For the complete documentation index, see llms.txt. This page is also available as Markdown.

Author a Masking Data Policy

Permissions

GOVERNANCE Immuta permission or Manage Policies domain permission

Build the policy

  1. Click the Policies icon in the navigation menu and select the Data Policies tab. Click New data policy and complete the Policy name field.

  2. Select Mask from the first dropdown menu.

  3. Select columns tagged, columns with any tag, columns with no tags, all columns, or columns with names spelled like.

  4. Select a masking type (some of these types will only be available for Snowflake integrations):

  5. Select everyone except, everyone, or everyone who to continue the condition.

    • everyone except: In the subsequent dropdown menus, choose is a member of group, possesses attribute, or is acting under purpose. Complete the condition with the subsequent dropdown menus. For a list of exceptions and an explanation of their behavior, see the Masking policies reference guide.

    • for everyone who: Complete the Otherwise clause. You can add more than one condition by selecting + Add Another Condition. The dropdown menu in the policy builder contains conjunctions for your policy. If you select or, only one of your conditions must apply to a user for them to see the data. If you select and, all of the conditions must apply.

  6. Opt to complete the Enter Rationale for Policy (Optional) field, and then click Add.

  7. Click the dropdown menu beneath Where should this policy be applied and select When selected by data owners, On all data sources, or On data sources. If you selected On data sources, finish the condition in one of the following ways:

    • tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with columns tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with column names spelled like: Select this option, and then enter a regex and choose a modifier in the subsequent fields.

    • in server: Select this option and then choose a server from the subsequent dropdown menu to apply the policy to data sources that share this connection string.

    • created between: Select this option and then choose a start date and an end date in the subsequent dropdown menus.

  8. Click Activate Policy or Stage Policy.

Last updated

Was this helpful?