GOVERNANCE
connecting…
Live Activity

Live Request Feed

Every data request intercepted by the governance proxy, grouped by agent session, in real time.

0
Intercepted
0
Sessions
0.0 pts
Risk Neutralized
Request Streamlive
Waiting for agent requests… open the agent UI and ask a question.
Select a request to see its governance decision.
All Sessions 0
No sessions yet
Select a session to view
its governance timeline

Data Sources

Connected databases and APIs — classified by PII sensitivity

Deployment
Organization-level configuration. Changes are saved to the proxy config bundle; click Apply changes in Configured sources below to restart the proxy and pick them up.
Customer ID (used as prefix for audit log groups and Redis keys)
Display name
Industry
Configured sources
Add, edit, or remove the upstream databases the proxy governs. Changes are saved immediately to the proxy config; click Apply changes to restart the proxy (~30–60s downtime) so the new pools come up.
ID Type Secret ARN
Loading…
Discovered fields
Loading…
PII Classification Legend
Direct IDName, email, SSN, per-person FKs — S = 1.0, I = 1.0
CredentialAPI key, token, password — S = 1.0
BiometricFingerprint, face/voice template — BIPA; S = 0.85
Criminal RecordConvictions, arrests, background — FCRA; S = 0.85
HealthDiagnosis, plan, claims — HIPAA; S = 0.80
Special CategoryRace, religion, politics, sex life — GDPR Art. 9; S = 0.80
FinancialSalary, debt, FICO, bankruptcy, payments — S = 0.70
Precise LocationGPS lat/lon, sub-ZIP geo — CCPA sensitive PI; S = 0.70
Content SensitiveFree text — NER scanned at query time; S = 0.50
Vehicle IDVIN, license plate — CCPA PI; S = 0.30
Device IDIMEI, MAC, IDFA/AAID — CCPA PI; S = 0.30
Quasi-IDZIP, DOB, gender, IP — entropy bits; S = 0.20
DemographicDepartment, performance band — S = 0.10
Non-SensitiveTimestamps, counts, flags — S = 0.0
UnknownPending async classification

System Health

Live status of all proxy instances and latency performance

Loading…
Proxy Performance
Loading…

Audit Log

Every data request recorded by the governance proxy

Replaying session
Loading…

Admin Activity

Governance changes by dashboard operators — who changed what, and when

Loading…

Classification

LLM classification queue and results for unknown fields

Performance
Fields Classified
Avg Latency
p95
p99
Pending Queue 0
No items in queue
Classified 0
No classifications yet
Needs Review 0
No items

Access Approvals

Time-bound exceptions to a rule or tier — approved for one agent identity, expiring on their own

Request access
Agent identity
Held by one identity, never by a role — a role-held exception widens to everyone mapped to it
Rules excepted
Tiers excepted
The sensitivity floor has no rule to name, so a tier is what an approval binds to
Sources
Unlocks
TOKENIZE answers "is it set / do these match / what shape" without disclosing the value
Reason
Awaiting decision 0
Nothing awaiting a decision
In force 0
No approvals in force
Decided
Nothing decided yet

Governance Policies

Configure enforcement rules — changes apply to the proxy immediately

Unknown field policy
Type Policy Roles Enabled

Regulatory Frameworks

Framework scoring models, enforcement thresholds, and HIPAA Safe Harbor configuration

Frameworks
GDPR — General Data Protection Regulation
Scores identifiability I across accumulated fields. GDPR = I × (1 + minimization penalty + Art.9 penalty). Redaction kicks in when score ≥ threshold; CEO is exempt as data controller.
HIPAA — Health Insurance Portability and Accountability Act
Multiplicative model: HIPAA = I × H, where H combines a base health-data weight and cross-source bonus. Neither identifiers nor health data alone trigger PHI risk — both must be present. No role exemption.
CCPA — California Consumer Privacy Act
Scores breadth of consumer data assembled in a session. CCPA = I × breadth_factor, where breadth rises with the number of distinct sensitive categories accessed. CEO exempt from enforcement.
HIPAA Safe Harbor
Safe Harbor De-identification
When enabled, the 18 HIPAA Safe Harbor identifiers (name, zip, DOB, email, employee ID, medical plan code) are redacted from any response that also contains health data, regardless of role or purpose.
Risk Score Thresholds
GDPR 0.70
I × (1 + minimization + Art.9) ≥ threshold → redact
HIPAA 0.80
I × H + loaded-gun bonus ≥ threshold → redact
CCPA 0.70
I × breadth_factor ≥ threshold → redact
Threshold and mode changes apply live to enforcement and persist across proxy restarts.
Monitoring keeps a framework fully scored, audited, and visible on the session curve — it simply stops contributing redaction. Use it when your deployment is audited against a different regime. The sensitivity floor below is unaffected: setting every framework to monitoring does not serve credentials, health, or special-category data. This is not the global enforcement switch, which turns off governance entirely.
Sensitivity Floor
Categorical Sensitivity Floor
Fields in these categories are redacted on sensitivity alone — independently of the re-identification score above. This is what protects a lone credential or special-category field, which by itself carries near-zero re-id risk.
Loading floor…
The floor is read-only and changes via config + deploy, not the dashboard

Identity & Access

Map agent usernames to governance roles

Provision per-(human, agent) credentials. The cleartext password is shown once at create time and lives in AWS Secrets Manager for later retrieval. SCRAM verifiers and roles are pushed to the proxy via Redis — no proxy restart needed.
Provisioned agent users
Username Role Agent class Source grants Created
Loading…
What each role allows
Redacted fields and policy counts are derived from the Policies tab (read-only here). Source access is the structural allow-list of databases each role may read.
Role Source access Redacted fields Policies
Source grants

Accounts

Your dashboard account, operator accounts, and dashboard roles

My account
Change my password
Current password
New password (min 8 chars)
Confirm new password

Field Categories

Operator overrides on classification. Admin entries win over the static built-in table and over LLM-classified entries.

Filters
Classifications

Every discovered field — classified or UNKNOWN. Pick a category (and optional concept) and click Apply to override; the override is authoritative (wins over the classifier) and a set concept is block-eligible. Tick rows to override many at once.

Field Data source Current category Tier Conflicts Override Concept Scope