Skip to content

Information Classification

Goal

Help authors place information where the intended audience can use it without exposing people, chapters, or the National organization unnecessarily. This guide assumes good intent: classification mistakes are usually fixed by moving, summarizing, or removing content—not by blaming the author.

When to use this

Use this page before creating, copying, or publishing KTP content. Recheck the classification when a draft gains names, contact information, financial details, partner information, access links, member data, or material from a private conversation.

The three tiers are:

Tier Who can access it Intended use
Public documentation Anyone Approved information and reusable guidance that is safe to share outside KTP
Chapter-private systems Authorized members of one chapter Local operations, member coordination, and chapter records that do not need National-wide access
National-restricted systems Authorized National leaders and relevant portfolio owners Cross-chapter records, sensitive escalations, national operations, and restricted partner or governance information

Classification describes the minimum protection needed. A chapter can still limit access more narrowly when appropriate.

Classification matrix

Content type Default tier Guidance
Published chapter bio, founding date, and approved website Public documentation Keep the information current and link to an authoritative public source when possible.
Reusable event guide or public-safe semester retrospective Public documentation Use attendance and cost ranges; remove member and partner-sensitive details.
Approved National history, public policy, or EBoard archive Public documentation Separate completed facts from proposals and obtain approval for personal attribution.
Public outreach templates and approved sponsorship packet Public documentation Remove personal contacts, confidential terms, and organization-specific negotiation notes.
Chapter meeting agendas, operating calendar, and room plans Chapter-private systems Publish only a generalized lesson if it would help other chapters.
Local member roster, attendance records, and officer working contacts Chapter-private systems Limit access to people who need the records for their chapter role.
Recruitment applications, evaluations, and selection discussions Chapter-private systems Never copy applicant-specific material into public documentation.
Detailed chapter budget, dues tracking, reimbursements, or local sponsor notes Chapter-private systems Public pages may use approved ranges or generalized budgeting lessons.
Chapter constitution draft and unfinished EBoard planning Chapter-private systems Publish only the final version if the chapter and Nationals approve public release.
National chapter-status tracker and cross-chapter reporting National-restricted systems Give access only to the National portfolios responsible for the work.
National member or alumni master data National-restricted systems Use an approved system with defined ownership, retention, and access controls.
KTP Life App architecture, generic setup, team roles, beta status, and public release notes Public documentation Use synthetic examples and omit private service identifiers, invitation links, credentials, member records, and sensitive security details.
KTP Life App production configuration, administrators, signing, recovery, logs, incidents, schemas, and authorization policies National-restricted systems Store with the responsible technical owners; publish only the minimum safe operational summary.
Semester compliance submissions, member audit files, resumes, and cross-chapter reporting National-restricted systems The public site may explain the process; completed files and restricted submission links must remain limited to authorized reviewers.
Chapter financial audit workbooks, transaction ledgers, and receipts submitted to Nationals National-restricted systems Working records may begin chapter-private, but the cross-chapter compliance submission belongs in the approved National-restricted system.
Draft National policies, legal review, or governance deliberations National-restricted systems Publish the approved outcome and implementation guidance when ready.
National sponsor contracts, pricing, negotiation history, or private contacts National-restricted systems A public sponsorship packet can remain public; private terms cannot.
Conduct reports, sensitive escalations, or incident records National-restricted systems A local matter may begin chapter-private, but follow current escalation policy promptly.
Passwords, recovery codes, API keys, or account credentials Restricted credential manager Never place secrets in documentation. Use the approved chapter or National credential system matching the account's ownership.

Examples by tier

Public documentation

  • A chapter's founding date, Greek designation, approved bio, and website
  • A semester summary using membership and attendance ranges
  • A technical workshop guide with reusable setup steps and no participant data
  • The approved National EBoard roster and verified board-level contributions
  • A public corporate outreach email template with role-based placeholders
  • A downloadable sponsorship packet already approved for public distribution
  • A KTP Life App architecture diagram showing service categories without production identifiers

Chapter-private systems

  • The local membership roster and chapter working directory
  • Recruitment applications, interview notes, voting records, and evaluation rubrics with responses
  • Detailed event plans containing member assignments, private venue instructions, or internal links
  • The chapter's line-item budget, dues status, reimbursement records, and banking workflow
  • EBoard meeting notes, unfinished proposals, and officer transition documents
  • Local company-contact history that has not been approved for publication

National-restricted systems

  • A master chapter-status or compliance tracker
  • Semester member audits containing names, email addresses, majors, and resumes
  • Chapter financial audit packages submitted to National Finance
  • Colony-development records and private charter-readiness forms
  • Draft National policies and notes from restricted governance discussions
  • National sponsor agreements, pricing, negotiation notes, and private partner contacts
  • Cross-chapter incident reports or sensitive escalations
  • National system inventories containing private administrators, access arrangements, or recovery ownership
  • KTP Life App TestFlight tester rosters, invitation links, production logs, signing records, and incident evidence

Decision tree: When I'm creating content, where should it live?

Start with the content in its current form—not the version you hope to publish later.

  1. Would it still be safe and appropriate if a prospective member, university employee, company contact, search engine, and the general public saw it?
  2. Yes: Continue to question 2.
  3. No or unsure: Continue to question 3.
  4. Is it approved, accurate, useful outside one private team, and free of personal, confidential, credential, applicant, financial-account, or restricted partner information?
  5. Yes: Put it in public documentation.
  6. No: Keep the draft in the appropriate private tier until it is approved or sanitized.
  7. Does the content concern only one chapter's members, applicants, finances, planning, or local relationships?
  8. Yes: Put it in a chapter-private system with access limited to the roles that need it.
  9. No or it affects multiple chapters: Continue to question 4.
  10. Does it involve National operations, cross-chapter data, policy drafts, legal or conduct matters, colony records, national partnerships, or sensitive escalations?
  11. Yes: Put it in a National-restricted system limited to the responsible portfolio owners.
  12. Unsure: Pause publication and follow the escalation path below.
  13. Can a reusable public lesson be separated from the sensitive record?
  14. Yes: Keep the source record private and publish a generalized, approved version.
  15. No: Keep it private. Not every useful record needs a public copy.

Steps for authors

  1. Identify the people, chapter, partner, financial, access, and governance information in the draft.
  2. Use the matrix and decision tree to select the default tier.
  3. Remove information the intended audience does not need.
  4. Store the source in the approved system for that tier.
  5. Ask the appropriate owner to review personal attribution, partner details, or policy statements.
  6. Recheck classification before merging, sharing, or changing access permissions.

Common mistakes and how to fix them

Common mistake Practical fix
Assuming a repository named “internal docs” is private Check the deployed site and repository visibility. Treat this repository as public unless access controls prove otherwise.
Publishing a personal email because the person already uses it for KTP Replace it with an approved role-based channel or omit contact information.
Copying a private meeting note into a useful public guide Extract the reusable process, remove people and sensitive context, and leave the original note private.
Linking to a private document from a public page Remove the link. Describe the resource by role or category and provide it through the appropriate private system.
Publishing an exact budget, dues ledger, or sponsor price Use an approved cost band or general budgeting lesson; keep detailed records private.
Treating a draft policy as a current requirement Keep the draft National-restricted and publish only the approved policy with an effective date.
Putting credentials in a handoff document Rotate any exposed secret and move credentials to the approved credential manager. Keep only ownership and recovery responsibilities in documentation.
Restricting a generic guide because its source was private Create a new public-safe version containing only reusable, approved information. The source can remain private.
Keeping duplicate copies in several tiers Choose one authoritative source. Link or summarize downward only when the receiving tier is appropriate.

If something is already in the wrong place, reduce access first, then contact the appropriate owner and create a sanitized replacement if useful. Fast correction matters more than fault.

What worked

The safest documentation pattern is private source, public lesson: keep operational records in the tier where the work happens, then publish only the approved guidance another chapter or reader can reuse.

Short labels also help reviewers. In drafts and merge requests, state the intended tier and audience explicitly—for example, Public — chapter contributors and prospective colonies.

What to adapt

Each chapter may use different approved tools, and National portfolios may apply narrower access within the restricted tier. Tool choice can vary; the audience and sensitivity rules should remain consistent.

If school policy, law, a contract, or an approved KTP policy requires stronger protection than this guide, follow the stronger requirement.

Escalation path if unsure

  1. Pause sharing or merging. Keep the draft in the narrowest reasonable approved location while it is reviewed.
  2. Ask the chapter documentation owner or President when the information concerns one chapter's operations.
  3. Ask the relevant National portfolio owner when it affects multiple chapters, colonies, National policy, technology, finance, alumni, outreach, or partnerships.
  4. Escalate promptly to National leadership for conduct, legal, safety, contractual, privacy, or accidental-publication concerns.
  5. Record the classification decision in the merge request or private source so the next author understands the boundary.

When asking for help, share only the minimum information needed to classify the content. You can describe the type of information without pasting the sensitive material into a wider channel.

Public-content review

  • [ ] The intended audience and tier are identified
  • [ ] Personal and confidential information is removed or stored privately
  • [ ] Applicant, member, alumni, financial, and partner details are appropriately protected
  • [ ] Private systems are referenced only by role or category
  • [ ] Credentials and recovery information are not present
  • [ ] Draft policies are not described as current requirements
  • [ ] Public facts and individual contributions are approved and verifiable
  • [ ] A private source was summarized rather than copied when only the lesson is public