Collaboration should not widen who can see the data

The usual way analysis gets shared, a screenshot in a chat, quietly defeats every access control. A note on collaboration that respects the permissions you set.

For Risk and compliance teams

Part of: iGaming risk and compliance

The moment a finding leaves the tool it was made in, the access controls stop applying. An analyst screenshots a chart, pastes it into a chat, and a number that was carefully scoped to the people entitled to see it is now visible to everyone in the channel. No policy was broken on purpose. The tool simply had no way to travel with its permissions, so the permissions were left behind. Most data exposure in an operator is not a breach. It is collaboration working exactly as the tools allow.

The screenshot is the leak

Sharing analysis by copying it out is convenient and quietly corrosive. Each copy strips the context, the definitions and, crucially, the access rules that governed the original. A player-level detail meant for a small team ends up in a thread, forwarded, screenshotted again, and there is no way to recall it and no record of who saw it. The problem is not that people are careless. It is that the only sharing mechanism available discards the controls, so using it defeats them by default.

Share the thing, not a picture of it

The fix is to make sharing a first-class action inside the workspace, one that respects the access model rather than escaping it. When a colleague is mentioned on a finding or sent a link to it, the system can check that they are entitled to the underlying data before showing it, so collaboration never becomes a way to widen access. The person receives the context, the evidence and the discussion, only if they were allowed to see it in the first place. The convenience of sharing is preserved; the leak is not.

Permissions per product, per role

Underneath this sits an access model granular enough to be meaningful. Roles and permissions defined per product and per category let an operator decide who sees which data, and that decision holds wherever the data appears, in a report, in a chat inside the workspace, in a shared finding. Access that is set once and respected everywhere is what makes sharing safe. Access that is set in one place and ignored the moment something is copied out is a policy that exists only on paper.

The record matters as much as the rule

For a regulated operator, being able to control access is half the requirement; being able to show it is the other half. Collaboration that stays inside the governed workspace leaves a trail: who was shown what, when, and on what basis. That record is what turns "we control access" from an assertion into something demonstrable. A screenshot in a chat leaves no such trail, which is precisely why it is a problem worth designing out.

The goal is not to make sharing harder. It is to make the easy way to share also the safe one, so that collaborating and protecting access stop being in tension.

If sharing a finding widens who can see it, the access control was never real.

Ask Bounty about your own data.

Book a 15-minute call. We scope a pilot with your team and your data.

Book a Pilot

More from Resources

All resources