What Restricted mode does
When enabled, two restrictions take effect immediately:- AI processing is restricted to Google (Vertex AI) only. Only routes covered by a signed Business Associate Agreement are permitted; any AI route to a provider without a BAA is blocked at the API level. Every AI feature already routes to Vertex AI for all workspaces, so this restriction is a guarantee that it stays that way rather than a change you will notice.
- Content only reaches services covered by a BAA. AI quality monitoring runs at a provider covered by our signed BAA, so request and response text stays inside that boundary rather than being withheld from it. Session replay, autocapture, and every other content-bearing analytics capture remain disabled. Plain analytics events, which carry only event names and metadata and never content, still operate.
- External sharing is disabled. Share links cannot be created for any artifact in the workspace. Existing share links are not retroactively removed, but no new ones can be generated.
What still works in Restricted mode
The following features run entirely on Google (Vertex AI, BAA-covered) and remain available:- Voice transcription, on Gemini (Vertex AI) with Google Cloud Speech-to-Text as the automatic fallback. Both are covered by the Google Cloud BAA, so your audio stays on Google.
- Photo OCR and text extraction (Gemini Vision)
- AI-generated descriptions for attachments (Gemini)
- Chat with Bower, note authoring, summaries, and titles, all on Vertex AI
- Search, the knowledge graph, protocols, equipment, and audit logs, which never leave Bower
What is not available in Restricted mode
Each of these sends content to a third party that has not signed a BAA, so the workspace blocks it. The restriction is per workspace, not per user: a colleague in a different workspace is unaffected.
If you try to use a blocked feature, Bower tells you it is unavailable in this workspace rather than failing quietly.
Word (.docx) imports
Outside Restricted mode, Bower converts Word documents using a third-party conversion service. That service has no BAA, so in Restricted mode your .docx is never sent to it; Bower converts the file itself. Legacy .doc files are the one exception: they are converted via Google Workspace, which is covered by a separate signed BAA, so they too stay inside a BAA boundary. The import still works. Text, headings, lists, and tables come across as usual. What you lose is embedded images: pictures inside the Word file are not imported. Bower adds a short note at the top of the imported document explaining this, so an image-less note is never a mystery. The original file stays attached, so nothing is lost; you can open it if you need the figures.Enabling Restricted mode
Only workspace admins and owners can toggle Restricted mode.1
Go to Settings > Workspace
2
Find the Restricted mode toggle in the workspace card
3
Click the toggle to enable
4
Confirm in the dialog that appears
Disabling Restricted mode
You can disable Restricted mode from the same toggle. A warning dialog will explain that the protections will be removed. Disabling is also immediate: AI provider restrictions are lifted and sharing is re-enabled.Important notes
- Restricted mode is forward-only. Enabling it does not retroactively re-process content that was previously handled by non-Gemini providers.
- Restricted mode is a workspace-level setting. If you have multiple workspaces, each one can be configured independently. Consider creating a dedicated workspace for PHI data.
- Bower’s Restricted mode restricts AI processing and sharing. It does not replace a full HIPAA compliance program. You are responsible for ensuring your organization meets all applicable requirements, including staff training, risk assessments, and BAA coverage for other tools in your workflow.
Further reading
- Data privacy: encryption, workspace isolation, and access controls
- Sub-processor list: all third-party services that process your data
- Audit logs: track every action in your workspace
- Terms of Service: the contractual side of Restricted mode and PHI