Skip to main content

Monitor and Investigate Data Governance

Open Data Governance → Overview to monitor your current posture.

The Overview uses live DLP scan telemetry when it is available. Before the tenant has scan activity, some widgets may show clearly marked sample data.

Choose a time range from 1 hour, 24 hours, 2 days, 1 week, or 2 weeks, then use the analysis views:

ViewWhat it helps you investigate
Top risksThe most important sensitive-data exposures and governance gaps
ComplianceFindings and enforcement grouped by compliance framework
Behavioral sequencesRelated events that form a suspicious sequence
Live decisionsRecent policy decisions and their detector findings

Selecting an event or risk can take you to the corresponding Tool Activity record or a filtered policy view.

Recommendations

Recommendations use observed traffic and configuration to identify opportunities to improve governance. Review the proposed detector, scope, and action before enforcing a recommendation.

The Behavioral Governance tab on the Policies page is a preview surface for recommendations and composite behavioral rules. Treat recommended rules as proposals: inspect their conditions and begin with a monitoring action when possible.

Understand activity records

Data Governance decisions also appear in Tool Activity. A record can show:

  • Whether a request or response was allowed, redacted, or blocked
  • The detector or sensitive-data type involved
  • The policy responsible for the decision
  • The MCP server, tool, user, or Agent Persona involved

Sensitive values are masked by default. Only users with reveal permission can choose to display them.