Business Operations
Sensitive Clients
How to protect a high-profile or confidential client so only the right people can ever see them — and exactly what that hides.
Some clients need to be invisible to most of your team by default — a celebrity, a public figure, someone under an NDA, or anyone whose privacy matters more than usual. Peasier calls this flagging a client sensitive, and it's one of the few things in the product that's genuinely all-or-nothing: once it's on, it's enforced everywhere that client shows up, not just on their profile.
Who can flag a client
Only workspace owners and admins can mark a client sensitive, or remove that flag later. No other staff role can do this — not even to edit an already-sensitive client's ordinary details like their phone number. This is deliberate: sensitivity is a decision an owner or admin makes, not something that happens by default or by accident.
What actually disappears for everyone else
- The client directory and search — a sensitive client simply doesn't appear. Not as a locked row, not as a hint that someone's been hidden — they're absent, the same as if they didn't exist in the system at all.
- Galleries — staff can't open a sensitive client's gallery unless they created it themselves, or an owner/admin has explicitly given them access to that specific gallery (see below).
- Invoices — the invoice may still show up in a list, but the client's name is replaced with
(Restricted)and their email is removed entirely. Searching invoices by that client's name or email also returns nothing, so invoices can't be used as a back door to find them.
Giving one staff member access anyway
Sometimes a specific photographer or editor genuinely needs to work with a sensitive client's gallery. Rather than lifting the sensitive flag entirely, an owner or admin can grant that one person access to that one gallery — everyone else stays locked out, and the person who created the gallery in the first place keeps their access automatically.
What it looks like when someone hits the wall
If a staff member has no real connection to a branch at all, trying to find a sensitive client looks exactly like the record simply isn't there — a plain "not found," with nothing suggesting anything's being hidden. If they do have some legitimate presence at that branch but the client is sensitive, they instead get a clear "you don't have access" — which does confirm something exists, just not what. Either way, no unauthorized staff member ever gets confirmation of who a hidden client actually is.
A record of who looked
For a sensitive client's gallery, Peasier keeps a log of every view, download, and PIN entry — visible only to owners and admins, and invisible as a feature entirely to anyone else. That log deliberately leaves out the raw technical detail: no full IP address (just a masked version), no full browser string (just something like "Chrome on macOS"), no exact page path. The raw data still exists behind the scenes, but it's only ever released through Peasier Support handling a formal legal request — not something anyone can browse to on their own. Entries are kept for 18 months and then deleted automatically.
Where else this applies
Sensitive-client protection is the same rule referenced throughout these docs — see Client Management for how the client registry works day to day, and Security & Privacy for how this fits into Peasier's broader approach to protecting personal data.