← All Use Cases articles

Five Days, One Data Leak: Company Notes to Personal WhatsApp

How permitted company-data access becomes a multi-day AI disclosure risk when Obsidian notes mix work, public research, and a side job before a WhatsApp summary.

An employee can legitimately retrieve company information and still disclose it through a later personal task. When an agent combines confidential work notes, public research, and side-job notes, the resulting summary needs its own destination check—even if the original access happened days ago.

On Monday, an employee retrieves a confidential company document they are allowed to access. On Tuesday, they collect public research on the same topic. By Friday, an agent has combined those sources with notes about a personal side job and sent the summary to the employee’s personal WhatsApp.

No one had to steal a password. No malicious web page had to redirect the agent. The employee’s initial access was legitimate. The failure was losing the connection between the company information’s origin and a later decision about where a derived summary could go.

The following is an illustrative scenario, using synthetic details. Assume the organization permits this employee to retrieve the document and keep it in the approved local work area, but does not permit its confidential contents to be sent to personal messaging accounts. Obsidian and WhatsApp make the workflow concrete; the scenario does not depend on a vulnerability in either application.

Company notes, public research, and side-job notes converge in local Obsidian, then become an AI summary sent to personal WhatsApp across separate days.
Illustrative information flow. Company, public, and personal sources enter one note system; the later summary crosses into a personal destination.

The five-day flow

  1. Day 1 · Monday

    Company information arrives locally

    The employee asks the agent to fetch an internal procurement-strategy brief. The employee is authorized to access it and store a work note locally. That note contains confidential supplier terms and an unreleased pilot plan.

    Company source → local work note. Access is permitted; the information remains confidential.

  2. Day 2 · Tuesday

    Public research enters the same note system

    In a new session, the agent gathers public articles and market research about procurement software and saves them in the same local Obsidian vault. Some notes link to the company brief because they discuss the same topic.

    Public web sources → research notes. Related subject matter does not make every source public.

  3. Day 3 · Wednesday

    Side-job notes share the workspace

    The vault already holds notes for the employee’s independent consulting side job. The employee adds a possible service offering and questions for a prospective client. The agent can now find work, public, and personal material through the same note search.

    Personal side-job notes + public research + confidential work notes coexist locally.

  4. Day 4 · Thursday

    A broad summary blends the sources

    The employee asks, “Summarize what I learned this week about procurement software for my side project.” The agent retrieves relevant notes across the vault and writes a new summary, mixing public trends with the employer’s private plans.

    Mixed notes → derived summary. A new file and new wording do not erase the source restrictions.

  5. Day 5 · Friday

    The summary goes to personal WhatsApp

    In another session, the employee asks, “Send that summary to my personal WhatsApp so I can read it tonight.” If the agent sends it without checking its contents, sources, and destination, company information crosses into an unapproved personal channel.

    Derived summary → personal WhatsApp. This is the outbound boundary that must be evaluated.

One disclosure path across five days and potentially five agent sessions. Local notes and the saved summary connect the steps; the agent does not need to remember the original conversation.

Authorized access is only the first decision

The employee’s permission to read the internal brief answers who may access that source. It does not settle every subsequent use, combination, or destination. In this scenario, local work access is permitted, while sending confidential content to a personal messaging account is outside the organization’s policy.

That distinction should remain visible throughout the workflow. Blocking Monday’s legitimate retrieval would interrupt useful work without explaining the later problem. Allowing Friday’s send simply because the employee could read the original document makes the opposite mistake: it treats read access as unrestricted redistribution authority.

Likewise, a side job is not by itself evidence of misconduct, and mixed storage is not proof that disclosure occurred. The relevant questions are which company information actually entered the personal output and whether that output was permitted at its destination.

Why shared notes make the connection easy to miss

Obsidian stores notes as plain-text Markdown files in a local folder called a vault. That makes the local files a possible input to an agent with filesystem access, independently of the original conversations that created them. Obsidian’s documentation explains its storage model.

A topic-based search can return an internal strategy note, a public article, and a consulting outline together. All three may be relevant to the question. Relevance does not establish that they are equally appropriate for a personal task. If the agent receives the whole vault as undifferentiated context, it may synthesize across those boundaries without an obvious change in tools or accounts.

The public research need not contain any prompt injection. It can be entirely benign and still help the agent connect the employer’s private plans to the employee’s side-project question. The risk comes from the combination of source access, broad retrieval, synthesis, and an outbound action.

A summary can disclose a secret without copying it

Imagine the company note says that a supplier has agreed to a confidential pricing concession and that a pilot will begin next quarter. The summary might omit the supplier’s name yet state that unusually favorable terms are already available and a specific pilot is imminent. The wording has changed, but the underlying private information can remain.

Removing a “confidential” heading or an exact document title is therefore not enough. A destination decision should consider the actual output together with evidence about the sources that informed it. Conversely, reading a confidential note does not prove that every sentence in the final summary is sensitive; the system needs a way to distinguish evidence of disclosure from uncertainty.

If the available evidence cannot establish that a personal summary is appropriate to share, preserve the draft and offer a useful alternative: regenerate from an explicitly selected set of public and personal notes, then check the regenerated output. Simply relabeling the existing summary as personal does not resolve its mixed origins.

The security context has to outlive the chat

On Friday, the agent may see only the saved summary and a send request. Monday’s corporate session may be closed, and Thursday’s synthesis may have run in a different process. Looking only at the current prompt misses the history that gives the message its sensitivity.

The useful evidence chain links the original source to the local note, the note versions used during synthesis, the resulting summary version, and the proposed message destination. Renaming a file or restarting an agent should not be treated as a fresh grant of authority. An edit after review also matters: permission for one summary should not automatically cover a later version with an added paragraph.

This is a practical Agent Detection and Response (ADR) problem. Detection should connect the attempted send with relevant earlier activity. Response should address the consequential action while explaining the reason to the employee. Recording an alert after the message was delivered provides visibility, but it does not demonstrate prevention.

Three points where control can preserve useful work

  1. When storing and retrieving: retain the company source’s identity and sensitivity context where supported. Limit personal-task retrieval to appropriate notes rather than treating the whole vault as one permission domain. Separate folders or vaults help organization; actual access restrictions must support that separation.
  2. When creating the summary: keep evidence of the inputs and the derived artifact. If the request is for a personal purpose, select suitable sources before synthesis. Check whether the output still contains confidential facts or implications.
  3. Before sending: evaluate the exact message, attachments, sending account, and destination under the applicable policy. A send-to-self request still transfers data to another environment. Give the employee a specific explanation and an option such as a public-source-only summary.

A useful explanation would be: “This draft includes information from the internal procurement brief. Personal WhatsApp is not an approved destination for that information. I can create a new summary using only the selected public research and your personal notes.” The explanation should identify enough evidence to resolve the problem without unnecessarily reproducing the secret in an alert.

What to evaluate with Gensee Crate Enterprise

Gensee Crate Enterprise brings endpoint and cloud agent control together with central policy, activity logs, and investigation. This scenario gives those capabilities a concrete evaluation target: connect permitted company-data access with later note retrieval, generated content, and a proposed personal export.

Test the actual execution path. A local file operation, note-search tool, generated script, and messaging action may expose different control points. The evaluation should establish which source relationships are captured, which survive separate sessions, and where the outbound effect can be governed. The scenario is not a claim of universal Obsidian or WhatsApp integration coverage.

Use synthetic company facts and run each step on a different day or in separate restarted sessions. Include a public-only summary that should pass, a mixed summary containing a paraphrased company fact, a renamed note, and an edited draft after review. Verify both whether the message actually reached its destination and whether legitimate research and personal work remained possible.

The acceptance criterion is continuity: the organization can permit the initial access without losing control of a later disclosure. A local rollback cannot recall a message that has already left the approved environment.