For the complete documentation index, see llms.txt. This page is also available as Markdown.

Investigation

Investigation allows you to create cases that group files requiring further review. Each investigation maintains a record of which files were examined, by whom, and any comments added during the review process, providing an audit trail for compliance purposes.

Within an investigation case, you can tag detected sensitive data as Important or Not Important, review previous comments, and download password-protected files as a ZIP for analysis outside of GuardWare.

Field Group
Field
Description / Details

Scan Details

Scan Name

Name of the scan job.

Scan Date

Date the scan job was executed.

File Details

File Name

Name of the file where sensitive data was found.

Folder Path

Path of the file that contains the sensitive data.

File Owner

Name of the file owner.

Endpoint / Data Source

Target Name

Device or service name where the scan was executed. Endpoint and data source are the same in this context.

Scan Results

Data Types

List of sensitive data types found by the scan job. Click to view details.

Remediation Action

Action

Action performed on the file (e.g., move, copy, delete, or notify device/file owner).

Download / Investigation

Download Status

Status indicating whether the file is available for download: -Available: File is available for download.Not Available: File is unavailable for download currently.

Investigation

Action to make the file available for download for manual examination of sensitive data.

Investigated By

Name of the user who performed the investigation.

Investigated At

Timestamp when the investigation was initiated.

Investigation Available At

Timestamp when the file became available for download. Always later than Investigated At.

Previous Comment

Comments from previous investigations.

Create New Investigation

Before performing any file-level examinations in the Results page, you must first create an Investigation. Each investigation group related files together for review, tracks examiner activities, and stores comments made during the investigation process.

  1. Navigate to DISCOVER > Investigation and click +Investigation.

  2. Enter a unique Name and add a short Purpose.

  3. Click Create.

View Investigations

View Investigation shows a searchable record of all investigations.

  1. Navigate to DISCOVER > Investigation and click View Investigations.

  2. Search for or select an investigation from the dropdown.

  3. Review the investigation details, including its name, purpose, creation date, and who created it.

Last updated