Why Classification Matters for Compliance
Auditors ask: “Where is your PII?” You need an answer that isn’t “let me check.” AnomalyArmor’s auto-classification and custom tags give you:- Instant PII inventory across all databases
- Audit-ready exports of sensitive data locations
- Continuous monitoring as new tables appear
Common Compliance Scenarios
SOC 2 / Security Audits
Auditor asks: “Show me all tables containing customer data.” Your response:- Go to Assets → Filter → Classification →
pii:* - Export the filtered list
- Hand auditor a complete inventory
GDPR Data Mapping
Requirement: Know where personal data is stored. Your workflow:- Auto-classification tags emails, names, addresses automatically
- Filter by
pii:email,pii:name,pii:address - Document each table’s purpose and retention policy using descriptions
Access Reviews
Requirement: Verify who can access sensitive data. Your workflow:- Tag sensitive tables:
sensitivity:high,sensitivity:medium - Cross-reference with database permissions
- Use tags to prioritize access review scope
Recommended Tag Structure
| Tag | Use For |
|---|---|
pii:email, pii:phone, etc. | Auto-classified PII (automatic) |
sensitivity:high | Manually flagged critical data |
compliance:reviewed | Audit trail of reviewed assets |
compliance:gdpr-scope | GDPR-relevant data |
retention:30-days | Data retention policy |
Audit Preparation Checklist
Staying Compliant Over Time
New tables appear. Schemas change. Stay ahead:- Alert on new PII: Create rule for “New asset detected” + filter by auto-classification
- Review cadence: Monthly review of
compliance:needs-reviewtagged assets - Discovery schedule: Run frequently enough to catch new tables before auditors do
