Skip to main content

Confidential Assessments

How to make assessments confidential

Written by Beth

Some risk assessments contain information that should not be visible to everyone in the company. Confidentiality lets you restrict who can view or edit a Task, COSHH or PUWER assessment, while still letting the rest of the company carry on as normal.

This article covers how the feature is switched on, what each confidentiality state does, how to set one, how to filter your list to show only confidential items, and answers to the questions we get most often.

Turning the feature on (company administrators)

Confidentiality is an opt-in feature, controlled by a single On/Off switch in Settings › Risk Assessments.

  • It is Off by default. While it is off, nothing changes anywhere — there are no confidentiality badges, no Confidentiality option, no "Show confidential" filter, and assessments behave exactly as they always have.

  • When an administrator switches it On, the Confidentiality access model dropdown appears underneath it, and the rest of the feature described in this article becomes available across the company.

  • Switching it back Off hides all confidentiality controls again and stops the restrictions being enforced.


Only users who can manage system settings see this switch.

The three confidentiality states

Once the feature is on, every assessment has a confidentiality state. The default for all new assessments is Not confidential.

  • Not confidential. Anyone in the company with assessment access can view and edit. This is the existing behaviour.

  • View only. Restricted to the access list. View members can see the published PDF only; Full members can also edit. Users not on the list have no access.

  • Full access. Restricted to the access list. Both the editable assessment and the published PDF are hidden from anyone not on the list. View members can see the PDF only; Full members can also edit.


Who can always reach a confidential assessment

Two roles are always permitted, regardless of state or access list:

  • The assessment owner.

  • A Super user at the location where the assessment lives. Super user override is location-scoped, so someone who is a Super user at one location is not treated as super at locations where they hold only Risk Assessor.


The company-wide access model

Settings › Risk Assessments has a single dropdown called Confidentiality access model (shown only while the feature is On). It controls how access can be granted across the company:

  • Owner only. Only the owner and Super users can reach the assessment. No additional people can be added.

  • Owner + named users. The owner picks individual users who get access.

  • Owner + role / group. The owner grants access to a whole role. Everyone who holds that role at the location gets access.


Changing this setting only affects how access can be granted going forward. Users and roles already assigned to existing confidential assessments will retain their access — update each assessment individually if you need to change who has access.

Per-user access levels

When you add someone to the access list, you choose their level:

  • View only. They can open the published file.

  • Full access. They can view and edit the assessment.


You can mix levels in a single list, and the buttons All full / All view let you set everyone at once. The list header shows live counts ("X full · Y view"). You can add both named users and roles to the same assessment — both lists are honoured, and a person who matches more than one grant gets the highest level.

Setting an assessment confidential

You can change confidentiality from two places:

  1. Inside the assessment, on the Confidentiality step of the wizard (this also appears on the PUWER assessment edit page).

  2. From the assessments list, by clicking the three-dots menu on the row and choosing Confidentiality.


Only the assessment owner and Super users see the Confidentiality option. Super users can also multi-select assessments from the Tools menu and apply a confidentiality state in bulk.

Filtering the assessments list

To see only confidential assessments:

  1. Open the assessments list.

  2. Click Advanced Filters.

  3. Switch Show confidential to On and apply.


The list will then show only assessments marked View only or Full access. The filter chip remains visible at the top so you know the view is filtered.

The Confidential badge

Confidential assessments carry a small badge next to their title. The badge wording reflects your own access:

  • Confidential (Owner) if it is yours.

  • Confidential (Admin Access) if you are a Super user.

  • Confidential (Full Access) if you have been granted full access.

  • Confidential (View Only) if you can see the published file but not edit.

  • Confidential with no qualifier means it is confidential and you do not have access.


The same viewer-aware badge appears in the list view, the tile view, the dashboard "Recent Assessments" widget, and the substance screens.

Requesting access

If you see a Confidential assessment you cannot open, the row menu shows a Request Access option. Selecting it sends an email to the assessment owner asking for access. The owner can then open the Confidentiality settings on that assessment and add you, either as View only or Full access. You receive an email when access is granted, naming who granted it.

What happens elsewhere in the system

  • Dashboard. The viewer-aware confidential badge also appears on the "Recent Assessments" widget, and opening a row from there is gated by your access level.

  • Bulk download. Confidential assessments are never included in a bulk download — even for the owner or a Super user. If your selection is a mix, the non-confidential ones download and a toast tells you which were left out. Confidential assessments can still be downloaded one at a time by people with access.

  • Substance area (assessment usage, SDS updates). Confidential assessments do not leak through these views. People without access see them listed under a substance but cannot open them; the viewer-aware badge and a view-published PDF icon (for those who can access it) are shown.

  • Archiving a user. If a user owns confidential assessments, archiving them is blocked until each one is reassigned, or a Super user chooses Archive anyway. When an assessment is reassigned, the archived owner is removed from its access list, and the new owner receives an email (in their language) listing the assessments reassigned to them.

  • History log. Every confidentiality change is recorded against the assessment, showing who made it and when — state changes, users/roles granted, revoked or moved between View and Full, reassignment on archive, and a Super user overriding the archive block. Entries read as proper sentences in every supported language and appear without needing to refresh the page.


Frequently asked questions

Does this apply to all assessment types?
Yes. Task, COSHH and PUWER assessments all support confidentiality.

Can I make an existing assessment confidential, or only new ones?
You can apply confidentiality to existing assessments as well as new ones.

Our company doesn't see any of this — why?
The feature is off by default. A company administrator needs to switch it on in Settings › Risk Assessments first.

If I change the company access model from "Named users" to "Role / group", do my existing confidential assessments break?
No. Existing access is preserved. The new model affects how you grant access from that point forward, but every row already on the access list stays in place. Update each assessment individually if you want to change who has access.

If I move an assessment from "Full access" back to "View only" or "Not confidential", is the access list deleted?
No. The access list is sticky. Lowering the state opens the assessment back up without forcing you to rebuild the list if you later raise the state again. (The one exception is Owner only mode, where re-saving clears the lists by design.)

Who can change confidentiality on an assessment?
The assessment owner and Super users. Other users will not see the Confidentiality option in the row menu, even if they otherwise have edit rights on the assessment.

Will users on the access list be notified when they are added?
Yes. Each newly-added user receives an email when access is granted. Re-saving the list without adding anyone new does not re-send emails.

What does a user see if they try to open a confidential assessment they have no access to?
A "This assessment is confidential" page, with a Request Access button (naming the owner) and a Go to Assessments button. From the assessments list they can also use Request Access to email the owner directly.

Does Super user override work everywhere?
Super user override is location-scoped. A user is treated as Super user only at the location they are currently working in. At locations where they hold only Risk Assessor, the normal rules apply.

Can I see who has access to a confidential assessment without opening it?
Open the Confidentiality option on the row menu (if you are the owner or a Super user). The access list shows every named user and every role grant, along with their View / Full level.

Does the published PDF respect confidentiality?
Yes. On a Full access assessment, both View Only and Full Access members need to be on the access list before they can open the PDF. On a View only assessment the PDF is public within the company; only editing is restricted.

If a user doesn't have edit-assessment permission and was given full access to a confidential assessment, will they be able to edit it?
No. The user's normal access/permission takes precedence over confidentiality — confidentiality can only restrict access further, never grant a permission the user doesn't already have.

Did this answer your question?