Classification & Clearance
Label records with a classification level and hold users at a clearance, so that access, export, watermarking and auditing follow the label.
Schemes and Levels
Classification labels a record with how sensitive it is. Clearance says how sensitive a record a person may see. The two are compared on every access.
Where to find it
Architect Panel → Security:
- Classification & Clearance — the console
- Classification Schemes — the schemes themselves
- Classification Levels — the ranked levels within a scheme
- User Clearance — what each person is cleared to
Schemes and levels
A scheme is a named set of levels — you might have one for information security and another for commercial sensitivity. A level belongs to a scheme and carries a key, a label and a rank.
Rank is what makes comparison possible: a higher rank is more sensitive, and access requires a clearance that reaches it.
What a level can enforce
This is what makes the feature more than a coloured label. Each level carries its own controls:
- Minimum clearance — the clearance rank needed to see records at this level.
- Caveats — handling instructions carried with the label.
- Allow export — whether records at this level may leave the system.
- Watermark template — a watermark applied when the record is rendered or printed.
- Audit reads — force read logging at this level regardless of the datastore setting.
- Require break-glass — access demands a recorded justification.
Export control is the one people underestimate
Most classification systems control who can open a record and stop there — which does nothing about the person who opens it legitimately and then exports ten thousand of them to a spreadsheet.
Turning off export at the higher levels closes the gap that classification alone leaves open. It is usually the single most effective setting here.
Watermarking
A watermark carrying the viewer's identity and the time does not prevent a screenshot — it makes the screenshot traceable. That changes behaviour, which is the point: most inappropriate disclosure is casual, and casual disclosure stops when attribution is visible.
Keep the ladder short
Three or four levels. People classify accurately when the choice is obvious and inaccurately when it is not, and a seven-level scheme produces everything landing on the middle two.
Over-classification is as damaging as under-classification: when routine records are marked highly sensitive, people learn to work around the label rather than respect it.
Decide the default
Every record gets a level, including the ones nobody thought about. Choose deliberately whether an unclassified record is treated as the lowest level or refused — and prefer the safer option on a datastore holding anything sensitive.
Worked example
An organisation runs one scheme with four levels. The top two require a clearance, disable export, apply a watermark and force read auditing; the top level additionally requires break-glass. Most records sit at the lower two and are unaffected. The controls are concentrated where they earn their cost.
Recommendations
- Three or four levels, no more.
- Disable export at the top levels.
- Force read auditing where the label matters.
- Decide what unclassified means before go-live.
User Clearance
A clearance says what level of classified record somebody may reach within a particular scheme.
Where to find it
Architect Panel → Security:
- User Clearance — clearances, who granted them and when they expire
- Classification Levels — the ranks a clearance is compared against
- Classification & Clearance — the console
What a clearance records
- The scheme it applies to.
- The person, by the platform's three-part identity.
- The clearance rank.
- Granted by and granted at.
- An expiry.
Per scheme, not global
Somebody can hold a high clearance for commercial sensitivity and none for personal data. That is usually correct — a finance director needs contract terms, not case files — and a single global clearance cannot express it.
Clearances expire
The expiry is the most important field. Clearance is granted for a role or a piece of work, and both end; without an expiry the clearance outlives the reason, and organisations accumulate people cleared for things they stopped doing years ago.
Set one always. Annual is a reasonable default, aligned to a review cycle you already run.
Grant to the role, review on change
Base the clearance on what the person needs to do, and review it when they change role. A promotion or a move to a different team is the natural moment — and it is the moment most often missed, because clearance is rarely on anybody's leaver or mover checklist.
Add it to that checklist. It costs one line and prevents the commonest form of accumulated over-access.
Granted by is not bureaucracy
It answers who authorised this, which is exactly what an audit asks. It also creates a small, useful moment of accountability at the point of granting.
Do not clear people to make an error go away
When somebody cannot open a record, the tempting fix is to raise their clearance. Sometimes that is right. Often the record is misclassified, or the person genuinely should not see it, and raising clearance solves the immediate complaint while quietly widening access to everything else at that level.
Check the record's classification before changing anybody's clearance.
Review what the top clearances can reach
A yearly look at who holds the highest clearances, and why, is the single most valuable review here. The list is usually short, and it is usually longer than anybody expected.
Worked example
An organisation grants clearances annually, aligned to appraisals. A review finds four people cleared at the top level who moved to roles that no longer need it — two years earlier. Their clearances are reduced rather than revoked, keeping the access their current work needs, and clearance is added to the internal-move checklist so it does not recur.
Recommendations
- Always set an expiry.
- Put clearance on your movers and leavers checklist.
- Check the record's classification before raising anybody's clearance.
- Review the top clearances annually.