Introduction

Sensitive information is often hidden across growing enterprise datasets. Discovering it, determining appropriate protections, and managing access can involve significant manual effort. As data, schemas, and user roles change, approved controls can become misaligned with organizational policies and access requirements.

A custom framework built on Oracle AI Data Platform (AIDP) can provide a governed environment for sensitive data discovery, applying masking, role-based access control, human approval, and continuous checks on the alignment of deployed controls with approved policy.

This article outlines an AI-assisted, human-controlled custom approach to sensitive-data masking and role-based access control using AIDP and OCI Generative AI.


One governed path from discovery to assurance

The solution uses three connected layers. The first brings together the data, protection rules, and user roles. The second finds sensitive information and records the steward’s decisions. The third gives users protected access and checks that the controls continue to work.

Figure 1. The complete customer journey from governed inputs to protected data products and continuous assurance.
Figure 1. Reference workflow from configured inputs to protected outputs and ongoing policy verification.


Layer 1: Data & Configuration

The journey begins with AIDP ingesting data from enterprise sources into a storage layer and making them available for processing.

Governance choices can be supplied by users in two ways:

OptionHow it worksBest suited for
Configuration filesApproved files define sensitive-data knowledge, masking rules, roles, environments, and notification settings.Automated deployments and teams that manage policy through controlled files
Configuration InterfaceA guided UI captures the allowed choices and generates files in the format expected by the workflow.Business-friendly setup without direct file editing


Figure 2. The Governance Configuration Studio provides guided policy setup without requiring users to edit configuration files directly.
Figure 2. A configuration interface provides guided policy setup without requiring users to edit configuration files directly.


Layer 2: Governance & Review

After ingestion, the AIDP-based framework examines column names, data types, patterns, and data samples. This helps identify obvious sensitive fields such as email addresses and identity numbers, as well as less familiar columns whose names may not clearly describe their contents.

The framework records the evidence and prepares classifications and masking recommendations for the data steward. The recommendations appear in a user interface (Steward Decision Console), where the steward can approve, reject, or reopen decisions. Only the steward’s committed decisions become approved policy.


Layer 3: Protected access and continuous assurance

After the steward approves the policy, the framework creates the protected data products that consumers can use. The original source remains unchanged and is not the normal access path for analysts or business users.

Customers can configure the framework and choose how the protected data is produced and accessed:

Configurable choiceAvailable options
Protection typeCreate protected logical views or a physically masked table copy
View typeUse session views, shared views, or permanent role-specific views
Role treatmentMask, hash, redact, generalize, allow, or deny a sensitive field
EnvironmentApply different rules in production and non-production
Assurance checksSelect policy, schema, view, permission, and publication checks


For example, an analyst may see a partially masked CUSTOMER_EMAIL, a hashed CUSTOMER_ID, and an age range instead of a birth date. A business user may receive access based on an approved role policy while an auditor may see additional governed fields where the policy permits it. The framework uses roles and permissions information on AIDP when publishing protected access.

Logical protection creates different governed views of the same source. Physical protection creates a separate masked dataset for non-production, data exchange, or downstream processing. The source remains unchanged in both cases. Configured verification checks then compare approved policies with current tables, protected outputs, and permissions, recording any difference for correction.

Figure 3. Approved masking and role policies create different governed results for analysts, business users, and auditors.
Figure 3. Approved masking and role policies create different governed results for analysts, business users, and auditors.



Intelligent Automation with AIDP and OCI Generative AI

The three-layer architecture creates the control foundation. OCI Generative AI and AIDP make that foundation faster to operate, easier to understand, and reusable across datasets and business domains.

Start with knowledge or start from zero

Not every organization begins with the same level of sensitive-data knowledge. The solution supports three discovery modes:

Discovery modeHow it worksWhen it helps
Policy-seeded discoveryUses the organization-defined column names, business terms, patterns, and existing policiesThe organization already understands much of its sensitive data
Zero-start discoveryUses profiling evidence and OCI Generative AI to identify potential sensitive fields without a predefined customer listTeams are exploring a new or poorly documented dataset
Hybrid discoveryCombines customer knowledge, deterministic rules, and Gen AI recommendationsUseful when established policies exist but additional discovery is desired.

Each recommendation can include a table and column, proposed sensitive-data category, masking rule, confidence score, and plain-language reason. This gives the steward more context than a simple sensitive-or-not-sensitive label.


Steward decisions in natural language

A steward review interface gives reviewers a structured view of the recommendations.

It also supports commands such as: “Reject phone number from customer profile”. AI interprets the request through NL2SQL, while deterministic checks confirm the table, column, and allowed action before anything is saved. The steward remains the decision-maker, and only committed approvals become policy.

Figure 4. The Steward Decision Console brings recommendations, supporting evidence, and human decisions into one review experience.
Figure 4. A Steward Review Interface brings recommendations, supporting evidence, and human decisions into one review experience.


Turn evidence into agent-assisted communication

A governance agent built on AIDP retrieves governed evidence using approved SQL-backed tools. It identifies whether the request relates to a steward decision or an assurance finding, prepares the correct business explanation, and sends a formatted email through the configured email service (OCI Email Delivery/ OCI Notifications).

Agent inputEmail producedWhat the recipient learns
Approved steward decisionsSteward Approval SummaryWhat was approved, which masking policy applies, and when the decision takes effect
Verified assurance findingsGovernance Assurance and Policy Drift ReportWhat changed, which data or access is affected, the severity, and the recommended action

The agent explains and routes verified evidence. It does not approve classifications, apply masking, change permissions, or detect drift on its own.

Figure 5. The AIDP Governance Steward Agent prepares separate Steward Approval and Governance Assurance reports from governed evidence.
Figure 5. An AIDP Governance Steward Agent prepares separate Steward Approval and Governance Assurance reports from governed evidence.


How AIDP holds the process together

AIDP capabilityCustomer value
Shared data and AI foundationProfiling, evidence, protected data products, permissions, and AI assistance operate close to the data
Configuration-driven operationCustomers can switch discovery, protection, access, environment, and assurance behavior without rebuilding the workflow
Spark-based processingProfiling and masking can scale beyond small demonstration datasets
Catalog and access permissionsProtected data products can be published with controlled, role-based access
Persistent governance evidenceRecommendations, decisions, generated outputs, and assurance findings remain available for review and audit
Integrated agent workflowsAgents can retrieve trusted evidence, explain it for different audiences, and coordinate communication
Reuse of OCI servicesExisting OCI data, identity, storage, Gen AI, and email services can support the solution


Conclusion

Sensitive-data governance works best as a continuous process rather than a one-time masking exercise. AIDP can turn masking and role-based access into a repeatable governance lifecycle – configurable discovery, human approval, protected data products and continuous assurance. Carefully controlled AI assistance can help organizations onboard sensitive data faster while keeping policy decisions accountable.


Learn more