Skip to content

Glossary

File upload

Attaching a file is where a personal habit quietly becomes an organisational fact, because it is one click and it is the first moment your material leaves your control.

In plain terms

Attaching a document, spreadsheet or image so the thing can work from it. Mechanically it is one click. It is also the first moment your material goes somewhere you do not control, and the answers about what happens next differ by which plan you are on rather than by which product you chose.

01

Why it matters

Because it is the smallest possible action with a genuinely organisational consequence. Nobody convenes a meeting about attaching a file, and the contract in front of you, the export of customer records or the unreleased results all leave the building the same way, which is why this rather than anything grander is where most policies are actually breached.

02

How it works

The file is read and converted into something the system can work with, and that conversion is where quality is decided. A clean text document survives intact; a scanned page, a complex table or a multi-column layout may arrive damaged in ways that produce confidently wrong answers rather than obvious failures.

Where it goes and how long it stays are policy questions with different answers on different plans. Consumer tiers and business tiers of the same product frequently differ on whether material may be used to improve the service and how long it is kept, which is why product-level reassurance is close to meaningless without the plan attached.

Size and shape limits bite sooner than people expect. Long documents may be truncated or summarised rather than fully considered, and this frequently happens without a warning, so an answer covering only the first part of a long file looks exactly like an answer covering all of it.

The click is invisible to everyone but the person making it, which is the governance problem in one sentence. There is no approval step, no record anybody reviews and nothing that distinguishes a menu from a due diligence pack, so the control has to be a shared understanding rather than a gate.

Two ways material leaves the building

Two ways material leaves the buildingThe asymmetry here is worth sitting with, because it is not a failure of anyone's diligence. Connecting an application is legible as a decision: it has a moment, a requester, an approver and an entry somewhere afterwards, so it attracts the process that decisions attract. Attaching a file has none of those properties. It is a click inside a tool somebody already had open, indistinguishable from attaching the same file to an email, and it produces no artefact that any reviewer will ever see. So the thing that is easy to govern gets governed thoroughly and the thing that actually moves the material gets governed not at all. The only control that works at this scale is a shared understanding of what may not be attached and where, arrived at before anybody needed it, which costs a short conversation and is skipped for exactly that reason.Connecting an appSomebody asks permission.Security reviews it.It appears in an admin console.It can be revoked.Attaching a fileNobody asks anybody.Nothing reviews it.It appears nowhere.It cannot be taken back.Nearly all the governanceattention goes to the leftcolumn. Nearly all the materialgoes out through the right one.
The asymmetry here is worth sitting with, because it is not a failure of anyone's diligence. Connecting an application is legible as a decision: it has a moment, a requester, an approver and an entry somewhere afterwards, so it attracts the process that decisions attract. Attaching a file has none of those properties. It is a click inside a tool somebody already had open, indistinguishable from attaching the same file to an email, and it produces no artefact that any reviewer will ever see. So the thing that is easy to govern gets governed thoroughly and the thing that actually moves the material gets governed not at all. The only control that works at this scale is a shared understanding of what may not be attached and where, arrived at before anybody needed it, which costs a short conversation and is skipped for exactly that reason.
03

Seen in the wild

  • A research tool answering strictly from the material you supply, where what you attach is the entire world it will draw on.

    NotebookLM
  • Document intelligence placed inside the reader itself, so the work happens on the file already open rather than in a separate tool.

    Adobe Acrobat AI Assistant
  • A private document tool where taking material in and storing it locally is handled for you, on hardware you operate.

    AnythingLLM
04

Common misconceptions

People assume

The vendor's data promise covers us.

In fact

The promise usually attaches to a plan rather than to a product, and the consumer tier of the same tool frequently makes a weaker one. Anybody relying on the business terms while their team uses personal accounts has a policy on paper and a different arrangement in practice.

People assume

If it answers, it read the whole thing.

In fact

Long files are frequently truncated or summarised without an announcement, and scanned or heavily formatted material can arrive damaged. Both produce fluent answers about the part that survived, which is much harder to notice than an error would be.

05

Telling them apart

File upload vs Connected apps

File upload

One file, one click, no record.

Connected apps

Standing access, approved once, logged.

The reviewed one is the connection; the unreviewed one is the click, which is the reverse of where the attention usually goes.

06

Questions

What should we settle before people start attaching things?
Which accounts are acceptable and which categories of material are not. Both are simple enough to state in two sentences, and stating them is the entire control, because there is no gate at the moment of the click and nothing that will stop anybody who has not been told.
How do I know the file was read properly?
Ask something whose answer sits in an awkward part of it: a figure in a table, something on a late page, a detail in a footnote. A confident wrong answer to that is the signal, and it arrives far faster than any inspection of what was extracted.
Is a local tool the safer answer?
For genuinely sensitive material, frequently yes, since nothing leaves the machine and the policy question does not arise. The trade is capability and convenience, and the sensible pattern for most teams is one approved route for ordinary work and a local option for the narrow set of things that must not travel.
07

Key takeaways

  • The smallest action with an organisational consequence.
  • What happens next is set by the plan, not by the product.
  • Conversion quality decides the answer, and it fails quietly.
  • Long files can be truncated without any warning.
  • There is no gate at the click, so the control is a shared understanding.
09

Tools that use this

Last checked July 2026

All glossary terms