When a board is moved to a space, it should not retain the permissions it had in its previous location (including if it was “not in a space”), it automatically adopt the default permissions of the new space. If not, the board security should default to the least privileged access—ideally private to the board owner or with explicitly defined access.
This would prevent unintended access, especially in enterprise environments where boards can contain sensitive or in-progress content. Retaining broader permissions from a space (or from being outside a space) increases the risk of accidental oversharing.
Applying a "zero trust" default helps teams control visibility intentionally, rather than having to retroactively restrict it.
Thanks for considering this improvement to safeguard content and support more secure collaboration.