Search & Discover - Redaction

This article covers how the Redaction functionality for Search & Discover works. 

Overview

Redaction is a new capability within Search & Discover that lets reviewers permanently obscure sensitive or non-relevant information from search results before that data is exported and shared outside the organization. Users with the appropriate permission can define a list of keywords and phrases (Find & Redact) or highlight the content in the message body they want redacted and have every exact match across their search redacted at the point of export.

Redaction is non-destructive: redactions are applied only at export time. The underlying archived content is never modified, preserving the integrity and evidential value of the archive while producing a safe-to-share output. Every redaction action is captured in the audit log.

How it works

The redaction model
  • Define: Within a search in Search & Discover, a user with the Redact permission opens the Find & Redact modal and supplies a list of keywords and phrases, or highlights terms directly in the content view using Redaction mode. 

  • Match: Terms are matched using exact match, case-insensitive, no stemming — "car" matches "car" but not "cars". Matching applies to the message body.

  • Export: Redactions are applied at the point of export. Every redacted occurrence is removed from the data.

  • Audit: Each redaction action is logged in the audit log with the user, content ID, date/time, and app

HTML Handling 

Email bodies are commonly multipart (plain text + HTML) or HTML-only; however, Redactions are applied to plain text content HTML is not redacted. This will be available in a future release and will be announced via Service Update.

Redaction does not: 

  • Modify, delete, or alter the archived data in any way — the archive remains the immutable source of truth.

  • Support fuzzy matching, wildcards, regex, or semantic matching — matching is exact only.

Using Redaction

Apply Find & Redact to a search

  1. Run your search in Search & Discover as normal.
  2. Open the Find & Redact modal (requires the Redact permission).
S&DFindandRedact.png
  1. Enter the keywords and phrases to redact. Remember: matching is exact and case-insensitive add plurals and variants explicitly if needed (e.g. add both "car" and "cars").
S&RKeywords.png
  1. Apply. Matches are highlighted in the message view so you can review what will be redacted.
redactionsearch.png
  1. Manage the redaction list at any time — terms can be added or removed, and the User Interface (UI) updates accordingly.

Alternatively, you can highlight text to be redacted by using Redact Mode as described below

  1. Open a message and click the Redact button:
redactmode1.png
  1. You will now be in Redact Mode
redactmode2.png
  1. Select the text you want to redact, then click Save.
Redactmodesave.png
  1. Click Finish Redacting to apply the redactions. The highlighted text will be removed. 
redactmode3.png

Export with redactions

  1. Start an export as normal with redactions in place.
S&DExport.png
  1. Complete the export. All redacted occurrences will be removed in the output, and the export is captured in the audit log.
S&DExport2.png

 

See also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.