Skip to content

Security and data visibility

A tenant-admin guide to what leaves S4Ready and what users can see in-app.

Governed rollout, security, and handoff

Use this with security reviewers and tenant admins before enabling external validation or PII masking policies.

Control external egress

External validators are tenant-enabled but deployment-owned.

  • Egress modes are masked, raw, or allowlist depending on deployment policy.
  • When the validator is enabled but unavailable, S4Ready fails closed and blocks export until rerun or break-glass.
  • Returned validator issues map by dataset_id plus record_id, never row number.

Control visibility

Viewing surfaces and work surfaces intentionally behave differently.

  • The LICENSED customer-managed profile supports masking presets; Hosted Demo uses FREE, so its effective policy remains Off.
  • Duplicate review, Quick Fix, approval review, and export show real values to authorized users because decisions require them.
  • Shareable evidence redacts known or high-confidence PII to keyed hashes with masked previews.

How to use this page

Each guide is a compact operating view. Use it to act, then continue into the related workflow page when you need the next step.

  1. 1ScanRead the section headings and confirm you are in the right guide for the role or moment.
  2. 2ActUse the bullets as the checklist for the extraction, review, approval, or handoff task.
  3. 3ContinueJump to a related guide when the work moves into upload, mapping, governance, or security.

Related guides

Use these when the workflow moves to the next handoff point.