Product

Data Guard Classification

Apply your organisation's own categories to the data discovery found — automatically where the match is clear, with a reviewer where it is not.

Overview

A Finding Is Only Useful Once It Carries a Label

Discovery tells you a file contains something that looks sensitive. That is not yet enough to act on. A policy cannot decide whether a document may be emailed to an external address until somebody has said what kind of document it is — and said it in terms the organisation actually uses, not in terms a scanning engine invented.

Classification is where that judgement gets made once and then reused everywhere. Your category scheme is defined a single time. Where the evidence is unambiguous the label is applied automatically; where it is mixed, the item waits for a person rather than being guessed at. Either way, the decision is recorded with the rule that produced it, so it can be explained months later.

Why It Matters

Why Classification Comes Before Control

Every downstream control depends on this step being right.

Policy needs context

Without a label, a rule can only match on raw content, which is how controls end up blocking a template because it looks like a customer record.

Manual labelling drifts

When every team decides for itself what counts as confidential, two departments classify the same document differently within a month.

The backlog never shrinks

Labelling new documents at creation is manageable. The years of files already sitting on shares are not, without automation.

Nobody can explain it afterwards

If a label cannot be traced to a reason, a disputed decision turns into an argument about judgement rather than a look at the record.

Capabilities

One Scheme, Applied Consistently

Six capability areas covering both new documents and the backlog behind them.

Your category scheme

Levels, names and meanings are yours. Defined once centrally, then used by every part of the platform without redefinition.

  • Define your own levels and their meanings
  • Scope a category to a team or a location
  • Change a definition and re-apply it in bulk

Automatic where it is clear

Pattern matches are weighed against the surrounding document, which is what separates a real record from something that merely resembles one.

  • Content, context and structure considered together
  • Confidence threshold you set per category
  • Re-evaluated automatically when a file changes

Reviewed where it is not

Ambiguous matches go to a queue for a person instead of being forced into a category the evidence does not support.

  • Review queue routed to the right team
  • Reviewer sees why it was flagged
  • A decision teaches the rule for next time

Labelling by the author

The person creating a document usually knows best what it is. They can set the category at the moment of creation, within the scheme you defined.

  • Prompt at save or at send
  • A default suggested from the content
  • Downgrades require a justification

Labels that travel

The category is written so it stays with the file when it moves, rather than living in a side database that the file leaves behind.

  • Label persists across copy and move
  • Visible marking where you want it shown
  • Readable by policy without re-reading content

The existing backlog

Classifying new work is the easy half. Bulk classification works through the years of files already on your shares.

  • Works directly from discovery findings
  • Run in batches, by location or team
  • Preview a batch before it is committed
Open by Design

Labels Are Not a Private Format

A classification scheme is only useful if the rest of your estate can read it. Categories and decisions are exposed in a structured form, and we confirm a specific system against your environment in writing rather than showing you a logo.

  • Authenticated API for the scheme, labels and decisions
  • Labels written as file metadata that other tools can read
  • Structured event output for every classification decision
  • Directory-sourced groups for review routing
  • Labels are read directly by DLP policy, with no sync step
Where Teams Use It

Four Situations Classification Is Built For

Turning on DLP for the first time

Movement rules need something to reason about. Classifying first is what stops the first week of enforcement from being a wall of false alarms.

Clearing a historical backlog

Years of unlabelled documents on departmental shares, worked through in batches rather than by asking teams to do it by hand.

Making sensitivity visible

A visible marking on a document changes behaviour on its own, before any control has to intervene.

Settling disagreements

When two teams categorise the same kind of document differently, one central scheme with a recorded reason ends the debate.

What Sets It Apart

Why This Classification

01

It does not guess

Ambiguous matches go to a reviewer instead of being forced into a category. Over-labelling destroys trust in a scheme faster than under-labelling.

02

Context beats pattern matching

The surrounding document is weighed alongside the match, which is the difference between finding a customer record and finding the blank form for one.

03

Decisions stay explainable

Every label can be traced back to the rule and the version of the scheme that produced it, however long ago that was.

04

It handles the backlog

Working directly from discovery findings means the years of existing files are in scope, not just documents created from today onwards.

Questions

Frequently Asked

Do we have to use a standard set of categories?

No. You define the levels, their names and what each one means. The platform applies your scheme rather than imposing one.

What happens when the automatic decision is wrong?

It can be corrected, the correction is recorded, and the rule that produced it can be tuned and re-run against findings you already hold.

Does the label survive if the file is copied or renamed?

The category is written so it travels with the file rather than living in a separate database the file leaves behind.

Can we classify files we already have, not just new ones?

Yes. Bulk classification works from discovery findings, in batches by location or team, with a preview before a batch is committed.

Do we need Discovery to use Classification?

Not strictly, but the two are designed to work together. Without discovery you can classify new documents as they are created; with it, the existing backlog is in scope too.

The Rest of the Platform

Works With

The four products are designed to hand work to each other. Each one is stronger for what the others produce.

Bring Us Your Category Scheme

If you already have one on paper, we can show you it running against a sample of your own documents. If you do not, that is a good conversation to have first.

EN عربي
Request a Demo ›