Documentation forService Desk

Setup: Labs - Data masking

How to use Labs

Features in Labs are temporary. You do not need to test each feature. If your organization might benefit from a new feature and/or enhancement, go to Setup > Labs. In the list of available features, toggle the feature to On.

Some features in Labs are interconnected. You may activate more than one feature simultaneously to maximize the benefit of new Labs offerings.

As new features prove successful, SolarWinds will permanently integrate them into Service Desk. Likewise, if a feature is found to not be beneficial, it will be deleted permanently.

Enable features in Labs

  1. Navigate to Setup > Labs.

    ESM customers: navigate to Organization > Setup > Labs.
  2. In the list of available features, toggle the feature(s) of your choice to On.

Introduction to Data masking

Premier and Advanced plans only. Advanced plans are limited to system fields (title, description, and comments). Premier plans have no limitations.

When you enable data masking, Service Desk masks sensitive information so only users with the proper permissions can see the data.

About data masking

Data masking uses a classification model to hide/redact sensitive data to comply with regulatory and privacy guidelines for Protected health information (PHI), Personally identifiable information (PII), and Payment card industry data (PCI).

By masking these types of data, Service Desk protects sensitive information from unauthorized access and maintains data privacy. You can use custom fields to mask sensitive data beyond PHI, PII, and PCI.

Only authorized users can unmask data.

Where data masking applies

Data masking is applied across communication channels and to multiple fields and file formats.

PHI/PII/PCI data that does not match the standard pattern may remain unmasked.
Communication channels
  • MS Teams
  • Slack
  • Virtual Agent
  • Mobile app
Attachment file types
Data masking does not apply to file names. As needed, rename files before attaching to prevent sharing sensitive data in file names.
  • Plain text file types, including but not limited to:
    • Text (.txt)
    • CSV (.csv)
    • JSON (.json)
    • XML (.xml)
    • Log files (.log)
  • Other file types, including but not limited to:

    • Portable Document Format (PDF)
    • Word (.docx)
Outgoing email

Service Desk sends only masked fields and files. To unmask data, email recipients need to go to Service Desk.

User input text

Service Desk masks all PHI/PII/PCI text input provided by a user. Only authorized users can unmask data.

Custom fields
Data masking for custom fields is available in Labs with the Premier plan.

After enabling the data masking feature, you must configure each custom field you want protected. When properly configured, Service Desk treats all data in the custom field as sensitive. It is protected so that only authorized users can unmask the data.

Data masking for custom fields supports two custom field types: Text and Text Area.

To enable data masking on a specific custom field:

  1. Be sure that data masking is enabled for Labs by following the instructions under Enable data masking and set permissions.

  2. Navigate to Setup > Service Desk > Custom Fields.

  3. Select the specific custom field where you want to enable data masking, and then mark the check box: Mask the data in this custom field.

  4. Remember to set role-based permissions as described in Set unmasking permissions for the user roles your company wants to allow to unmask data.

What data is masked

Personally identifiable information (PII) refers to any information designed to identify an individual, either on its own or when combined with other information. PII can include, but is not limited to:

  • Full name
  • Social Security Number (SSN)
  • Driver's license number
  • Email address
  • Home address
  • Telephone number
  • Date of birth
  • Biometric records
  • Any other information that is linked or linkable to an individual

Payment card information (PCI) refers to any information related to payment cards (such as credit or debit cards) designed to be used to process transactions. PCI typically includes, but is not limited to:

  • Primary Account Number (PAN): The full credit or debit card number.
  • Cardholder Name: The name printed on the card.
  • Expiration Date: The date when the card expires.
  • Service Code: A 3- or 4-digit code used to specify restrictions or special conditions on the card.
  • Card Verification Value (CVV/CVC): A security feature for credit or debit card transactions, typically a 3- or 4-digit number printed on the card.

Protected health information (PHI) refers to any information about health status, provision of health care, or payment for health care that can be linked to a specific individual. PHI typically includes, but is not limited to:

  • Medical record numbers (MRN): Unique identifiers used by hospitals or clinics.

  • Health plan beneficiary numbers: Insurance ID numbers and health plan identifiers.

  • Patient account numbers: Specific identifiers for healthcare-related billing.

  • Clinical dates: Significant dates related to a patient (e.g., admission, discharge, or birth dates).

  • Medical device identifiers: Serial numbers for pacemakers, implants, or other medical equipment.

  • Certificate or license numbers: Health-related professional or patient certifications. Biometric identifiers: Fingerprints, voiceprints, or retinal scans used in a medical context.

Enable data masking and set permissions

Data masking can be applied to two different scopes: attachments and inputs. After enabling the masking the scope(s) for your organization in Step 1 below, PII/PCI masking is enabled. Organizations that have a need to mask PHI can then configure a more granular approach to masking data in Step 2.
  1. Identify the scope(s) for masking PII/PCI.

    Navigate to Setup > Labs > Data Masking and select the scope(s) you want to enable, and then switch the toggle to On.

    ESM customers: Navigate to Organization > Setup > Labs > Data Masking and switch the toggle to On.
    • Data Masking - Attachments: Masks sensitive information in supported attachments (.txt, .csv, .json, .xml, .log, .pdf, .docx).
    • Data Masking - Inputs: Masks sensitive information (SSNs, credit cards, PII, email addresses, phone numbers) in user inputs, including titles, descriptions, comments, and custom fields.
  2. Optionally, identify what type(s) of data to mask.

    You can configure a more granular approach to data masking by identifying the specific types of data you want masked in the different scopes.

    In Step 1 above, you made selections based on the scope, that is, where Service Desk would mask the data. But the only type of data being masked was PII/PCI.

    • If you enabled Data Masking for attachments, the selection was applied in Global Settings.
    • Likewise, you if enabled Data Masking for inputs, the selection was applied in Global Settings.

    To expand your data masking to a more granular level, navigate to Setup > Global Settings > Service Desk Settings and activate the data masking options appropriate for your organization.

    ESM customers: Navigate to Service Provider > Setup > Global Settings > Service Desk Settings to activate data masking.

    The first time you see the Global Settings Data Masking options after enabling PII/PCI in Labs, you see that only the PII/PCI options below are selected by default. An administrator needs to individually select the appropriate PHI masking options to enable them.

    Available options are:

    • Mask sensitive information (PII/PCI) in supported attachments (.txt, .csv, .json, .xml, .log, .pdf, .docx).
    • Mask Protected Health Information (PHI) in supported attachments (.txt, .csv, .json, .xml, .log, .pdf, .docx).
    • Mask sensitive information (PII/PCI) in user inputs, including titles, descriptions, comments, and custom fields.
    • Mask Protected Health Information (PHI) in user inputs, including titles, descriptions, comments, and custom fields.
  3. Set unmasking permissions for the user roles your company wants to allow to unmask data.

    1. Navigate to Setup > Account > Roles & Permissions.

    2. To the right of the role where you want to add the permission, click Add Permission.

    3. In the pop-up, select Action: Manage, and then click the dropdown under Subject and scroll to the bottom to select Unmask Data.

    4. Apply the permission to the roles you want to allow to unmask sensitive data.

      Any role with Manage > All permission can see sensitive data in attachments and fields. If you want to prevent specific roles from being allowed to unmask data, add a restriction to that role. See Add permissions for more information.
    5. If you are a Premier customer and want to enable data masking for specific custom fields, see: To enable data masking on a specific custom field.

Agents can unmask data

These options are available for agents to show or hide sensitive data:

  • At the field level, hover over the field and click .
  • At the object level (for example, incident, service request, problem, audits), click Show sensitive data.
  • At the index page level, click Show sensitive data.

Clicking displays sensitive data if the account allows inline editing (see Inline Edit on records and Inline Edit On Service Catalog Items).