Who should see what in your data room

    Access levels are a judgement, not a setting. The common mistake is not being too restrictive, it is granting everyone the same thing because deciding per person feels like work.

    Yash Kadam · Last reviewed 6 October 2026

    The short answer

    Grant the least that lets someone do the thing they are currently doing, and raise it when the conversation advances. Diligence escalates; access should escalate with it rather than being set once at the start.

    The reason this matters is not paranoia. It is that a room where everyone sees everything is a room you cannot stage, so you either over-disclose early or you hold the whole room back.

    The ladder

    XDrop AI uses a cumulative role model, each rung includes everything below it:

    RoleCanTypically
    viewRead what they have been grantedAn investor at first look
    commentRead and leave commentsAn investor in active diligence
    ask-AIRead, comment, and ask the AI questionsAn investor doing the reading themselves
    editChange documentsYour CFO, your counsel
    manageChange documents and manage accessA co-founder running the raise
    ownerEverything, including the NDA and the room itselfYou

    Note where ask-AI sits. Asking the AI is a higher privilege than reading, because a question can traverse many documents at once. It is granted deliberately, not bundled with read access.

    Why over-granting is the normal failure

    Nobody sets out to over-share. It happens because granting everyone the same thing is one decision and granting per person is twelve, and you are mid-raise.

    Three specific consequences:

    • You lose the ability to stage. If the first investor got everything, the fifth gets everything too, because that is now the room.
    • Sensitive documents sit in front of people with no reason to read them.Founder vesting and employee contracts rarely need to be open at first look.
    • “Who could have seen this?” becomes “everyone”.Which is the answer you least want if something is later disputed, and the one that makes a DPDP breach report hardest to write. See DPDP and your investor data room.

    A workable default by stage

    1. First conversation. No room access. Deck and headline metrics by email.
    2. Expressed interest. view on Corporate, Financials and Product. Not the cap table, not Legal, not Team.
    3. Active diligence. Raise to comment or ask-AI, add the cap table and Legal. This is where the AI earns its place, an associate with a hundred questions can ask them without routing each through you.
    4. Post term sheet. Add Team, employee contracts and the sensitive tier. Many funds will sign a mutual NDA at this point as a matter of course. See should investors sign an NDA.
    5. Round closes, or does not. Revoke. This is the step everyone skips.

    The step everyone skips

    When a conversation ends, access usually does not. Six months later a fund that passed still has standing access to a room that now contains a new cap table, a new model and a new set of contracts.

    Revoking is thirty seconds of work and nobody does it, because the raise is over and attention has moved on. Put it on the same list as the closing documents.

    XDrop AI access can also be time-limited at the point of granting, which turns remembering into not having to.

    Non-investor roles worth separating

    • Your counsel: edit on Legal, view elsewhere. They need to correct documents, not run the room.
    • Your CA or CFO: edit on Financials. Same logic.
    • A co-founder running the process: manage, so they can grant access without needing you.
    • An advisor making introductions: view on the deck only. They are advocating, not diligencing.

    How the limit is enforced

    Two properties are worth knowing, because they are what make per-person grants meaningful rather than cosmetic.

    Every request resolves the caller’s role before any data is returned, and the document set handed to the AI is filtered to what that caller may read. So the same question from two investors with different grants produces different answers, and for one of them, no answer at all.

    The limit applies when the system searches, not after. A document outside someone’s grant is never a retrieval candidate, so it cannot be quoted, summarised, or confirmed to exist. Filtering after retrieval is materially weaker: a summary that has already absorbed restricted text can leak it without ever naming the source. More on that in can you trust an AI with your data room.

    XDrop AI is a data room for Indian fundraising, with an AI that answers investor questions and cannot read what you have not shared.

    Start free