> For the complete documentation index, see [llms.txt](https://handbook.harmonic.security/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.6-cross-app-data-flow-and-live-artifacts.md).

# 4.6 Cross-app data flow and live artifacts

How to control AI data moving through apps, connectors, generated artifacts, shared links, publishing workflows, and downstream systems.

*Last reviewed: August 18, 2026*

{% hint style="info" %}
A session can move data between tools faster than users notice. Shared artifacts and connector-backed outputs need the same review as apps.
{% endhint %}

## What security teams need to know about cross-app data flow and live artifacts

AI sessions can combine prompts, files, connector results, browser pages, local code, and generated artifacts. A user may think they are working in one tool while data moves through several systems.

Live artifacts raise the review bar because a generated page or component can call connectors when a viewer opens it and approves access. That makes the artifact a small app, not a static file.

## Common cross-app data flow and live artifacts security failures

* Sensitive data is generated into an artifact, so sharing the artifact shares the data regardless of connector controls.
* A user approves an artifact's connector access on first interaction without reviewing what it reads or writes.
* Data from one connector appears in another system without a transfer review.
* External sharing is allowed for outputs built from sensitive inputs.
* Users treat generated apps as documents.

## Cross-app data flow and live artifacts security controls checklist

* Map source, retrieval, prompt, model, tool, artifact, and downstream destinations inside each approved workflow.
* Record which identity and credential authorizes each transfer and action.
* Review live artifacts and connector-backed outputs as applications, not static files.
* Restrict external sharing and public publishing for outputs built from sensitive data.
* Preserve classification, labels, ownership, retention, and deletion requirements when data changes format or application.
* Log artifact creation, opens, sharing changes, connector calls, publishing, user identity, and data class where possible.
* Require an owner, review date, expiry or archival rule, and takedown path for durable shared artifacts.
* Test whether source permission changes and deletion requests reach generated and downstream copies.

## Trace the complete fan-out

Start with the source record and follow every copy: retrieval result, prompt context, model response, tool argument, temporary file, generated document, published page, message, ticket, code change, analytics event, and compliance export. Mark the identity, application, region, retention rule, and evidence source at each hop.

Classification must survive transformation. A summary, embedding, chart, screenshot, generated document, or code patch can remain sensitive even when it no longer resembles the source. Where labels do not propagate automatically, require the workflow or user to apply the destination control before sharing or publishing.

Give every durable artifact a removal path. Incident response should be able to find and revoke public links, unshare files, retract messages where supported, disable connector-backed behavior, and identify copies that cannot be recalled.

## Anthropic

### Overview

Claude artifacts are standalone content — documents, code, HTML pages, SVGs, React components — rendered in a dedicated window, and they require the Code execution and file creation capability. On paid plans an artifact can connect to external services through MCP connectors, but the credential model is per-viewer: users are prompted to approve access on first interaction, and each user must authenticate MCP servers independently, even for shared or published artifacts. An artifact does not carry its author's credentials to a new viewer; the residual risks are data generated into the artifact itself, sharing that outruns the data's classification, and viewers approving connector access without reviewing it.

Organization admins can enable or disable artifact MCP access at the organization level. Connectors retrieve data and take actions according to each person's source-system permissions, but that does not stop content already baked into a shared artifact. Cowork adds two more paths: remote sessions can move between web, desktop, and mobile, and the Claude Office add-ins can pass context between open Excel, PowerPoint, Word, and Outlook files. That cross-app transfer can happen inside one session, so the target file needs its own classification and sharing review.

Claude Tag creates another cross-app path from shared Slack context into connected repositories, dashboards, ticketing systems, and document stores. Channel work uses the agent's service accounts and posts results back to a shared thread; direct messages use the individual's connectors and attribution. Preserve that distinction in data-flow diagrams, especially when the same person can invoke both modes.

### Anthropic documentation

* [What are artifacts and how do I use them?](https://support.claude.com/en/articles/9487310-what-are-artifacts-and-how-do-i-use-them)
* [Use connectors to extend Claude's capabilities](https://support.claude.com/en/articles/11176164-use-connectors-to-extend-claude-s-capabilities)
* [Use Claude Cowork on web, desktop, and mobile](https://support.claude.com/en/articles/15520349-use-claude-cowork-on-web-desktop-and-mobile)
* [Use Claude Cowork safely](https://support.claude.com/en/articles/13364135-use-claude-cowork-safely)
* [Work across Microsoft 365 apps](https://support.claude.com/en/articles/13892150-work-across-microsoft-365-apps)
* [What is Claude Tag?](https://support.claude.com/en/articles/15594475-what-is-claude-tag)
* [How Claude Tag agent identity works](https://claude.com/docs/claude-tag/concepts/agent-identity)

### Applicable Harmonic guides for Anthropic

* [Securing Claude Cowork: A Security Practitioner's Guide](https://www.harmonic.security/resources/securing-claude-cowork-a-security-practitioners-guide)

## OpenAI

### Overview

ChatGPT Work can combine files, workspace resources, plugins, apps, browser activity, and local desktop context to create documents, spreadsheets, presentations, reports, and Sites. Plugins package the workflow, while underlying apps still control the data and actions. ChatGPT for Excel or Google Sheets and ChatGPT for PowerPoint carry approved apps and skills into Office-native files, so a source-system permission can become a document write without leaving the host application.

Sites are a publication path, not just a generated file. Enterprise public publishing is off by default and requires admin enablement, but every deployment URL is a production URL. One lifecycle gotcha also remains: disabling or uninstalling a plugin does not necessarily remove or disable every underlying app shared with other workflows. Inventory plugins, apps, connected accounts, generated files, and published Sites separately.

### OpenAI documentation

* [RBAC](https://help.openai.com/en/articles/11750701-rbac)
* [Apps in ChatGPT](https://help.openai.com/en/articles/11487775-apps-in-chatgpt)
* [Admin Controls, Security, and Compliance in apps](https://help.openai.com/en/articles/11509118-admin-controls-security-and-compliance-in-apps-enterprise-edu-and-business)
* [ChatGPT Work and Codex](https://help.openai.com/en/articles/20001275)
* [ChatGPT Work Admin FAQ](https://learn.chatgpt.com/docs/enterprise/work-admin-faq)
* [Plugins in ChatGPT and Codex](https://help.openai.com/en/articles/20001256)
* [Creating and managing ChatGPT Sites](https://help.openai.com/en/articles/20001339)
* [ChatGPT for Excel and Google Sheets](https://help.openai.com/en/articles/20001063)
* [ChatGPT for PowerPoint](https://help.openai.com/en/articles/20001242)

### Applicable Harmonic guides for OpenAI

* [Securing ChatGPT Enterprise Guide](https://www.harmonic.security/resources/securing-chatgpt-enterprise-guide)

## Frequently asked questions about cross-app data flow and live artifacts

### What is cross-app data flow in AI?

It is the movement of data between prompts, files, connectors, browser sessions, tools, Office documents, outputs, artifacts, and published Sites within a single AI workflow. A session that reads a CRM record, summarizes it, and writes the summary into a presentation has crossed three systems in one conversation. Trace the chain from source system to AI surface to target file or publication.

### Why are live artifacts risky?

Because they behave like small applications: an artifact can render interactive content and, on paid Claude plans, request access to MCP connectors when a viewer interacts with it. The realistic risks are sensitive data generated into the artifact itself, sharing that outruns the data's classification, and viewers approving connector access without review. Note that each viewer authenticates connectors independently — a shared or published artifact does not carry the author's credentials.

### Should artifacts be externally shareable?

Only after a short, concrete review: what data class went into the artifact, whether sensitive content is embedded in the output itself, whether it requests connector access, and who the audience is. If any sensitive input was used, treat the artifact as a document of that class and restrict sharing accordingly. Durable shared artifacts need an owner and a review date, like any published application.

### What should be logged for live artifacts?

Where the platform exposes them, log artifact creation, sharing changes, opens, and connector approval events, together with user identity and the data class of the inputs. Expect gaps: some artifact activity only appears in the connected system's own audit logs, so include downstream SaaS logs in the evidence plan (see 6.6).

### How should teams review artifact risk?

Treat connector-capable artifacts and Sites as lightweight applications: identify an owner, the data class of the inputs, the connector scopes requested, and the sharing audience. For Office agents, add the open source and target files and the cross-app setting. Re-review when an artifact or Site is republished, a plugin gains a new app, or its sharing scope widens.

## Applicable regulations and frameworks

| Governance page                                     | Relationship to this article                                                                                                                       |
| --------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| G.1 Map your controls to NIST AI RMF and CSF 2.0    | This article supplies implementation evidence for the NIST AI RMF and matching NIST CSF 2.0 outcomes.                                              |
| G.3 DORA and AI resilience in financial services    | Conditional: for a DORA-regulated workflow, this supports data protection, integrity, and third-party service review.                              |
| G.4 Colorado AI Act and the US state patchwork      | Conditional: for covered Colorado ADMT, this supports the cross-system input and decision path behind an outcome.                                  |
| G.5 SANS Critical AI Security Guidelines mapping    | This article implements relevant SANS Data Protection guidance.                                                                                    |
| G.6 Write an AI Acceptable Use Policy that holds up | This article supplies a technical or process control used to enforce the acceptable-use policy.                                                    |
| G.7 Ownership and RACI for AI security              | This control depends on the ownership and evidence responsibilities defined in the RACI.                                                           |
| G.8 ISO/IEC 42001 AI management system              | This article supports ISO/IEC 42001 AIMS preparation through traceable data flows and responsibilities across integrated systems.                  |
| G.9 HIPAA controls for AI systems handling PHI      | Conditional: for a workflow handling ePHI, this supports HIPAA PHI identification, minimum-necessary handling, retention, and disclosure controls. |

*G.2, G.3, G.4, and G.9 are conditional mappings. They apply only when the deployment is within the legal or regulatory scope described on the linked governance page.*

## Related handbook guidance

* [4. Data Protection & Residency](/handbook/4.-data-protection-and-residency.md)
* [2.1 Connectors and apps: the integration backbone](/handbook/2.-supply-chain-and-extensibility/2.1-connectors-and-apps-the-integration-backbone.md)
* [3.5 Computer Use / desktop control risks](/handbook/3.-runtime-sandbox-and-autonomy/3.5-computer-use-desktop-control-risks.md)
* [5.2 Data exfiltration via tools and connectors](/handbook/5.-threats-and-adversarial/5.2-data-exfiltration-via-tools-and-connectors.md)
* [6.6 Evidence by surface and investigation paths](/handbook/6.-observability-audit-and-evidence/6.6-evidence-by-surface-and-investigation-paths.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://handbook.harmonic.security/handbook/4.-data-protection-and-residency/4.6-cross-app-data-flow-and-live-artifacts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
