Kestryl · Cockpit for Canada · How it works

Seven steps from a connected system to evidence counsel can read.

The operating journey, step by step: what happens, who owns the action, what is recorded, and where the cockpit stops. Each boundary is stated explicitly so teams can evaluate scope, ownership, and evidence requirements before deployment.

DISCOVER · RESOLVE · REVIEW · APPROVE · ACT WHERE SUPPORTED · CHECK KNOWN COPIES · EVIDENCE

The operating journey

Each step has an owner, a record, and a boundary.

01

Discover

The Informatica Secure Agent reads connected systems through the agreed connector and extraction scope into the governed Kestryl working environment. Attachment relationships can be included within the agreed scope, and the scan records findings against the configured rule set.

WhoPDI under White Glove; customer admin RecordedRun, scan scope, rule and parameter versions, findings, and unresolved coverage

BoundaryConnection does not mean automatic access to every field, attachment, or object. Coverage depends on connector availability, permissions, extraction scope, attachment relationships, and deployment configuration.

02

Resolve

The cockpit applies the jurisdiction and statute-family settings approved for the deployment. Organization profile, province or territory, cross-border context, and configured parameters contribute to the operating association.

WhoConfigured resolver; reviewer can review or override a request association RecordedJurisdiction, statute family, basis, confidence where used, rule text, and parameter-table version

BoundaryThese associations support workflow and evidence review; they do not determine legal applicability. Customer counsel confirms the applicable requirements.

03

Review

Reviewers confirm findings using record references rather than exposing personal values. Data owners can provide dated attestations, and sensitive-category or age indicators remain candidates for human review.

WhoReviewer decides; owner attests RecordedRecorded decision history, attestation, owner, time, reason, and unresolved items

BoundaryCandidates and inferences are not treated as proof of a legal classification. Role boundaries support separation of duties; they do not replace customer governance.

04

Approve

A remediation request and its approval decision are recorded separately, with the applicable hold checks. For an incident, the cockpit records the customer’s or counsel’s risk and reportability decision and its timestamp.

WhoApprover, separate from the requester RecordedRequest, approval, hold check, risk or reportability decision, and timestamp

BoundaryThe cockpit does not make the legal risk determination and does not send regulator or individual notices.

05

Act where supported

Mask, Vault, and Strip apply only to approved supported structured working data. The action follows review, recorded approval, and applicable hold checks.

WhoAuthorized operator under the deployment workflow RecordedApproved scope, action, run, result, and evidence needed for follow-up review

BoundaryActions in source business systems are executed separately and verified through the operating workflow. Strip is not represented as erasure from every source, backup, or unknown copy, and is not represented as legal anonymization.

06

Check known copies

Requests and recorded consent withdrawals are followed into downstream relationships your team declared or imported from an available data catalog. The workflow shows where follow-through is evidenced and where a copy still needs attention.

WhoReviewer; approver where a decision is required RecordedKnown copies checked, copies still lagging, declared processors and countries, and residual findings

BoundaryThe scanner does not independently discover every downstream copy. A copy nobody declared or imported remains outside the operating register.

07

Evidence

Findings, decisions, approvals, actions, incidents, and open issues are assembled by run, request, jurisdiction, or matter into a reviewable evidence record.

WhoReviewer, approver, and admin according to the operating workflow RecordedEvidence pack, source-system confirmations where available, applicable settings, and outstanding issues

BoundaryTechnical evidence supports customer and counsel review; it is not a statement that a legal obligation has been satisfied.

Three inputs to the configured jurisdiction view

Not one law. Three inputs, applied per record.

Canadian privacy requirements can vary by organization, activity, jurisdiction, and data context. Kestryl records the configured operating association and the basis used, while unresolved cases remain visible for customer and counsel review.

01 / SECTOR

Organization and activity

The organization profile and activity context inform the approved operating association. Federal, provincial, territorial, public-sector, and health-information contexts can remain distinct in the settings used for review.

02 / INDIVIDUAL CONTEXT

Province or territory

The individual’s province or territory can be an input to the configured view. An address or postal signal informs review; it does not decide legal applicability, the required clock, or the regulator.

03 / BORDER

Cross-border context

Declared transfer context, hosting country, processor, and applicable assessment records help reviewers understand known copies. Counsel confirms the applicable requirements and any required assessment.

Illustrative examples
Different organizations, activities, individual contexts, and declared transfers can produce different review questions. Illustrative examples do not replace legal applicability review.

Registers

Keep the questions that need a record in the operating view.

01 / INCIDENT

Incident register

Organize what happened, the jurisdictions and categories in scope, the customer’s or counsel’s assessment, notification decisions, owners, dates, and supporting evidence. Legal reporting duties remain with the customer and counsel.

02 / TRANSFER

Transfer and PIA register

Associate each source and declared copy with its hosting country, processor, applicable assessment status, owner, and evidence link. The register makes missing information visible without asserting complete enterprise lineage.

03 / QUEBEC DUTIES

Quebec duties view

Track approved Quebec-related duties, governance records, assessments, owners, status, and evidence links in one view. Counsel confirms the statutory scope, interpretation, and required timing for each duty.

Control

Five roles. Role boundaries support separation of duties.

Intended Canada operating model, subject to deployment configuration
RoleTypical responsibilityBoundary
ViewerRead the operating screens and evidence available to the role.Does not change workflow records.
ReviewerReview findings, raise requests, open incidents, declare known copies, and request remediation.Does not replace owner attestations or approval decisions.
OwnerProvide attestations, maintain retention decisions, and own assigned duties.Does not approve an action they should not approve under the deployment workflow.
ApproverRecord risk or reportability decisions and approve or reject remediation requests.Remains separate from the request where separation is required.
AdminManage users, sources, organization settings, parameter tables, and scans.Administrative access does not replace legal review or approval authority.

This is the intended operating model. Exact permissions and enforcement are confirmed as part of deployment configuration; the page does not claim unvalidated code-level controls.

Deployment architecture

Designed to operate within the customer’s governed environment.

Kestryl works with the customer’s approved Informatica and data environment. Deployment architecture, residency, connectivity, storage, and scan behavior are confirmed as part of implementation planning.

The deployment record defines which systems are connected, which fields and attachments are in scope, how known copies are represented, who owns each decision, and what evidence reviewers expect. The product page does not assume one server design, a specific residency architecture, or a particular storage pattern before that planning is complete.

Why Pacific Data Integrators

Put the integration and the evidence in the same conversation.

PDI combines Informatica-based data integration with Kestryl discovery, approved action, and evidence workflows. White Glove supports installation, configuration, and scheduled Kestryl operations, with scope, cadence, and systems defined in the applicable order form.

Bring one priority privacy workflow and its source systems to a briefing. Define the evidence required, the decisions that remain with your team, and the exceptions that must stay visible before expanding the deployment.