Content remediation surfaces sensitive content findings and matches directly on a board, so board owners, co-owners, and editors can review and act on them without waiting for a Sensitive Content Admin to reach out. People can remove sensitive data or report false matches so the board can be reclassified.
Why content remediation
Board owners, co-owners, and editors get visibility into why a board was classified the way it was, so they can review specific sensitive content before making any classification changes. They can act on findings themselves, without waiting on a Sensitive Content Admin, which means faster remediation and less back-and-forth. And because content remediation surfaces the finding, context, and available actions right on the board, the right people see it at the moment it matters, rather than relying on a Sensitive Content Admin to track detections and follow up individually.
Who can review content remediation findings
Board owners, co-owners, and editors on a board where content remediation is active. A user with the Edit Content Metadata privilege (for example, a Content Admin, Team Admin, or a custom role with that privilege) can also see content remediation on the board and change its classification, even with only viewer or commenter access.
How it works
- When a board's content triggers auto-classification, content remediation appears on that board for permitted users. This check is based on the detected sensitivity label, not the board's current classification. Content remediation can still appear even after someone manually reclassifies the board.
- Reviewers can see where the sensitive data is located on the board and what type was detected, and can review each match individually. They can take action: manually remove the content, adjust the board's classification level (if manual reclassification is allowed), or report a match to an Admin as a false positive (if that action is enabled).
- After content is remediated, for example when sensitive text is removed or a match is reported, data discovery rescans the board according to its scan schedule. Board owners and editors can also manually trigger a scan to see the latest results right away. The board's classification and any guardrails are updated automatically after the rescan.
What admins can configure
Sensitive Content Admins or custom roles with the Content Remediation privilege can configure content remediation once for the whole organization, along three controls:
- Trigger controls when content remediation appears. It appears whenever auto-classification detects sensitive content, or only when that content also maps to a classification level that carries a guardrail.
- Manual reclassification controls how freely reviewers can change a board's classification level. They can change it freely, or only move it to a stricter or equally strict level than the one determined by the auto-classification configuration.
- Report false match controls whether reviewers are allowed to flag a detected match as a false positive.
For step-by-step setup instructions, see Configure content remediation.
Example scenarios
These examples show how content remediation behaves for a board, based on a sample auto-classification and guardrail configuration.
Example configuration
The following table lists the configuration used for the scenarios on this page. It's for explanatory purposes only. Configure your own classification levels, labels, and guardrails based on your organization's requirements. See Define Auto-classification and Define guardrails.
| Classification level | Sensitivity order | Sensitive label | Guardrail |
| Public | 1 (least sensitive) | None | None |
| Internal | 2 | GDPR | Block sharing publicly |
| Confidential | 3 | PII | Block sharing with organization |
| Strict | 4 (most sensitive) | PCI | Block sharing with team |
Table 1: Example configuration, for illustration only.
When content remediation triggers
These scenarios assume Trigger is set to Automatic classification, except where noted.
| Detected sensitive content | Resulting auto-classification | Trigger setting | Content remediation appears? |
| None | Internal (default) | Automatic classification | No |
| A label not mapped in your configuration | Internal (unchanged) | Automatic classification | No |
| GDPR | Internal | Automatic classification | Yes |
| PII | Confidential | Automatic classification | Yes |
| PII (Confidential has a guardrail) | Confidential | Automatic classification and Guardrails | Yes |
Table 2: Content remediation checks the detected label against your configuration, not the board's current classification.
Reclassifying a board with content remediation active
| Scenario | Manual reclassification setting | Result |
| Board is auto-classified to Confidential (PII detected). The owner manually tries to set it to Internal. | Stricter only | Content remediation still appears, because the check follows the detected label, not the board's current level. The owner can't reclassify below Confidential while PII is present. |
| Board is auto-classified to Confidential (PII detected). | Allow manual reclassification | The owner can freely move the board to any level. Content remediation is informational only and never blocks the change. |
| Board contains PII and PCI content and is auto-classified to Strict. The owner removes the PCI content only. | Stricter only | Auto-classification lowers the board to Confidential, because PII still maps there. Content remediation stays active, and the floor moves down to Confidential, not lower. |
Table 3: Manual reclassification never changes whether content remediation appears, only how far a board can be reclassified.