Protection levels & workflows
Protection levels form a fixed hierarchy. Every step reduces data exposure and may lock or remove additional data classes.
The four levels
Section titled “The four levels”| Level | Effect | Recoverable? |
|---|---|---|
| Original data | Complete source data is available. | Initial state |
| Pseudonymized | Identities are replaced by stable, explicit labels such as [Person 1]. Original media and mappings are protected. | Yes, while recovery material exists |
| Identifying data removed | Identifying data is removed without a stable replacement identity. | Yes, while the protected original exists |
| Permanently anonymized | Original data, media, mappings, and recovery material are destroyed. | No |
The operation covers more than the visible transcript. StoryVault also governs titles and descriptions, speakers and participants, media and thumbnails, attachments, shares and exports, and derived data used by search, AI chat, knowledge stores, graphs, and qualitative coding. Corrected transcript content is processed as well, and users see the version allowed by the active level.
Tenant, project, and session
Section titled “Tenant, project, and session”Tenant policy is the minimum protection. A project may be stricter but never less strict than its tenant; a session may be stricter but never less strict than its project. A project operation includes its sessions, while a session operation affects only that session.
Protect a project or session
Section titled “Protect a project or session”- Open the project or session in the correct tenant.
- Open the Data protection and protection level shield menu.
- Select Pseudonymized, Identifying data removed, or Permanently anonymized.
- Select a purpose and enter the displayed confirmation phrase exactly.
- For a project, review the draft plan. It can still be changed or discarded.
- Start the plan with the visible play button.
- Complete DPA approval and monitor progress in data protection administration.
Operations that increase protection require the current user’s DPA capability, a purpose, exact confirmation, and an audit trail. They do not require a fresh login.
Restore original data
Section titled “Restore original data”Pseudonymized or redacted data can be restored only if tenant policy permits original data, recovery material still exists, no legal hold or manual review blocks the operation, and the current user is a DPA in that tenant.
- Open the shield menu and select Original data.
- Provide the purpose and exact confirmation phrase.
- Complete the security confirmation and start the operation.
- Monitor progress in data protection administration.
The security confirmation is valid for ten minutes and is renewed only by a real password, Microsoft, or magic-link sign-in. Tenant switching and token refresh do not renew it.
Moving from pseudonymized or redacted data to permanent anonymization destroys the remaining recovery material. Moving from permanently anonymized data back to a less restrictive level is impossible.
Failure handling
Section titled “Failure handling”During processing, the affected scope remains locked. A partial or failed operation never exposes originals. An assigned DPA or platform super admin can find the safe recovery entry and continue the existing auditable run after the underlying issue is fixed.