Advanced security · personal data detection and security events
Two administrator tools on one screen: a scan that discovers which fields hold personal data across your objects, and a panel that reads the audit trail through a security lens, separating login, export, role changes, security configuration and deletions.
Two questions come up in every security audit: where is the personal data the company keeps, and what relevant things happened during the period. This screen answers both. Open Settings and click Advanced security.
Personal data detection
- On the PII detection tab, pick the object under Select an object.
- If you want, check Analyze free text with AI.
- Click Scan PII and wait.
- Read the result field by field: Field, Data type, Method, Affected, Confidence and Recommendation.
The scan reads a sample of records, one hundred by default and five hundred at most, and classifies field by field. The first layer uses fast, cost-free patterns that recognize email, phone, credit card, SSN and national tax IDs, with check-digit validation where the format allows. If you turn the AI option on, a second pass classifies the free-text fields where the patterns reached no conclusion. That AI usage is metered and goes through your organization's credit limits.
The read respects your access: fields your role cannot see are left out of the analysis, and fields configured as masked reach the scan already masked. The scan is read-only and never alters a value. The recommendations Mark as sensitive, Mask and Review are suggestions; no action is applied automatically.
Security events
- Open the Security events tab.
- Set the period in the From and To fields. With no period entered, the default window is the last thirty days.
- Pick the Category or leave it on All.
- Read the list with When, User, Category and Action, with the summary by category at the top.
- Login: sign-ins to the system and access blocked by network address.
- Export: data and configuration exports.
- Roles and access: changes to roles, permissions and members.
- Security configuration: changes to the security, governance and AI policies, plus configuration imports.
- Deletion: deletions, removals, emptying the trash and anonymizations.
- Sensitive data: merges, restores and resolutions of links between records.
These events are not a second, parallel log. They come from the system's own audit trail, which only accepts inserts and cannot be altered or deleted, presented here with a security classification and filters of its own. Routine actions that are not security events, such as creating and editing a record day to day, are left out of this list on purpose.
Who can do this
Both tabs require permission to manage settings. If you do not have it, the screen answers that only administrators can run the action. Isolation by organization applies here as everywhere else: neither the scan nor the events reach another organization's data.
What this screen does not do
- It does not encrypt fields with a key managed by your company. The screen itself states that this capability is planned and not available yet.
- It does not apply the scan's recommendations. Hiding or masking a field is still done under Settings, Roles and permissions.
- It does not delete or correct the personal data it finds. To fulfill an erasure request, use Anonymize on the data subject's record.