Agent365 Data Security and Purview¶
Atlanta, USA
Last updated: 2026-08-04
References
Data security objective¶
Protect sensitive information in prompt, grounding, tool, and response flows with policy-driven controls that remain auditable at enterprise scale.
Purview-aligned controls¶
| Control | Implementation focus |
|---|---|
| Classification | Label sensitive content and map to data zones |
| Data loss prevention (DLP (data loss prevention)) | Detect and block risky sharing and exfiltration |
| Insider and communication risk | Correlate risky user and interaction patterns |
| Records and retention | Preserve evidence for compliance and investigation |
| eDiscovery support | Enable traceable investigation workflows |
Agent365 data control blueprint¶
- Classify and label core enterprise data stores before broad onboarding.
- Apply DLP (data loss prevention) controls to high-risk prompt and output channels.
- Restrict unmanaged external transfer paths.
- Create policy exception process with explicit expiry and owner.
- Validate retention and eDiscovery alignment for critical workflows.
Validation checklist¶
- Sensitive-data labels are applied and testable in target workloads.
- DLP (data loss prevention) rules cover prompt and response pathways for high-risk scenarios.
- Exception approvals are logged with expiry and review owner.
- Data-residency and retention requirements are documented by region.
Business example¶
A healthcare operations agent drafts internal summaries from sensitive records. Purview labels and DLP (data loss prevention) controls prevent external sharing, while retention and audit policies preserve interaction evidence for compliance review.