Configured playbooks
An identity suddenly accesses large volumes of classified personal data outside its baseline.
Signal chain
- 1Access Assurance flags an anomalous authentication or volume spike
- 2Data Discovery confirms the sensitivity and consent scope of what was touched
- 3Database Activity Monitoring corroborates with query-level detail
Response
- Terminate active sessions
- Suspend the identity
- Raise a SOC incident
- Open a breach assessment
Extraction is stopped before it becomes a reportable breach, or the reportable scope is materially reduced.
A legitimate user accesses personal data outside the purpose assigned to their role.
Signal chain
- 1Classification indicates a high-risk category
- 2Behaviour deviates from the historical baseline
- 3No corresponding ticket or case reference exists
Response
- Flag for investigation
- Throttle further access
- Notify the data owner
The incident is identified before mass extraction rather than after it.
An administrator accesses unstructured repositories containing personal data with no operational reason.
Signal chain
- 1Rare behaviour for the privileged identity
- 2Data layer confirms regulated data is present
- 3Access falls outside any change window
Response
- Immediate containment
- Preserve the evidence chain
- Revoke elevated access
Chain of custody is preserved and the department's defensibility is maintained.
Consent is withdrawn, the data has not yet been erased, and an identity attempts to access it.
Signal chain
- 1Consent Manager records the withdrawal
- 2Discovery marks the affected elements as withdrawn
- 3An identity requests those elements
Response
- Block the access
- Log the attempt
- Accelerate the erasure task
Processing genuinely stops on withdrawal rather than waiting for the erasure batch — the difference between compliance and a grievance.
Why these four
They are the four scenarios where identity signals and data classification have to be read together to produce a correct answer. A compromised account looks identical to a busy analyst until you know the data it touched was classified. An insider looks identical to a diligent officer until you know the access fell outside the declared purpose. Consent-withdrawal enforcement in particular has no equivalent in a conventional security stack — it exists only because the Act creates the obligation.