Organise information by protection level and recipient group.
Create an information list before disclosure. For each class, record recipients, purpose, scope, approval and end date. Confidentiality is then implemented in the process rather than merely asserted.