Introduction
Sensitive information is often hidden across growing enterprise datasets. Discovering it, determining appropriate protections, and managing access can involve significant manual effort. As data, schemas, and user roles change, approved controls can become misaligned with organizational policies and access requirements.
A custom framework built on Oracle AI Data Platform (AIDP) can provide a governed environment for sensitive data discovery, applying masking, role-based access control, human approval, and continuous checks on the alignment of deployed controls with approved policy.
This article outlines an AI-assisted, human-controlled custom approach to sensitive-data masking and role-based access control using AIDP and OCI Generative AI.
One governed path from discovery to assurance
The solution uses three connected layers. The first brings together the data, protection rules, and user roles. The second finds sensitive information and records the steward’s decisions. The third gives users protected access and checks that the controls continue to work.

Layer 1: Data & Configuration
The journey begins with AIDP ingesting data from enterprise sources into a storage layer and making them available for processing.
Governance choices can be supplied by users in two ways:
| Option | How it works | Best suited for |
| Configuration files | Approved files define sensitive-data knowledge, masking rules, roles, environments, and notification settings. | Automated deployments and teams that manage policy through controlled files |
| Configuration Interface | A guided UI captures the allowed choices and generates files in the format expected by the workflow. | Business-friendly setup without direct file editing |

Layer 2: Governance & Review
After ingestion, the AIDP-based framework examines column names, data types, patterns, and data samples. This helps identify obvious sensitive fields such as email addresses and identity numbers, as well as less familiar columns whose names may not clearly describe their contents.
The framework records the evidence and prepares classifications and masking recommendations for the data steward. The recommendations appear in a user interface (Steward Decision Console), where the steward can approve, reject, or reopen decisions. Only the steward’s committed decisions become approved policy.
Layer 3: Protected access and continuous assurance
After the steward approves the policy, the framework creates the protected data products that consumers can use. The original source remains unchanged and is not the normal access path for analysts or business users.
Customers can configure the framework and choose how the protected data is produced and accessed:
| Configurable choice | Available options |
| Protection type | Create protected logical views or a physically masked table copy |
| View type | Use session views, shared views, or permanent role-specific views |
| Role treatment | Mask, hash, redact, generalize, allow, or deny a sensitive field |
| Environment | Apply different rules in production and non-production |
| Assurance checks | Select policy, schema, view, permission, and publication checks |
For example, an analyst may see a partially masked CUSTOMER_EMAIL, a hashed CUSTOMER_ID, and an age range instead of a birth date. A business user may receive access based on an approved role policy while an auditor may see additional governed fields where the policy permits it. The framework uses roles and permissions information on AIDP when publishing protected access.
Logical protection creates different governed views of the same source. Physical protection creates a separate masked dataset for non-production, data exchange, or downstream processing. The source remains unchanged in both cases. Configured verification checks then compare approved policies with current tables, protected outputs, and permissions, recording any difference for correction.

Intelligent Automation with AIDP and OCI Generative AI
The three-layer architecture creates the control foundation. OCI Generative AI and AIDP make that foundation faster to operate, easier to understand, and reusable across datasets and business domains.
Start with knowledge or start from zero
Not every organization begins with the same level of sensitive-data knowledge. The solution supports three discovery modes:
| Discovery mode | How it works | When it helps |
| Policy-seeded discovery | Uses the organization-defined column names, business terms, patterns, and existing policies | The organization already understands much of its sensitive data |
| Zero-start discovery | Uses profiling evidence and OCI Generative AI to identify potential sensitive fields without a predefined customer list | Teams are exploring a new or poorly documented dataset |
| Hybrid discovery | Combines customer knowledge, deterministic rules, and Gen AI recommendations | Useful when established policies exist but additional discovery is desired. |
Each recommendation can include a table and column, proposed sensitive-data category, masking rule, confidence score, and plain-language reason. This gives the steward more context than a simple sensitive-or-not-sensitive label.
Steward decisions in natural language
A steward review interface gives reviewers a structured view of the recommendations.
It also supports commands such as: “Reject phone number from customer profile”. AI interprets the request through NL2SQL, while deterministic checks confirm the table, column, and allowed action before anything is saved. The steward remains the decision-maker, and only committed approvals become policy.

Turn evidence into agent-assisted communication
A governance agent built on AIDP retrieves governed evidence using approved SQL-backed tools. It identifies whether the request relates to a steward decision or an assurance finding, prepares the correct business explanation, and sends a formatted email through the configured email service (OCI Email Delivery/ OCI Notifications).
| Agent input | Email produced | What the recipient learns |
| Approved steward decisions | Steward Approval Summary | What was approved, which masking policy applies, and when the decision takes effect |
| Verified assurance findings | Governance Assurance and Policy Drift Report | What changed, which data or access is affected, the severity, and the recommended action |
The agent explains and routes verified evidence. It does not approve classifications, apply masking, change permissions, or detect drift on its own.

How AIDP holds the process together
| AIDP capability | Customer value |
| Shared data and AI foundation | Profiling, evidence, protected data products, permissions, and AI assistance operate close to the data |
| Configuration-driven operation | Customers can switch discovery, protection, access, environment, and assurance behavior without rebuilding the workflow |
| Spark-based processing | Profiling and masking can scale beyond small demonstration datasets |
| Catalog and access permissions | Protected data products can be published with controlled, role-based access |
| Persistent governance evidence | Recommendations, decisions, generated outputs, and assurance findings remain available for review and audit |
| Integrated agent workflows | Agents can retrieve trusted evidence, explain it for different audiences, and coordinate communication |
| Reuse of OCI services | Existing OCI data, identity, storage, Gen AI, and email services can support the solution |
Conclusion
Sensitive-data governance works best as a continuous process rather than a one-time masking exercise. AIDP can turn masking and role-based access into a repeatable governance lifecycle – configurable discovery, human approval, protected data products and continuous assurance. Carefully controlled AI assistance can help organizations onboard sensitive data faster while keeping policy decisions accountable.
