Skip to main content

PII redaction

Personal data (PII) redaction is a workflow setting: a run replaces or removes personal data at the stages you choose and its Summary reports what it did. For anyone who builds or reads runs that handle personal data, and everyone in a governed deployment, where it is on by default. It is set per workflow version in the builder's Settings popover and in the Redact PII step, nowhere else. The deployment default is a floor: Off on a standard deployment, Mask on a governed one; an Organisation administrator can change it.

Steps​

  1. In the builder click Settings and find PII redaction. The first line states the floor: "Deployment default: Mask - you can tighten, not loosen." or "Deployment default: Off - this workflow decides." The footer: "Personal data is removed at the stages you choose. The deployment default is a floor: a workflow may tighten it, never loosen it."
  2. Choose a mode: Off ("Nothing is redacted."); Mask ("Each value becomes a stable placeholder such as [EMAIL_1]; the same value gets the same placeholder within a run."); Hash ("Each value becomes a deployment-keyed token such as EMAIL:3f9a…; identical across runs, so files can still be joined."); Drop rows ("Rows that contain personal data are removed from CSV, JSON and Parquet files; free text is hashed."). Below the floor: "This is below the deployment default; the deployment default applies at run time."
  1. Choose what and where:

    SettingOptionsDefault
    CategoriesE-mail addresses, Phone numbers, National ids, Bank accounts (IBAN), Card numbers, Postcodes and addresses, Person names, Dates of birth, IP addresses, Medical facts, Personal financial factsAll ticked when you switch on
    Redact atRun inputs (copied from a connector before the first step), Uploads, Connector results (a step reads), Outputs (under outputs/ plus the run summary), result.json (the result the API returns)All ticked
    Semantic pass (Opus)Off (pattern detectors only), Cued chunks (Opus also reads chunks with a name or date-of-birth cue for names, medical and financial facts), Every chunk (most thorough, most Opus calls)Cued chunks
    Minimum confidence0.5 to 1 in steps of 0.050.8
    Opus calls per run (max)0 to 100,000200
  2. To redact one file mid-run, add a Redact PII step: File to redact, a run-relative path under inputs/… or outputs/… (for example outputs/customers.csv); Redacted copy, a path under outputs/ (empty gives outputs/name.redacted.ext; the next step must read this copy, never the original); Mode: The workflow's policy, Mask, Hash or Drop rows ("Only a tighter mode than the workflow's policy is honoured; the run's mode is never loosened.").

What you should see​

The Summary's outcome strip carries "PII redacted · N values · k categories" (or "PII redaction · completing…" while the final sweep runs; API outputs are served only once it completes); the PII redaction section shows the mode, model and Opus calls, then one line per stage and file ("outputs · outputs/memo.md · 6 values (person_name 6) · 3 Opus calls"), ending in "capped" when the call limit stopped the semantic pass, with "Opus cap reached" in the header; Stages shows an Outputs redacted shield beside each redacted step.

In the files: Mask gives a bracketed category and number ([EMAIL_1], [PERSON_NAME_3], [IBAN_1]), the same placeholder for the same value everywhere in a run (a name in a CSV and in the memo built from it read identically), numbers restarting each run; Hash gives the category in capitals, a colon and sixteen hexadecimal characters (EMAIL:3f9a1c…), identical for the same value in every run and file on the deployment, joinable and irreversible; Drop rows removes the whole row from CSV, JSON and Parquet files and hashes the value in free text.

Notes​

  • The floor is never loosened: a looser choice is overridden at run time and the popover says so; a Redact PII step likewise only tightens. Redaction runs as part of the run, at the stages the policy names.
  • "Name the file to redact (inputs/… or outputs/…).", "The file must be a run-relative path under inputs/ or outputs/.", "The redacted copy must go under outputs/.": fix the path in the drawer.
  • A stage reads "skipped:" with a reason: the file could not be processed there. "capped": raise Opus calls per run (max) and save a new version. Detectors and posture: PII redaction posture.