Tuning & Simulation
SL-08Run a policy against real traffic without blocking anything, see what it would have caught, then promote it. Deploying an untuned policy straight to enforce is how a control ends up disabled by the people it inconveniences.
DischargesR.6
Policies in simulate
1
Noisy policies
3
False positives above 8%
Confirmed false positives
8
Average false positive rate
7%
3 policies are producing too much noise
Above roughly 10% false positives, people stop reading the alerts and start requesting exceptions. Tighten the classification triggers rather than loosening the action — the second option looks like progress and is not.
Precision by policy
True positives against false positives over the last thirty days. A tall bar that is mostly amber is a policy that needs work, not a policy that is working hard.
Simulating now
These would have acted on the traffic below. Promote when the precision is acceptable.
Redact identifiers in printed output
District offices
Matched
386
Would block
300
False positives
22.4%
Precision77.6%
PrintMedium
Confirmed false positives
Incidents an analyst marked as false. Each one is a signal about which classification trigger is too broad.
- DLP-2026-07113Warn on personal data submitted to unsanctioned web servicesWeb & APIGovernment identifierDate of birth
- DLP-2026-07132Block outbound email containing government identifiersEmailEducational recordDate of birth
- DLP-2026-07139Redact identifiers in printed outputPrintEducational recordBank account
- DLP-2026-07150Block sharing of data with withdrawn consentEmailGovernment identifier
- DLP-2026-07153Warn on personal data submitted to unsanctioned web servicesWeb & APIEducational record
- DLP-2026-07157Quarantine children's data leaving the departmentEmailDate of birthEducational record
- DLP-2026-07158Block sharing of data with withdrawn consentEmailBank account
- DLP-2026-07161Warn on personal data submitted to unsanctioned web servicesWeb & APIDate of birthGovernment identifier