The workflow is deliberately boring: connect a source, review what's found, apply a control, keep the proof. No agents on endpoints, no data leaving your boundary.
Credentials are read-only and encrypted per tenant. You decide which schemas, buckets, or repositories are in scope. Nothing is scanned by default.
Each finding carries the detected entity type, row count, confidence score, and the context that produced the classification.
Masking, in-place anonymisation, or a synthetic export — the control runs inside your environment, and the output lands directly in staging or object storage.
What was found, what was changed, who approved it, and when — recorded in a hash-chained log as the work happens.