Skip to main content
This recipe creates a PII policy that masks personal data, assigns it to a Guardian, and verifies it with a real call. See Guard Policy for the model.

1. Create & assign the policy

Open your Guardian → PoliciesAdd on Input PoliciesCreate & Assign Policy. Name it (e.g. PII Masking Policy), set Policy Type = PII, and create. It starts at v0.1.0 and opens in the editor.
Create a PII policy

Create a PII policy

2. Add rules

Use Add in the editor to add rules one at a time, choosing the kind: For masking, set policy_type: MASKING and a mask word (e.g. PHONE_NUMBER) — matches become [PHONE_NUMBER_1].
A masking NER rule

A masking NER rule

Faster: load JSON

Choose JSON to paste a whole policy at once. Allowed top-level keys are ner, regex, keyword:
The editor validates before saving. Save creates a new version.
Loading a PII policy as JSON

Loading a PII policy as JSON

3. Apply the new version

Saving created a new version (the number only has to be unique for this policy — it needn’t be higher than the last). Saving doesn’t apply it — you must re-point (pin) the Guardian to the new version, or the change won’t take effect. See Version & apply a policy update.
Re-point the Guardian to the new version

Re-point the Guardian to the new version

4. Verify

Send a test call with PII and confirm it’s masked:
A masked response ("action":"MASK", processed_content with [PHONE_NUMBER_1]) confirms it works. Review it in Opticon.
Confirm the MASK in Opticon

Confirm the MASK in Opticon

Starfort ships a comprehensive default PII policy (Korean phone, RRN, passport, card, email, …). Loading it via the JSON editor is the quickest start — then trim to what you need.