- Go to Govern > PII.
- Enable PII Detection.
- Configure the PII protection settings.
- Enable and configure built-in patterns or create custom patterns.
- Save your changes.
PII protection settings
The following project-level settings control PII detection behavior.Credential and secret scrubbing for API keys, access tokens, passwords, and similar credentials is always enabled and cannot be disabled.
Built-in patterns
Built-in patterns use platform-managed detection logic for commonly used PII types, including Email Address, Phone Number, Social Security Number, Credit Card Number, and Date of Birth. Each pattern can be enabled individually and configured with its own context anchoring, redaction strategies, consumer access settings, and live test configuration.Custom patterns
In addition to built-in patterns, you can create custom patterns to identify organization-specific or domain-specific PII. Select Add Pattern to create a custom pattern and configure the following settings.Context anchoring
Context anchoring improves detection accuracy by evaluating context words that appear near a potential match.Redaction strategies
Redaction strategies determine how detected PII is rendered before it is shared with a consumer.Only enabled strategies are available when configuring render modes.