We’ve found that the bot returns all content from published Unily pages. This includes widgets that are hidden to those viewing the page, but available to those editing.
Here are two examples of when this can be problematic:
- When a team is preparing sensitive content for an upcoming announcement, this should only be visible to page editors. Because of this issue, draft information is available to anyone with access to the bot, which is a compliance risk
- When a team hides a widget from display because it contains outdated information, this still serves in the bot which is problematic and reduces confidence in answers the bot gives
We’ve been informed that Unily has two APIs:
- The Content API which returns all content on a page (even content that is unpublished)
- The Search API which only returns published content
Our understanding is that Moveworks uses the Content API. Please could you fix this issue and ensure that only published Unily content is visible in the bot?