An Agent that answers the public does not inherit the organization. A stranger's answer follows a configured path — the Agent, its Areas, and the content attached to them — and one line in that path is not configurable at all.
Visitor
Anonymous. Never signed in.
Widget
The public entry point, on an allowed domain
Agent and Areas
Instructions, routing, and attached resources
Eligible content
Knowledge — and never a Standard
A visitor never reaches a Standard
This is the boundary that is not a setting. An anonymous visitor reaches Knowledge and never a Standard, whatever the Standard's own visibility says and whatever the Agent behind the widget may read internally. Making a Standard organization-wide does not make it public, and there is no configuration that would.
If the public needs to know what a rule says, publish that version as its own Knowledge Source, written for the audience that will read it. That keeps the governed rule and the public explanation as two separate things that can move at their own speed.
Knowledge follows the Agent
A Source is reachable only when the Agent names it, or an Area the Agent draws on holds it, and only when it is in a usable state. A Source does not become public because it exists in the organization.
Connectors are explicit
Any Connector capability the visitor's question can reach has to be deliberately attached and permitted. Treat an external system as its own data boundary, and review what each capability can read or change before a stranger's question can trigger it.
Test the published path
Before you share a widget, ask representative questions and inspect the sources behind the answers. Ask one question that fishes for internal material, and confirm it comes back empty. Re-test after changing the Agent, its Areas, or what its Sources contain.
See The website widget for the publishing workflow.