.
- Office files and plain text go as text. A small file with no extracted text yet is extracted on the spot; a larger one is queued and refused until extraction has run.
- Images are never read from a document here; scanned images are read by the separate OCR route.
Text is never cut short: a document too long to send is refused, because a model shown half a document answers confidently about that half.
Making documents ready for AI
- In Tasks, switch on Document Text Extraction. It ships disabled; until it runs, nothing queued is extracted and only Claude can be sent a PDF.
- Review Allow Export on each Classification Level, so that nothing which must stay in the building can be sent.
- For attachments uploaded through ordinary file fields, turn them into documents first; see Bringing Documents In.
- After the first real use, open Document Access for the period and check the hand-overs and refusals are what you expect.
Citations
When a feature asks Claude to cite its sources, each claim in the answer can point to the document and page it came from. Whether those citations are shown to people depends on the feature that asked; no standard screen displays them today.
What goes wrong, and how to tell
- A feature reports a document was refused: Document Access shows the refusal and its reason, such as the classification or a read-only grant.
- "not extracted": the document has no text yet. Check Document Text Extraction is switched on.
- "too large": the PDF or text is over the limit. Send fewer documents, or a smaller one.
- A redacted document refused: its redaction could not be shown removed from the text, or records only a marked area. That is deliberate.
Worked example
A housing team's custom feature asks a model to check each tenancy pack against a checklist. Most packs go through; one is refused. Document Access shows the refusal: the pack's medical letter is classified at a level with Allow Export off. The team leaves the rule in place, and the checklist for that pack is completed by hand.
Recommendations
- Set Allow Export deliberately on every classification level before any AI feature goes live.
- Switch on Document Text Extraction wherever documents may reach a non-Claude model.
- Read Document Access after go-live; it is the record of what left.
- Prefer Claude for document work, where PDFs and page citations are supported.