Classify Fields using Tags

Define custom tags and apply them to fields


PREVIEW
GraphOS Agent Services is in private preview. You need an Apollo team member to help you onboard. Use this documentation for reference only.
note
To classify fields using tags, you need an Org Admin role.

A tag is a label that rules reference to determine whether they apply to a field. Use tags to create a group of fields together that share the same access decisions. Then, create rules to restrict or allow access on tags for specific clients, groups, or users.

Start with the predefined tags. Create a custom tag when a field needs an access decision that predefined tags don't cover, then apply that tag to every field the decision should include.

Reuse the predefined tags

Apply these tags before you create a new one:

TagUse it for
sensitivity:PIINames, email addresses, phone numbers, and other personal data
sensitivity:financialPayments, billing, compensation, and other financial data
require-approvalMutations that require approval

A field can carry more than one tag. Add a second tag when that field needs a separate access decision. For example, Customer.email can carry both sensitivity:PII and require-approval.

Services installed from the catalog include default tags applied to fields. When you connect a service, the Tags step lists fields Apollo already tagged. Many services tag every mutation with require-approval. Review those tags, add the tags your organization needs, and continue. You can change the tags later.

Create a custom tag

Create a new custom tag when the default tags don't cover what you need.

Name custom tags as category:name, in the same form as the predefined tags. Reuse a name that already exists in the organization when the fields should share one rule.

  1. In GraphOS Agent Services, open Services and select the service.

  2. Open Fields.

  3. Select the field to open the field inspector.

  4. Select Create a new tag.

  5. Enter the tag name, for example, sensitivity:health.

  6. Enter a short description of what the tag means, for example, "Health information that stays denied until a director approves access."

  7. Select Create and apply. This step applies the tag to the field you have open.

Apply a tag to one field

  1. Open the service and select Fields.

  2. To find the field, search by field or tag, or filter to Untagged.

  3. Select the field to open the field inspector.

  4. Search for the tag and select it. Tags on this field shows the tag as added.

  5. Select Review.

To undo a tag you haven't applied yet, select Discard, or select the tag again.

Apply a tag to multiple fields

  1. Open the service and select Fields, then select Bulk edit.

  2. Select each field that should share the tag. Hold Shift to select a range of fields.

  3. Select Add tag at the top where it says X fields selected.

  4. Search for the tag and select it. Fields that already have that tag stay unchanged.

  5. Select Review changes.

To take a tag off the selection, select Remove tag at the top where it says X fields selected and choose the tag. Fields that don't have that tag stay unchanged.

Review the changes

The review dialog lists each field and whether you added or removed a tag. Read What this changes for agents before you confirm.

When you add or remove a tag for a field that is already covered by a rule, proceed with caution.

  • Adding a tag that a Deny or Mask rule already targets blocks or masks those fields for every client the rule targets. Clients that were previously reading the field will lose access.

  • Adding a tag that an Allow rule already targets grants access to those fields for every client the rule targets.

  • Adding a tag that no rule targets leaves access unchanged. Create the rule in Configure Access Rules.

  • Removing a tag from fields a Deny or Mask rule already targets now opens up access to those fields. Clients that were previously blocked can now read the field, or see the stored value instead of a mask.

  • Removing a tag from fields an Allow rule already targets removes that grant. Clients that were previously allowed will lose access unless another rule still allows the field.

Select Apply changes to save your changes. GraphOS Agent Services enforces the new tags within a minute.

Review rules that apply to a tag in the service

Open the service and select Rules. Each row is a tag applied to fields in that service, the rule that targets the tag, the effect, and how many fields on the service carry the tag.

Tag fields after a schema update

When you update a service to a newer catalog schema, existing tags and rules stay on the fields they already cover. New fields arrive untagged.

  1. Open the service and select Fields.

  2. Filter to Untagged.

  3. Apply the tags you need, then review and apply.