Automatically redact content with a policy
Information protection policies give you a rule-based way to detect sensitive data in Jira and Confluence, so you can take action automatically or manually.
Who can do this? |
Use an information protection policy to automatically redact sensitive information from Jira and Confluence when the policy’s conditions are met.
These steps apply to active policies with the Redact matching content control. This control removes matching information without waiting for an admin to review it. It doesn’t create a violation for review.
Read more about how to create, review, and resolve violations
Before you begin
If you haven’t already, create and test a policy with Redact matching content as its control. Save the policy in monitoring mode before activating it.
Create and test an information protection policy
Before you activate a policy
Start with a specific site or app so you can assess the impact before expanding the scope.
Review matches in monitoring mode and tune the conditions until they reliably identify information that should actually be redacted.
Check whether your organization needs a person to investigate or take another action before information is removed. If so, make sure they’re informed or consider creating a violation instead.
Make sure you or another admin can review unintended redactions and use the Guard Detect API within the recovery window.
Keep in mind, automatic redaction removes content without admin review, and can only be restored through the Guard Detect API within 30 days.
After 30 days, the original content is permanently deleted and can't be recovered. Test the policy in monitoring mode before activating automatic redaction.
If matches need human review, use the Create a violation control instead. For example, an exposed credential may need to be revoked or rotated before it’s removed.
It’s also a good idea to check for other active policies that cover the same content. If both controls match the same detection, Redact matching content takes precedence over Create a violation.
Monitoring one policy doesn’t stop another active policy from redacting content. Monitored policies don’t take action on a policy.
Activate a policy for automatic redaction
Activate the policy only when you’re satisfied that any matches can be redacted without human review.
To activate a policy:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
Open the policy you tested in monitoring mode.
Check that the scope, exclusions, and conditions match the configuration you tested, and that the control is Redact matching content.
Return to Policies, then select More actions (), then Activate for the policy.
When content is created or updated within the policy’s scope, the active policy assesses it and automatically redacts content that matches. The content is replaced with a redaction marker (a black box overlaying the content), and the redaction is recorded in the audit log. There will be no violation to resolve in Policy violations.
Activating a policy doesn’t scan all existing content. You can use a content scan in Guard Premium to observe existing content against the active policy, and then automatically redact matches across its scope.
More about running a content scan in Guard Premium
Review automatic redactions
Access the policy’s audit log events to check which content was redacted, and any other events.
To review automatic redactions:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security policies, then Policies.
For the policy, select More actions (), then View audit log events.
Review the affected content, triggering policy, redaction ID, timestamp, and actor to check that the policy acted as intended.
New activities can take a few minutes to appear. More on how to view audit log activity
How to handle inaccurately redacted data
Unintended redactions can only be restored through the Guard Detect API within 30 days. You’ll find the redaction ID in the audit log entry to identify the redaction for recovery. There’s no restore action in Security policies. View the Guard Detect API restore endpoint
If you encounter a few instances of inaccurate redactions, review and tune the policy before relying on it for further automatic redactions. Understand what happens when data is redacted or deleted
Was this helpful?