Kestryl Cockpit · How it works
One workflow. Clear responsibility at every hand-off.
Connect the systems in scope. Review where personal data sits and which state may be relevant. Approve the action, check the known copies, and retain the evidence. The cockpit keeps those steps connected without replacing the decisions your business must make.
The foundation
Build on the integration platform. Keep the operating decisions visible.
- ConnectThe Informatica IDMC Secure Agent brings in-scope records into a customer-controlled working environment. The attachment extractor retrieves supported documents through the source systems’ interfaces.
- DiscoverKestryl scans the local working data and documents. Findings are organized for review; pattern matches and category inferences are not treated as proof of a real identity or a legal classification.
- Review stateAddress and ZIP information support state assignment; phone area codes are a weaker signal. The cockpit retains the basis, confidence, and unresolved count for review.
- CoordinateRights requests, appeals, opt-outs, retention policies, and dated obligations share owners and evidence. Legal settings are drawn from a cited, versioned release approved by counsel.
- ActMask, Vault, and Strip require approval and hold checks. They apply to supported structured working data and supported document copies, not automatically to the live source system.
- EvidenceAssemble the findings, decisions, actions, source-system confirmations, and follow-up results by run, request, state, or matter. Preserve the rule and legal-setting versions used.
The working day
Move from a request to an answer your team can explain.
- Set scopeChoose systems, records, document links, and known downstream relationships. Assign an owner before calling the inventory complete.
- Review findingsConfirm candidates and resolve uncertain state assignments. Reviewers work with record references rather than matched personal values.
- Manage rightsTrack the deadline, any permitted extension, the request’s progress, and an appeal where applicable. Locate the individual’s in-scope data using the identifiers supplied.
- Check preferencesBring recorded opt-outs and consent status in from the customer’s tools. Compare them with permissions in the known downstream copies.
- Approve actionRecord who approved what, and check the applicable holds. Keep source-system execution separate from changes to working data or supported document copies.
- Review the resultBring back source-system confirmations and examine follow-up findings. Show missing evidence and exceptions rather than assuming an empty report means all data is gone.
- Retain the recordAssemble evidence for the request, state, or matter. Keep the owner, decision, applicable settings, and unresolved work attached to the outcome.
Incidents and obligations
Give the response team scope, not a guessed legal conclusion.
For an incident, select the affected tables and files and organize the findings by state and sensitive category. Where the evidence is available, review whether the affected working data was masked or vaulted at the relevant time; do not treat its current condition as proof of earlier protection.
For a consent order or other recorded obligation, retain the obligation text, owner, term, next reporting date, assessor where applicable, and supporting evidence pack. Keep the evidence date with the matter status.
The boundary
The cockpit supports incident scoping and obligation tracking. Counsel determines reportability, notification duties, and whether an obligation has been satisfied; the customer sends the notices.
Data handling
Broader document action. The same discipline around originals.
Mask, Vault, and Strip apply to approved structured working data and supported document copies. The document scope includes Word, Excel, PowerPoint, OpenDocument, email, archives, and supported text and data formats, subject to the limits of each format.
Supported document actions produce a separate cleansed copy. Original files are not overwritten. PDFs, scanned pages, images, and legacy Word .doc files remain discovery-only; audio and video handling is limited to supported metadata and tags.
Vault restoration is an authorized, recorded action and depends on the correct key and retained encrypted record. A changed target or an unavailable key can prevent restoration. Masking or stripping a working output is not a claim that originals, backups, or historical database pages have been securely erased.
Keep findings, working data, source documents, backups, and output copies within the organization’s access and retention controls. The existence of an evidence pack does not make every underlying store safe to distribute.
The source-system boundary
Salesforce Privacy Center remains part of the process, not the whole estate.
Where Salesforce is the system of record, the cockpit works alongside Salesforce Privacy Center and brings available execution confirmations into the evidence record. Deletion, correction, portability, and policy actions still need to be carried out through the appropriate source-system workflow.
Across other systems, the same distinction holds: locate the data, record the decision, obtain execution evidence, then review what remains. A connection to a source is not blanket authority to change it, and a locally protected copy is not proof that the source was altered.
Use the U.S. enforcement evidence baseline as a review input; it does not decide legal applicability for a customer.
Next step
Agree what a completed workflow must demonstrate.
Bring one priority privacy workflow and its source systems to a briefing. Define the required evidence, the decisions that remain with your team, and the exceptions that must stay visible before expanding the deployment.