Skip to main content
Org admins control what leaves the organization toward AI providers, how long each kind of record is kept, and what happens when the organization is closed. These controls live under Settings. All of them need the org admin role.

Mask sensitive values in AI prompts

Data anonymization masks IP addresses, email addresses, internal hostnames, internal URLs and credential-shaped strings in prompts before they go to an external AI provider. The response is unmasked on the way back, so tool queries still reach your real hosts.
1

Open AI Providers

Click Settings, then the AI Providers tab.
2

Find Data Anonymization

The Data Anonymization switch is on this tab. It is on unless an admin has turned it off.
3

Change it if policy requires

Click the switch. A message confirms Anonymization enabled or Anonymization disabled. Every change is recorded in the audit log, and a support person viewing as you cannot flip it.
Masking can reduce the model’s ability to correlate infrastructure, which is where investigation quality comes from. Keep it on when policy says raw infrastructure detail must not leave your tenant. To see the effect, open Security, then the AI Governance tab (Business). It shows calls over the last 30 days with the share that were anonymized, and each call shows Anonymized? as Yes or No.

Set retention

1

Open the retention table

Click Settings, then Preferences, and scroll to Data Retention. The same table is on the Retention tab of the Security page.
2

Set the window

Each row is a type of record, such as alerts, investigations, audit logs or findings. Change Retain Days and click the check mark.
3

Choose delete or archive

Purge Mode is Delete or Archive. Archive is disabled for record types that cannot be archived. A saved policy that cannot be archived says that nothing is being purged. Switch it to Delete if removal is what you want.
4

Enable and run

The Enabled switch turns a policy on or off. Run Now applies it immediately. Last Run and Last Purged show what happened.
Each record type starts with a default window, so a new organization is covered before you touch anything. Deleting an alert also deletes its investigations, with their findings, actions and reports. An alert is dated from when it resolved, so one that recovered through its own webhook is kept for your window. Your plan sets the audit log retention ceiling, shown on the Subscription page under Plan limits.
A purge is permanent. Export evidence first if an auditor may ask what your policy was.

Export retention evidence

Click Export evidence at the top right of Data Retention. You download a zip with:
  • Your retention configuration and the last purge run, as JSON for a script.
  • The same information in prose for an auditor.
  • A manifest with a checksum for each file.
Missing record types are filled in with their defaults, so nothing being purged is left out. Two things the export states rather than implies. A policy asking to archive a type that cannot be archived purges nothing, even though it records a run. And the purge history lists only runs that removed rows, so an empty history is not proof that retention never ran. The download is recorded in the audit log.

Delete the organization

The Delete this organization card is the last one on Preferences.
1

Cancel any paid plan

An organization whose paid subscription still grants access cannot be deleted. Cancel it on the Subscription page first. Deleting does not cancel billing.
2

Export what you want to keep

Deletion covers alerts, investigations, runbooks, SLOs, connectors, API keys, cards and member accounts.
3

Delete

Click Delete this organization, type the organization’s slug when asked, and click Delete organization.

What happens next

The organization stops resolving at once. Everyone signed in loses access the next time they load a page, and the public status page, webhooks and API keys stop working. Nothing is destroyed on the spot: contact support within about a month and the organization can be restored intact. After that it is removed permanently. Organizations that nobody uses can also close on their own. The admins whose addresses were confirmed receive two warning emails first, and the closure is the same soft delete with the same restore window. Paying organizations are never closed this way.