Purpose and location
Set finite audit and chat retention, inspect policy coverage and prepare a redacted user-data review without exposing customer content.
Open Platform → Data Governance. The available controls depend on the active edition, module entitlement, role and tenant scope.
Before you start
Platform changes can affect every tenant. Confirm a recent verified backup, an audit owner and a maintenance window whenever the operation can restart services or change entitlement.
Capture the current value or export the affected records before a bulk or routing change. This gives the operator a precise comparison point and makes a supported transaction undo easier to assess.
Step-by-step workflow
Complete the steps in order. Do not combine an initial configuration with unrelated cleanup; small, attributable changes are easier to test and reverse.
- Select the tenant scope and review Needs decision first.
- In Audit and chat retention, keep the policy unbounded until legal and operational approval exists, or select a window from 30 to 3650 days.
- Save the policy and confirm the policy_update event in Audit Log before the next hourly cleanup.
- Search Data-subject triage by name, email or extension.
- Download the redacted subject inventory with OPERATIONS.MANAGE and attach it only to the protected privacy case.
- Download the tenant inventory for the periodic privacy review.
Field reference
Use the reference below while completing the form. Fields hidden by edition, module entitlement or role are intentionally unavailable to the signed-in user.
- Status
- Managed, partial, unbounded, lifecycle-controlled or empty.
- Records
- Aggregate record count; file-backed capture data is reported without enumerating files.
- Retention
- Finite policy window, object lifecycle or an explicit missing expiry.
- Audit events
- Tenant-wide 30-3650 day policy. Empty means no automatic deletion.
- Softphone chat
- Tenant-wide 30-3650 day policy. Cleanup removes message rows, not just the read state.
- Oldest / newest
- Time boundaries used to identify unexpectedly old retained data.
- Data-subject search
- Portal user lookup by name, email or assigned extension.
- Subject inventory
- Audited JSON containing profile and aggregate data-footprint ranges, without content, files, secrets or raw payloads.
- Tenant inventory JSON
- Versioned, redacted report with counts, windows and gaps but no customer content or secrets.
Acceptance checks
A saved record is only the beginning of validation. Run every relevant check below and retain the call-session ID, time and result when telephony is involved.
- Confirm a tenant administrator cannot select, search or export another tenant.
- Set short test policies in an isolated tenant, backdate test records and confirm the hourly cleanup removes only data older than the cutoff.
- Verify retention.audit_event_purge and retention.softphone_chat_purge contain only counts, cutoff and policy days.
- Export a subject inventory and confirm message bodies, SIP credentials, PINs, media paths and raw CDR/SIP data are absent.
- Verify Audit Log contains data_governance.subject_inventory_export with the actor and subject ID.
Common mistakes and safe recovery
If a check fails, stop adding changes. Restore the previous value or use a supported transaction undo, regenerate PBX configuration, then repeat the smallest failing test.
- Shortening a window permanently deletes older rows on the next cleanup pass; verify legal hold and backup readiness first.
- The subject inventory is triage evidence, not a complete statutory data-subject response.
- Never use this screen as a shortcut around identity verification, approval, recording-consent requirements or the formal erasure workflow.
What to include in a support case
Provide the tenant, module and object name, local time with timezone, expected result, observed result and the most recent successful state. For a call problem, include the logical call-session ID and the redacted SIP/SDP text diagnostic before requesting PCAP.
Never paste passwords, private keys, raw license payloads or unredacted customer media into a ticket. Use the one-time diagnostic grant and attachment controls when support requests additional evidence.