Skip to content

Protection levels & workflows

Protection levels form a fixed hierarchy. Every step reduces data exposure and may lock or remove additional data classes.

LevelEffectRecoverable?
Original dataComplete source data is available.Initial state
PseudonymizedIdentities are replaced by stable, explicit labels such as [Person 1]. Original media and mappings are protected.Yes, while recovery material exists
Identifying data removedIdentifying data is removed without a stable replacement identity.Yes, while the protected original exists
Permanently anonymizedOriginal data, media, mappings, and recovery material are destroyed.No

The operation covers more than the visible transcript. StoryVault also governs titles and descriptions, speakers and participants, media and thumbnails, attachments, shares and exports, and derived data used by search, AI chat, knowledge stores, graphs, and qualitative coding. Corrected transcript content is processed as well, and users see the version allowed by the active level.

Tenant policy is the minimum protection. A project may be stricter but never less strict than its tenant; a session may be stricter but never less strict than its project. A project operation includes its sessions, while a session operation affects only that session.

  1. Open the project or session in the correct tenant.
  2. Open the Data protection and protection level shield menu.
  3. Select Pseudonymized, Identifying data removed, or Permanently anonymized.
  4. Select a purpose and enter the displayed confirmation phrase exactly.
  5. For a project, review the draft plan. It can still be changed or discarded.
  6. Start the plan with the visible play button.
  7. Complete DPA approval and monitor progress in data protection administration.

Operations that increase protection require the current user’s DPA capability, a purpose, exact confirmation, and an audit trail. They do not require a fresh login.

Pseudonymized or redacted data can be restored only if tenant policy permits original data, recovery material still exists, no legal hold or manual review blocks the operation, and the current user is a DPA in that tenant.

  1. Open the shield menu and select Original data.
  2. Provide the purpose and exact confirmation phrase.
  3. Complete the security confirmation and start the operation.
  4. Monitor progress in data protection administration.

The security confirmation is valid for ten minutes and is renewed only by a real password, Microsoft, or magic-link sign-in. Tenant switching and token refresh do not renew it.

Moving from pseudonymized or redacted data to permanent anonymization destroys the remaining recovery material. Moving from permanently anonymized data back to a less restrictive level is impossible.

During processing, the affected scope remains locked. A partial or failed operation never exposes originals. An assigned DPA or platform super admin can find the safe recovery entry and continue the existing auditable run after the underlying issue is fixed.