Every automated seat reaches something. Files, inboxes, a CRM, a billing system, a document store. The question of what it should be able to reach is almost always answered by whatever credentials were convenient during the build.
That is how systems end up with a service account that can read everything, held by a process that needed one folder. Nobody decided it. It accumulated, and the accumulation is invisible until something goes wrong or someone audits it.
The four classes
Public is what has been approved for distribution. Internal is ordinary operating material, neither secret nor for publication. Confidential covers commercial, client, contractual and founder material, handled on a need basis. Restricted covers credentials, security material, privileged and legal material, employment and personal records, and finance, where access is the exception rather than the rule.
Four is deliberately coarse. A scheme with twelve classes gets applied inconsistently within a month because nobody can hold the distinctions, and an inconsistently applied scheme is worse than none because it produces confidence without protection.
What it changes in practice
Every seat in a pod is specified against these classes when it is designed, which means the answer to what this agent can see exists in writing before the agent exists. Where a seat needs confidential material to do its job, that is stated and the reason is recorded.
It also makes the outbound checks tractable. The rule that client-facing email waits when it may disclose material not meant for that recipient is only enforceable if the material carries a class. Without classification, the check is an instruction to be careful, which is not a control.