Using column masks
Protect sensitive information by showing masked values when the user does not need to see the full content.
When to use this
- Use it when the table needs to be queried but some columns are sensitive.
- Use it to allow analysis without revealing personal identifiers or restricted data.
- Use it when the purpose calls for counts, trends, or segmentation, but not the raw value.
Before you start
- Identify the sensitive columns.
- Confirm whether the user needs the full value or only needs to work with protected data.
- Align the mask with your organization's privacy policy.
Step by step
- In the data rule, select the tables that will receive the protection.
- Open the column protection options.
- Choose the columns to be masked.
- Select the mask type available for the case.
- Simulate the rule and review the summary.
- Save the rule.
What happens next
- Queries keep working, but protected columns appear masked.
- The applied rule is recorded in the audit trail.
- Users who need the full value have to go through their own assessment.
Common errors
- Masking a column the analysis needs: the result may lose its usefulness.
- Forgetting equivalent columns: sensitive data may appear in another field.
- Releasing the full value in a hurry: it raises the risk of exposure.
Good practice
- Classify sensitive columns before granting access.
- Use masks by default when the raw value is not essential.
- Periodically review rules that release full values.
Next steps
Was this page helpful?
Report a problem on this pageDo not send passwords, keys, tokens, or customer data.