Skip to main content

Compliance violations for end users

Overview

You can enable inSync end users to view and take action on violations reported for the data stored in their system. This is helpful when the Data Compliance team is small, and a huge number of violations are reported because of the nature of data stored in the data sources.

For example, financial organizations may use test or mock data that contains sample account numbers, card numbers, or other values that resemble sensitive information. inSync may report violations for this data. End users who understand the business context can review and resolve such violations without administrator intervention, allowing administrators to focus on critical or unresolved violations.

Even when end-user violation visibility is enabled, administrators retain control over the compliance workflow. Administrators can determine which violations are visible to users, which resolution actions are available, how frequently notifications are sent, and how violations are handled when users do not take action.

Supported workloads

End-user violation visibility is supported for violations detected in backed-up data from the following workloads:

  • Endpoints: Windows, macOS, and Linux

  • Microsoft 365: Exchange Online and OneDrive

  • Google Workspace: Gmail and Google Drive


📝Note: The available actions may differ depending on whether the violation is associated with a file or an email.


How end-user violation visibility works?

As an administrator, you can configure the entire workflow of how a violation moves through various phases, right from detection to resolution. You have complete control over the entire process flow which ensures that there are no gaps or critical misses.

You can enable end-user violation visibility for individual Compliance Policies. When inSync detects a violation for a policy where this setting is enabled, the violation moves through the following stages.

Workflow of a violation with end user violation visibility enabled

Step 1: Scan the protected data

inSync scans the backed-up data for sensitive information based on the rules defined in the applicable Compliance Policy.

Step 2: Detect and create the violation

When matching sensitive information is found, inSync creates a violation and associates it with the user who owns the affected data.

Step 3: Notify the user

The user receives an email containing a summary of the reported violations and instructions to review them.

Step 4: Display the violation to administrators

The violation appears on the Active tab of the Sensitive Data Governance Dashboard, on the File Violations page. Its status is displayed as Pending on User.

Step 5: Display the violation to the user

The user signs in to the inSync Web panel and opens the compliance violations page to review the affected data, violation details, and the actions available to them.

Step 6: User reviews and resolves the violation

Depending on the policy configuration and the type of violation, the user can select one of the available resolution actions: Resolve, Acceptable Risk, False Positive, or Delete.

Step 7: Update the violation status

After the user submits an action, the violation status is updated. Depending on the selected action and the workflow configuration, the violation remains on the Active tab or moves to the Resolved tab.

Step 8: Apply automatic resolution when required

If the user does not take action within the configured period, inSync applies the default resolution behavior defined in the Compliance settings.

Step 9: Record the action for administrator review

Actions performed by end users are reflected in the Sensitive Data Governance Dashboard and can be reviewed by administrators through the violation details, history, and available compliance reports.

You can enable inSync client users to see violations per policy. The following workflow diagram shows how a file violation moves through different stages when End user violation visibility is enabled .

clipboard_e4543d8bbdae07b26cc06bb1fd484cc9b.png


📝 Note

  • C means that the option is Configurable.

  • The flow for email violations is the same. The only exception is the False Positive resolution as it is not applicable for emails.

  • The diagram also takes into consideration that all the default options are enabled for End User Violation Visibility.


The following is the sequence of events that are triggered when inSync finds a violation for a policy that has end user violation visibility criteria enabled:

  1. inSync scans the backed-up data for violations as per the details defined in the Compliance Policy.

  2. The user receives an email notification about the violations reported for the data owned by the user.
    The file violations are also displayed on the Active tab, in the Sensitive Data Governance Dashboard - File Violation page. The status of such a violation is Pending on User. The process is the same for Email violations.

  3. The user logs in to inSync Web using the link in the email to view details of the violations.

  4. The user resolves the violations using the available options. The resolution options visible to the end user depend on the resolution types available for end users.

  5. Depending on the resolution option selected by the user, the violation ends up either in the Active tab or in the Resolved tab on the Sensitive Data Governance Dashboard. If no one takes any action, the violation will be auto-resolved as per the defined criteria in Compliance settings. For more information, see Modify Compliance Settings.

All the activities of the administrator and the end user are logged in Admin Audit Trail and User Audit trail respectively. The details are also available in the Non-Compliant File report and Non-Compliant Email report.

Resolution actions available to end users

Resolve

The user selects Resolve when corrective action has already been taken or when the affected data no longer requires further remediation. The violation is marked as resolved based on the configured workflow.

Acceptable Risk

The user selects Acceptable Risk when the violation is valid but the data is required for an approved business purpose. This action records that the risk has been reviewed and accepted.

False Positive

The user selects False Positive when the detected content is not actually sensitive or is incorrectly classified. For file violations, inSync whitelists the file hash, automatically resolves matching violations for that file, and excludes the same file from future compliance scans.

Important: False Positive is available only for file violations. It is not available for email violations because email content cannot be uniquely identified using a file hash.

Delete

Depending on the policy configuration, users may see one or both of the following options:

  • Delete from Source: Deletes the affected item from the source data location.

  • Delete from Source and Snapshot: Deletes the affected item from the source and removes the non-compliant versions from applicable backup snapshots.

Only the non-compliant versions are targeted for deletion. Older compliant versions may remain available for restore, where applicable.

Important: Data associated with users who are on Legal Hold is not deleted.

Configure Settings related to end user violation visibility

When you enable end-user violation visibility for a Compliance Policy, default settings are applied. Review and update the settings based on your organization's compliance requirements.

Notification frequency

Specify how frequently users receive violation summary emails. Learn more.

Visibility criteria

Define which violations are visible to end users. Use this setting to ensure that users see only the violations they are expected to review. Learn more

Resolution options

Select the resolution actions that users are allowed to perform. The available options may include Resolve, Acceptable Risk, False Positive, and Delete. Learn more

Quarantine visibility

Enable this setting when users should be allowed to view files that have been quarantined because of a compliance violation.

Automatic resolution

Configure the period for which a violation can remain pending on the user and specify the default action to apply when the user does not respond.

Monitor end-user actions

Administrators can monitor end-user activity from the Sensitive Data Governance Dashboard. Review the violation status, selected resolution action, user comments where available, and the violation history to verify that the required remediation was completed.

Use compliance reports and violation details to identify:

  • Violations awaiting user action

  • Violations automatically resolved because the user did not respond

  • Violations resolved as Acceptable Risk

  • Files marked as False Positive

  • Deletion actions initiated by users

  • Violations that remain active or require administrator review

Things to consider

  • End-user violation visibility must be enabled separately for each applicable Compliance Policy.

  • Available resolution actions depend on the policy configuration and the violation type.

  • False Positive is supported for file violations only and is not available for email violations.

  • Files belonging to users on Legal Hold cannot be deleted.

  • The Delete from Source and Snapshot action applies only to non-compliant versions in applicable snapshots.

  • If the user does not act within the configured period, the automatic resolution settings are applied.

  • Administrators should verify end-user actions through the Sensitive Data Governance Dashboard and compliance reports.

When you enable End-user violation visibility for a policy, the default configured settings are auto-applied. If you want, you can configure these settings before you enable end users to view violations. The following settings are available:

  1. Define the notification frequency for the violation summary email that is sent to end users. Learn more.

  2. Violations visibility criteria applicable for end-users. Learn more.

  3. Configure the resolution statuses that will be available to end users. Learn more.

Did this answer your question?