Loading

Schemes and Levels

Classification labels a record with how sensitive it is. Clearance says how sensitive a record a person may see. The two are compared on every access.

Where to find it

Architect Panel → Security:

  • Classification & Clearance — the console
  • Classification Schemes — the schemes themselves
  • Classification Levels — the ranked levels within a scheme
  • User Clearance — what each person is cleared to

Schemes and levels

A scheme is a named set of levels — you might have one for information security and another for commercial sensitivity. A level belongs to a scheme and carries a key, a label and a rank.

Rank is what makes comparison possible: a higher rank is more sensitive, and access requires a clearance that reaches it.

What a level can enforce

This is what makes the feature more than a coloured label. Each level carries its own controls:

  • Minimum clearance — the clearance rank needed to see records at this level.
  • Caveats — handling instructions carried with the label.
  • Allow export — whether records at this level may leave the system.
  • Watermark template — a watermark applied when the record is rendered or printed.
  • Audit reads — force read logging at this level regardless of the datastore setting.
  • Require break-glass — access demands a recorded justification.

Export control is the one people underestimate

Most classification systems control who can open a record and stop there — which does nothing about the person who opens it legitimately and then exports ten thousand of them to a spreadsheet.

Turning off export at the higher levels closes the gap that classification alone leaves open. It is usually the single most effective setting here.

Watermarking

A watermark carrying the viewer's identity and the time does not prevent a screenshot — it makes the screenshot traceable. That changes behaviour, which is the point: most inappropriate disclosure is casual, and casual disclosure stops when attribution is visible.

Keep the ladder short

Three or four levels. People classify accurately when the choice is obvious and inaccurately when it is not, and a seven-level scheme produces everything landing on the middle two.

Over-classification is as damaging as under-classification: when routine records are marked highly sensitive, people learn to work around the label rather than respect it.

Decide the default

Every record gets a level, including the ones nobody thought about. Choose deliberately whether an unclassified record is treated as the lowest level or refused — and prefer the safer option on a datastore holding anything sensitive.

Worked example

An organisation runs one scheme with four levels. The top two require a clearance, disable export, apply a watermark and force read auditing; the top level additionally requires break-glass. Most records sit at the lower two and are unaffected. The controls are concentrated where they earn their cost.

Recommendations

  • Three or four levels, no more.
  • Disable export at the top levels.
  • Force read auditing where the label matters.
  • Decide what unclassified means before go-live.