Kythene lets an author keep an item private to themselves, and lets a project be private to named members. That's necessary - half-formed work and sensitive projects both need somewhere to live.
It also creates an obvious problem for whoever is accountable for the workspace: content exists that they can't see. Oversight resolves it without quietly making "private" a lie.
What it is
Owners and admins can review the workspace's hidden content - author-private items and private-project collections - through one dedicated surface in the workspace settings.
The constraints are the point:
- It's the only route. Hidden content never appears through the normal timeline, recall, search or MCP for someone who isn't entitled to it. There's no flag that quietly widens ordinary reads.
- Every access is audit-logged, by the core rather than by the UI, so the record doesn't depend on which surface was used.
- It's human-only. Oversight is not in the MCP toolset. An instance cannot read hidden content on an admin's behalf, deliberately - an audit trail of "an agent read 400 private items in 90 seconds" is not a governance story anybody wants.
Why it works this way
Two failure modes to avoid. One is a system where an administrator can see everything invisibly, which makes "private" a lie and stops people using it for anything real. The other is a system where an administrator can see nothing, which no regulated organisation will adopt and which makes offboarding impossible.
The middle is: they can look, through a named door, and the fact that they looked is recorded. Everyone can see the rules. Nobody is surprised.
Tell people this is how it works. It's a better position than either alternative, and it only holds if it isn't a secret.
What people should still know
- Private means private from colleagues, not from the organisation. Say so in your workspace guide.
- Secrets and credentials don't belong in Kythene at all, private or otherwise.
- A workspace export also includes private content, for the same reason - it's a governance surface, restricted to owners and admins, and audit-logged.