Skip to main content

Using column masks

Protect sensitive information by showing masked values when the user does not need to see the full content.

When to use this​

  • Use it when the table needs to be queried but some columns are sensitive.
  • Use it to allow analysis without revealing personal identifiers or restricted data.
  • Use it when the purpose calls for counts, trends, or segmentation, but not the raw value.

Before you start​

  • Identify the sensitive columns.
  • Confirm whether the user needs the full value or only needs to work with protected data.
  • Align the mask with your organization's privacy policy.

Step by step​

  1. In the data rule, select the tables that will receive the protection.
  2. Open the column protection options.
  3. Choose the columns to be masked.
  4. Select the mask type available for the case.
  5. Simulate the rule and review the summary.
  6. Save the rule.

What happens next​

  • Queries keep working, but protected columns appear masked.
  • The applied rule is recorded in the audit trail.
  • Users who need the full value have to go through their own assessment.

Common errors​

  • Masking a column the analysis needs: the result may lose its usefulness.
  • Forgetting equivalent columns: sensitive data may appear in another field.
  • Releasing the full value in a hurry: it raises the risk of exposure.

Good practice​

  • Classify sensitive columns before granting access.
  • Use masks by default when the raw value is not essential.
  • Periodically review rules that release full values.

Next steps​