Skip to main content

Troubleshoot Data Governance

Data Governance says it is off

Open Data Governance → Settings & Integrations and enable Data Governance. You need Super Admin or Security Admin access. See Settings.

The Overview shows sample data

The tenant does not yet have live DLP scan telemetry for the selected time range. Generate traffic through a protected MCP server or Agent Persona, then refresh after activity is recorded.

A detector is in the catalog but not in Your coverage

Your coverage only includes detectors used by enabled policies. Create or enable a policy that references the detector.

A policy does not produce findings

Check that:

  1. Data Governance is enabled.
  2. The policy is enabled.
  3. The correct MCP server or Agent Persona is in scope.
  4. The policy includes the expected detector.
  5. The traffic contains a value that satisfies the detector's format, context, and confidence requirements.
  6. No policy exception suppresses the match.

A policy creates too many false positives

Move the policy to Monitor, review the findings, and add narrow exceptions. For organization-specific detection, refine context, confidence, checksums, or composite conditions rather than disabling an entire coverage area.

Redacted or blocked traffic surprises users

Filter the Policies page by the affected MCP server, Agent Persona, detector, and action. Remember that a persona-attached policy follows the persona across every tool, API, and model it calls.

I cannot edit a policy

Auditors have read-only access. Policy, settings, and detector changes require Super Admin or Security Admin permissions.