Access Controls & Admin Approval for Brain Artifact Links (run.clickup.ai)
Mostafa Shabanpour
Brain Artifacts (slides, documents, etc.) published via run.clickup.ai are currently accessible to anyone with the link, including people completely outside our workspace. Since ClickUp increasingly serves as the single source of truth for entire organizations, this is not just a missing feature — it's a critical data leak vector.
Any artifact generated from workspace data (tasks, docs, dashboards) can unintentionally expose sensitive business information: financials, strategy docs, internal metrics, client data, and more. There is currently no way to restrict visibility or require internal approval before an artifact goes live on a public URL.
Proposed Solution:
Default to private. Artifact links should only be accessible to authenticated workspace members by default.
Public publishing as an explicit opt-in. If a user wants to share an artifact externally, they should submit a "publish publicly" request.
Admin approval workflow. Workspace admins (or a designated security role) should review and approve/deny public publish requests, ensuring sensitive data doesn't leave the organization without oversight.
Visibility indicator. Clearly show whether an artifact is private (workspace-only) or public, so creators and viewers always know the exposure level.
Why this is urgent:
This isn't a nice-to-have. Organizations trusting ClickUp with their entire operational data need confidence that AI-generated outputs inherit the same permission model as the source data. Right now, every artifact created from internal data is one shared link away from being fully exposed to the internet. The more powerful Brain becomes, the higher the risk.
Log In