Security and data visibility
A tenant-admin guide to what leaves S4Ready and what users can see in-app.
Governed rollout, security, and handoff
Use this with security reviewers and tenant admins before enabling external validation or PII masking policies.
Control external egress
External validators are tenant-enabled but deployment-owned.
- Egress modes are masked, raw, or allowlist depending on deployment policy.
- When the validator is enabled but unavailable, S4Ready fails closed and blocks export until rerun or break-glass.
- Returned validator issues map by dataset_id plus record_id, never row number.
Control visibility
Viewing surfaces and work surfaces intentionally behave differently.
- The LICENSED customer-managed profile supports masking presets; Hosted Demo uses FREE, so its effective policy remains Off.
- Duplicate review, Quick Fix, approval review, and export show real values to authorized users because decisions require them.
- Shareable evidence redacts known or high-confidence PII to keyed hashes with masked previews.
How to use this page
Each guide is a compact operating view. Use it to act, then continue into the related workflow page when you need the next step.
- 1ScanRead the section headings and confirm you are in the right guide for the role or moment.
- 2ActUse the bullets as the checklist for the extraction, review, approval, or handoff task.
- 3ContinueJump to a related guide when the work moves into upload, mapping, governance, or security.
Related guides
Use these when the workflow moves to the next handoff point.