Channels
SL-08Every route personal data can take out of the department, and what is actually enforcing on each. A channel with policies but none enforcing is a channel with no control.
Coverage by channel
3 policies · 27 incidents
- Inspect body and attachments before delivery
- Block, quarantine or encrypt messages containing classified personal data
- Prevent auto-forwarding to unauthorised domains
Auto-forwarding rules on shared mailboxes are the most common way a quarantined message still leaves the department.
2 policies · 9 incidents
- Prevent copying personal data to USB or removable media
- Control screen capture, printing and clipboard actions
- Detect bulk file staging prior to exfiltration
Staging detection matters more than the block itself — it catches intent before the transfer is attempted.
3 policies · 9 incidents
- Monitor uploads and shares in cloud storage
- Block public or external sharing of classified data
- Detect abnormal download or sync activity
Anonymous-access links created by a migration script caused a real exposure in this dataset.
3 policies · 9 incidents
- Inspect uploads to external websites and APIs
- Prevent submission to unauthorised services
- Apply real-time controls on unsanctioned cloud usage
This is where shadow AI traffic surfaces first, before the AI Processing Guard sees a prompt.
2 policies · 9 incidents
- Detect SELECT-INTO-FILE and unusual export tooling
- Block mass export from classified tables
- Work alongside Database Activity Monitoring for query-level context
Overlaps deliberately with SL-10: DLP blocks the transfer, DAM explains the query.
1 policy · 9 incidents
- Mask identifier columns in printed output
- Log print events against classified documents
Currently in simulate mode at district offices — the false-positive rate is too high to enforce.