Comparison

WonderForce vs ClickUp Brain: what carries the permission on an answer.

Both products answer questions from a company’s own work. They differ on one axis, and ClickUp documents theirs plainly: a Brain response is governed by the permissions of the location it was posted in. WonderForce attaches an audience to each fact and enforces it when the answer is served.

WonderForce · Updated 23 August 2026

When an AI assistant answers from a company’s internal work, the answer is a new artifact. It did not exist before the question, and it can combine sources that different people were allowed to read. The question that decides whether such a system is safe to run company-wide is therefore not whether a given person can open a given document, but what unit carries the permission on the new artifact — the container the answer lands in, the identity that asked, or each individual fact the answer was assembled from — and at what moment that permission is checked.

This page compares two answers to that question: the design ClickUp documents for ClickUp Brain and Super Agents, and the design WonderForce uses. Every statement about ClickUp below is a verbatim quote from ClickUp’s own help center, linked to the page it came from. Nothing here is a claim of a defect: the behaviour is documented, intentional, and disclosed by the vendor. It is a design contrast, and the reader can judge it.

The documented design

What ClickUp documents about who can see a Brain answer. *

Vendor documentation changes; each quote is linked to the exact page it was read from, so it can be re-checked.

What Brain can reach when you ask

ClickUp documents that Brain’s reach is granted per interaction, from where the question is asked: “While responding to you, Brain will temporarily have access to private tasks, Docs, or Channels if: You @mention Brain in a private task, Doc, or Channel.” It documents a restraint on the retrieval side in the same article: “You must explicitly mention the private item or location for Brain to use it to respond.” (@mention Brain, ClickUp Help)

Who can see the response

This is the sentence the comparison turns on, and it is ClickUp’s own: “Brain’s responses are visible to anyone with access to the location where it was posted, whether they have access to the private data used by Brain or not.” The same article states the visibility rule directly: “Anyone who has read permissions or higher to Brain’s response thread can see it.” (@mention Brain, ClickUp Help)

Read those two together and the unit of permission on a derived answer is named explicitly: the location, not the reach of the inputs the answer was built from.

What a Super Agent keeps

ClickUp models the agent as a principal in its own right: “Super Agents are treated as ClickUp users. This allows us to leverage permissions to control Super Agent access to your Workspace data.” Reach expands per invocation: “When a Super Agent is mentioned in a private location or a location that was not selected in its knowledge, the Super Agent has temporary access to the data in that location.” (Super Agent privacy, security, and permissions, ClickUp Help)

That temporary reach can become persistent state. ClickUp documents that Super Agents “can store information in their memory, including from private locations and direct messages (DMs),” that such content “Will be visible in the Super Agent’s memories to anyone with access to the Super Agent,” and that it “Could be used by the Super Agent in other interactions, outside of your private DM.” (What is Super Agent Memory?, ClickUp Help)

The same pattern is documented for connected personal accounts: “By adding personal app knowledge to your Agent configuration, you expose the data from the connected app to anyone who can interact with the Agent.” (Use Brain AI tools from personal connections, ClickUp Help)

The controls ClickUp documents

ClickUp also publishes the controls, and a fair comparison quotes them. There is a consent step before the behaviour is switched on: “Before activating Intelligence, you’ll see a warning message letting you know about this privacy info.” There is a manual remedy afterwards: “As long as you have access to manage the Super Agent, you can always view and edit the Super Agent’s memory to remove any sensitive or confidential information.” (What is Super Agent Memory?, ClickUp Help)

ClickUp summarises the control axis as access to the agent itself: “Secure: You have full control over who can use Super Agents, every action is logged, and they seek human approval for critical decisions.” Delivery is described as trigger-driven: “Collaborative: You can automatically or manually trigger the Super Agent to perform the work it was designed for.” (What are Super Agents?, ClickUp Help)

The other design

What WonderForce does differently: an audience on every fact.

WonderForce does not treat an answer as a message in a place. WonderForce treats an answer as an assembly of facts, and permission is a property of the fact.

The audience is derived, not declared

Every fact a company’s brain holds is drawn from a source: an email thread, a document, a meeting, a channel. That source already has a readership, and the fact inherits it. Nobody tags a fact by hand and nobody assigns a sensitivity level. The audience is derived from who actually had access to the evidence the fact came from, so it is as correct as the source system is.

A derived answer reaches the intersection

An answer built from three facts has three audiences to reconcile, and the honest reconciliation is the intersection: the answer reaches only the people cleared for every fact in it, and no one else. This is the case a container-level rule cannot express, because the container has one readership and the answer has as many as it has sources. Combining knowledge across deals, teams, and time is the whole point of a company brain, and it is also exactly where a boundary would be crossed, so the audience travels with the fact rather than with the room.

The check runs at delivery

The audience is enforced at the moment the answer is served, not only when the source was indexed. That matters because a brief is pushed rather than pulled: nobody typed a query to receive it, so there is no asker whose permissions could stand in for the recipient’s. Each person receives the version of the answer their own evidence supports. Agents connected over the Model Context Protocol read from the same brain under the same rule, and each agent reads exactly what its principal may read, so connecting one widens no one’s access. WonderForce recalls and delivers; nothing is written or sent on a person’s behalf.

Every claim served carries the supporting email, document, or meeting. A request that runs past the available evidence returns an explicit gap rather than an invented answer.

Side by side

ClickUp Brain and WonderForce, compared on five axes.

Every ClickUp cell is a verbatim quote from ClickUp’s help center, linked in the sections above.
Axis ClickUp Brain, as documented WonderForce
Unit of permission on an answer The location the response was posted in: “Brain’s responses are visible to anyone with access to the location where it was posted…” The individual fact. Each fact carries an audience derived from who had access to that fact’s sources.
When the check runs At retrieval, per interaction: Brain “will temporarily have access to private tasks, Docs, or Channels” when mentioned there; and on the thread, where “Anyone who has read permissions or higher to Brain’s response thread can see it.” At serve time, on every delivery, including a brief nobody asked for.
What governs a derived answer The location’s permissions, explicitly independent of the inputs: visible to anyone with access to that location “whether they have access to the private data used by Brain or not.” The intersection of the audiences of every fact the answer was assembled from.
Persisted or derived state Super Agents “can store information in their memory, including from private locations and direct messages (DMs)”; stored content “Could be used by the Super Agent in other interactions, outside of your private DM.” A stored fact keeps the audience it was born with, and re-use re-runs the same check at the next delivery.
Control over that state A consent step and a manual remedy: a warning “Before activating Intelligence,” and a manager who “can always view and edit the Super Agent’s memory to remove any sensitive or confidential information.” The audience check is the control, and runs before an answer is served rather than after it has been stored.
Delivery model Trigger-driven per configured agent: “You can automatically or manually trigger the Super Agent to perform the work it was designed for.” A brief is pushed to each person from their own evidence; agents recall the same context over MCP.
Due diligence

What to check for yourself, with any vendor.

These questions are vendor-neutral. Ask them of WonderForce too, and prefer a written answer in the documentation over an answer in a call.

  • What is the unit of permission on an answer? The container the answer lands in, the identity that asked, or each fact the answer was built from. Ask the vendor to name the unit, not to describe the feeling.
  • If an answer combines two sources with different readerships, who may receive it? There are only a few possible rules, and every product has picked one. Ask which, and ask where it is written down.
  • At what moment is the check run? When the source is indexed, when the question is asked, or when the answer is delivered. A product that only checks at index time cannot govern an answer that did not exist yet.
  • If the assistant keeps memory, what is the audience of a remembered item? Ask whether a remembered item keeps the readership of the source it came from, or takes the readership of whoever can reach the assistant.
  • When an answer is delivered without anyone asking — on a schedule, or into a shared channel — whose permissions decide the recipients? There is no asker in that path, so something else must be doing the work.
FAQ

Questions people ask about ClickUp Brain and permissions.

Is WonderForce an alternative to ClickUp Brain?

WonderForce is a company brain: a permission-aware layer over the tools a team already works in, which pushes a brief to each person and answers questions from that same evidence. ClickUp Brain is the AI layer inside the ClickUp workspace. The two overlap on answering questions from internal work, and they diverge on what carries the permission on an answer the AI assembled.

How does ClickUp Brain decide who can see an answer?

ClickUp documents that a Brain response is governed by the permissions of the location it was posted in. Its help center states: “Brain’s responses are visible to anyone with access to the location where it was posted, whether they have access to the private data used by Brain or not.” ClickUp also documents a retrieval-side restraint: “You must explicitly mention the private item or location for Brain to use it to respond.”

Can a ClickUp Super Agent re-use something from a private DM?

ClickUp documents that a Super Agent can. Its help center states that Super Agents “can store information in their memory, including from private locations and direct messages (DMs),” and that such content “Could be used by the Super Agent in other interactions, outside of your private DM.” ClickUp documents the remedy as manual review: a manager “can always view and edit the Super Agent’s memory to remove any sensitive or confidential information.”

What does WonderForce attach permissions to?

WonderForce attaches an audience to every fact, derived from who actually had access to that fact’s sources. A thread, a document, and a meeting each carry their own readership, and a fact drawn from them inherits it. Nothing is tagged by hand and no sensitivity levels are assigned.

What happens when an answer draws on facts with different audiences?

The answer reaches only the people cleared for every fact used to build it. WonderForce takes the intersection of the audiences of those facts and enforces that intersection at the moment the answer is served, which is the moment that matters for a brief nobody asked for.

Does WonderForce act on a person’s behalf?

No. WonderForce reads and delivers: briefs are pushed to each person, and connected agents recall context through the Model Context Protocol, each reading exactly what its principal may read. Nothing is written or sent on anyone’s behalf.

One company brain. Personalized for everyone.

WonderForce is in private development. Join the waitlist for product updates.

* Every quotation on this page is verbatim from ClickUp’s own public documentation, retrieved 23 August 2026, and each is linked to the exact page it was read from. Vendor documentation changes; the links are there so anything here can be re-checked at the source.