# Welcome to Teleskope.ai

## A Modern Data Security Challenge

Businesses today manage petabytes of data, sprawling across hundreds of different data stores and third party SaaS providers. As data permeates into every corner of the organization, and with every employee producing and ingesting more, it is becoming impossible for engineering, data, and security teams to keep up and secure their exponentially growing data, as well as comply with ever-evolving privacy regulations.

## Teleskope

Teleskope is building a platform to automate data protection at scale, from detection to remediation and prevention.

Our platform seamlessly monitors cloud and SaaS data stores to provide a comprehensive inventory of assets, hidden or otherwise, alongside associated security and compliance risks. Our classification engine, powered by a multi-model machine learning engine, adapts to your unique environment, identifying sensitive data and any associated personas, such as employees or customers.

Teleskope can automatically enforce compliance requirements, redact sensitive data or remediate security vulnerabilities directly at the source, and allows your developers to implement any custom security or privacy protocols through our open apis, helping to shift security left and reduce the manual overhead on security and engineering teams.

***

## Use Cases

### Data Classification

Teleskope can classify personal and sensitive data in your structured and unstructured data stores, and across all file formats (pdfs, images, parquet, csv, etc.). Teleskope detects over 150 distinct entity types, and can be trained to detect custom elements unique to your environment.

### Data Redaction

Teleskope can redact or anonymize personal or sensitive information from any piece of data, to prevent sensitive data from being stored in the first place, or to redact it from persisted storage and clean up unwanted and unnecessary PII. Teleskope’s redaction can be automated using pre-defined policies, or by plugging our redact API directly into your code. We support the following redaction mechanisms: replacing with the entity type, masking characters, encryption while maintaining referential integrity, and replacing with fake data of the same entity type.

### AI Governance

Teleskope enables the safe and transparent adoption of AI across your organization. Teleskope can prevent sensitive data from being used during training or inference. Teleskope can also govern your entire machine learning ecosystem, from discovering in-house or third-party models used in production, detecting model-data relationships, to protecting the underlying training data to reduce your AI attack surface.

### Data Security Posture Management

Teleskope helps organizations maintain a strong security posture by constantly monitoring and evaluating their on-premise or cloud data stores and third party vendors, pinpointing where personal and sensitive data is stored, and detecting and remediating any security and privacy vulnerabilities. Teleskope’s security findings are mapped to security standards, such as NIST, SOC2, PCI-DSS, CIS, and ISO.

### Data Subject Rights Requests

Teleskope can automate data subject rights requests end-to-end by leveraging its data classification findings and integrating with third party vendors for user data deletion, access, and portability. This eliminates gaps and saves time and cost stemming from manual audits.

### Regulatory Compliance

Teleskope automatically identifies what compliance or privacy regulation your company falls under, such as GDPR, PIPEDA, or CPPA, and continuously monitors your cloud data stores and infrastructure for any compliance violations including gaps in data subject rights requests or issues with data residency, backup and recovery.<br>


# Your Journey with Teleskope

## Setup

Your journey with Teleskope begins with one of our deployment models: [*<mark style="color:purple;">Self Hosted</mark>*](/setup/deployment#self-hosted) or [*<mark style="color:purple;">SaaS</mark>*](/setup/deployment#single-tenant-saas). Both option is designed to accommodate security, overhead, and support requirements for a variety of customers and industries. We offer flexibility in connecting to our systems and integrating with your existing infrastructure, and work with every customer to meet their own infrastructure, reliability, security, and access standards.

{% hint style="info" %}
Once your environment is deployed, your first admin completes a short guided onboarding wizard — workspace setup, identity provider, connectors, and inviting your team — started from a one-time setup link. Have the email address of your first admin (your "onboarding user") ready to kick it off.
{% endhint %}

After deploying Teleskope, you may begin enrolling Connectors. Each source of data is considered its own *Connector*, and the requirements of each vary from cloud to cloud and service to service. In the Connectors[ ](/specifications/data-store-coverage#data-stores)section, we've detailed how to set up and provide the necessary permissions for Teleskope to reach and read from each data source.

***

## Discovery

Post-setup, Teleskope initiates **crawling** and **scanning** of your data . Our crawlers continuously compile a comprehensive inventory of your data, while our scanners take samples of each resource and record its context and metadata, detecting any personal or sensitive data entities within. Our scanners are powered by a multi-model classification engine, capable of detecting over 150+ personal and sensitive elements.

These components communicate with your **metadata** service which houses all of Teleskope's findings and powers your frontend **observatory** dashboard.

Discovery configurations offer detailed control over operational parameters like scan frequency, data sampling methods and size, rate-limiting, and custom detectors.

***

## Remediation

After discovering your data ecosystem, Teleskope allows you to take action through its Policy Maker, delete customer information with DSR, and surface compliance shortcomings in Issues.

* **Policy Maker** enables security engineers to define and implement custom event-driven automations. Events are supplied by the crawling and scanning of your sources, so as soon as an object is discovered and cataloged, preconfigured automations take action: tagging, redacting, masking, quarantining, or alerting.
* **DSR** empowers privacy engineers to automate data subject rights requests wherever that data exists in your organization.
* **Issues** uncovers existing regulatory, compliance, and security vulnerabilities in connected datasources and grades each finding to you time in their resolution.


# Data Catalog

Once you've integrated Teleskope with a target data store(s), Teleskope's Data Catalog will showcase all of the insights that Teleskope has derived from your data, such as

1. Data Classification: Teleskope automatically classifies your data to pinpoint what types of personal, financial, health, secrets, or other sensitive data lives within your environment. This shows up in the data catalog under two columns
   1. Data Element: The exact data element that we've detected within each data asset, such as First Name, Country, Medical Diagnosis.
   2. Data Category: Teleskope maps these elements to categories. You can create new categories, or customize the mappings under Settings > Elements and Categories
2. Data Subject: Teleskope predicts who the data is in relation to, such as Customers or Employees
3. Permissions & Access:
   1. Last Accessed: Teleskope surfaces when a data store was last accessed
   2. Permissions View:
      1. Within each asset, Teleskope surfaces which users have access to the asset, when they last wrote or read the asset, and whether the users are internal or external to the organization
4. Configurations: Teleskope surfaces misconfigurations on the data such as if the file is publicly shared, if it allows downloads, etc.

#### Select a target data store

Select which data store you want to investigate (e.g Google Workspace) on the left hand side menu. By default, all integrated data stores will show up in the menu.

<figure><img src="/files/lcnwc2PnveCkD2s3AbyM" alt=""><figcaption></figcaption></figure>

#### Select an investigation level

Select the desired investigation level (within the left-hand side menu) to explore results. Choose "Drives" to get a list of drives in Google Workspace and a summary of findings. To view all files within Google Workspace at the file level, select "Files."

#### Investigate a particular data asset

Click on an asset to investigate the findings further (for example, for Google Workspace) click on a Drive or a File to get more details. Navigate to the data elements tab to review our classifications. Click the Preview button next to a classification to visualize what exactly got classified within the file.

<figure><img src="/files/wPJeN5lkEjAbO78Swgmu" alt=""><figcaption></figcaption></figure>

Navigate to the permissions tab to gain insights into who has access to the data asset, when they last used their access, their user type, as well as configurations on the asset.

<figure><img src="/files/qeX3mHsgET8rQE7GysAr" alt=""><figcaption></figcaption></figure>

#### Search for a set of filters

To search for assets that match a certain criteria (e.g all files that contain a SSN), filter the list view with the desired criteria.

<figure><img src="/files/llSo6BDWItclFK5AAA2B" alt=""><figcaption></figcaption></figure>


# Data Explorer & AI Search

*Currently in Beta*

## What is AI Search?

Finding exactly what you're looking for in your data catalog just got a whole lot easier. **AI Search** is a new feature that lets you search your data assets using plain English — no need to manually configure filters or know the exact name of a data element or category.

Instead of clicking through dropdowns to narrow down results, you can just type what you're looking for in natural language and let AI do the heavy lifting.

## What is Data Explorer?

**Data Explorer** is Teleskope's unified view of all your data assets across connected sources — S3, Google Drive, SharePoint, and more. It gives you a single place to browse, filter, and search every file, table, and object that Teleskope has scanned, with rich context about what sensitive data lives inside, who has access to it, and whether it has any active findings.

Each resource in the Data Explorer shows:

* **Sensitivity** — the highest sensitivity level detected in the resource (Critical, High, Medium, Low)
* **Data elements** — the specific types of sensitive data found (e.g., SSN, credit card numbers, email addresses)
* **Document Types** — document type and classification tags applied to the resource
* **Connector** — the data source the resource lives in
* **Findings** — any active policy violations associated with the resource
* **File path** — where the resource lives within its data source

Clicking any row opens a **detail panel** with a deeper view of the resource, including its full data classification breakdown, permissions, and findings history.

The Data Explorer has two modes: **Browse**, which lets you manually apply filters and sort the full catalog, and **AI Search**, which lets you find resources using plain English queries.

## How It Works

When you type a query, AI Search interprets your natural language input and automatically maps it to the right filters and data catalog parameters. Here's what happens behind the scenes:

1. **Your query is analyzed** — The AI identifies key terms in your search, such as data types (PII, SSN, PHI), connectors (S3, Google Drive, SharePoint), sensitivity levels, and compliance policies (GDPR, HIPAA).
2. **Terms are resolved** — Each term is matched to the right internal concept. For example, "PII" gets mapped to the relevant data category, and "S3" gets mapped to the correct connector type. When there's some ambiguity, the AI picks the best match and notes alternatives.
3. **Results are returned** — The catalog is queried and results are surfaced, just like if you'd applied the filters manually — but in seconds, with a single sentence.
4. **You see how it interpreted your query** — After each search, AI Search shows you a plain-language explanation of how it understood your input and what filters it applied. This helps you verify the results are accurate and refine your search if needed.

## What You Can Search For

AI Search currently supports the following types of search criteria:

* **Resource type** — e.g., CSV files, spreadsheets, Word documents
* **Data elements** — e.g., SSN, credit card numbers, phone numbers, email addresses
* **Data categories** — e.g., PII, PHI, PCI, Financial
* **Risk** — e.g., critical, high, medium, low
* **Data size** — e.g., large files
* **Connector / data source** — e.g., S3, Google Drive, SharePoint
* **Findings** — e.g., resources with active violations, GDPR findings
* **Document Types** — custom tags applied to resources
* **Access & permissions** — e.g., files shared with a specific user, domain-readable files in Drive, externally accessible SharePoint resources

## How to Use AI Search

1. Navigate to **Data Explorer** in the left-hand navigation
2. Click into the search bar at the top of the page — suggested example queries are surfaced here to help you get started
3. Type your query in plain English and press Enter
4. Review the results — AI Search will display a short message showing how it interpreted your query
5. If the results aren't quite right, try refining your query using the suggestions provided, or add more specific terms

**Tips for better results:**

* Be specific about the connector when you can (e.g., "S3 files" rather than just "files")
* Use familiar data terms like "PII", "SSN", "PHI", or "credit card" — AI Search understands these
* If you're looking for something related to violations or policy breaches, include terms like "violating", "at risk", or "with violations"
* If results are too broad, try narrowing by adding more context (e.g., instead of "PII files", try "critical PII files in Google Drive")

## Feedback

AI Search is new and actively improving. This is only supported for S3, Google Drive and Sharepoint/One Drive connectors. If you run into unexpected results, have suggestions, or want to share what's working well, please reach out to your Technical Account Manager — your feedback directly shapes the roadmap.


# Data Subject Rights

Teleskope's Data Subject Rights feature makes executing Deletion and Access requests simple and automated. Most DSR requests - otherwise known as the Rights to Know, Delete, or be Forgotten - enforce strict timelines as detailed at the bottom of this page.

First, configure your DSR ecosystem by enrolling datastores and third party integrations:

1. **Enrollment** - Enroll specific tables that should be subject to deletion or access requests. Optionally, enroll date-sharded tables to propagate deletions to future tables.
2. **Integrations** - Set up each 3rd party integration like Stripe, Hubspot, or Mailchimp in order to process deletion and access requests, and limit what sorts of requests can be performed on each.
3. **Webhooks** - Create webhooks to Post access and deletion requests to services without integrations or custom data stores.
4. **Identifiers** - Detail unique identifiers to enable deletion requests for company or industry-specific identity references.
5. **Settings** - Configure DSR Customizations, emails to vendors where automation is not supported, and Slack notifications.

Then, process your request:

1. **Submit** - Return to the **Requests** tab, and submit a new DSR request. Input the request type and identifiers and click submit.
2. **Tasks** - In each subtab, you're able to click into a request to view which table or integration is currently being processed, when each succeeds, and which, if any, failed.

## Regulatory DSR requirements

### United States DSRs

| Framework        | Time to Reply (days) | Extension (days) |
| ---------------- | -------------------- | ---------------- |
| CA - CCPA & CPRA | 25                   | 25               |
| VA - CDPA        | 45                   | 45               |
| CO - CPA         | 45                   | 45               |
| UT - UCPA        | 45                   | 45               |
| TX - TDPSA       | 45                   | 45               |
| MO - MTCDPA      | 45                   | 45               |
| CT - CTDPA       | 45                   | 45               |
| OR - OCPA        | 45                   | 45               |
| IA - ICDPA       | 90                   | 45               |

### International DSRs

| Framework       | Time to Reply (days) | Extension (days) |
| --------------- | -------------------- | ---------------- |
| EU - GDPR       | 28                   | 61               |
| BR - LGPD       | "Immediately"        | 15               |
| UK - GDPR & DPA | \~28                 | 61               |
| JP - APPI       | "Without delay"      |                  |
| CA - PIPEDA     | \~30                 |                  |
| AU - Cth & APPs | \~30                 |                  |
| SG - PDPA       | 30                   |                  |


# Integrations

### Cloud Data Stores

| Cloud      | Data Store |
| ---------- | ---------- |
| AWS        | RDS        |
| AWS        | Dynamo DB  |
| AWS        | Redshift   |
| GCP        | CloudSQL   |
| GCP        | BigQuery   |
| Azure      | SQL        |
| Snowflake  | Snowflake  |
| Databricks | Databricks |

### Third Party Vendors

#### Accounting

* Avalara
* Blackline
* Floqast
* Freshbooks
* Netsuite
* Quickbooks
* Webgility

#### Advertising

* AdRoll
* Amplitude
* Apple Search Ads
* Curalate
* DemandScience
* Google Ads
* Facebook Ads
* Facebook Marketing
* Heap
* HotJar
* LinkedIn Campaign Manager Ads
* Linkedin Marketing Solutions
* Pinterest Ads

#### Analytics

* Appsflyer
* Bevy
* Choozle
* Comodule
* Daasity
* EnquireLabs
* Fullstory
* Glew
* Google Analytics
* Heap
* Looker
* Mode
* Pepperjam
* Reach
* Snowplow
* StreetMetrics
* Tableau

#### Authentication & SSO

* Auth0
* Azure Active Directory
* Duo
* Okta
* OneLogin

#### Customer Engagement

* Alchemer
* Appcues
* Appfollow
* bazaarvoice
* Delighted
* Freshdesk
* Gorgias
* Intercom
* Jira Service Desk
* Kustomer
* Liveperson
* Narvar
* Okendo
* OpenWeb
* Pendo
* Qualtrics
* Talkable
* Tremendous
* TrustedShops
* Trustpilot
* Turnto
* Yepchat
* Zendesk

#### eCommerce

* Algolia
* Curalate
* Daasity
* Glew
* Shopify
* Takable
* Trusted Shops
* Trustpilot
* Webgility
* WooCommerce
* Yotpo

#### Recruiting

* Ashby
* Eightfold
* Fountain
* Greenhouse
* Lever
* LinkedIn
* SmartRecruiters

#### Hospitality

* Bentobox
* Eventbrite
* Sevenrooms
* Thanx
* tripleseat

#### Human Resources

* ADP
* BambooHR
* CultureAmp
* Fiverr
* Gem
* Guideline
* Gusto
* JustWorks
* Lattice
* Rippling
* TriNet
* UKG
* Upwork
* Workday

#### Logistics

* Happy Returns
* InEvent
* Lightspeed
* Narvar
* Onfleet
* Sendcloud
* ShipHawk
* Shipium
* Shippo
* ShipStation
* Shipwire
* Stitch labs

#### Marketing

* Acoustic
* Blueconic
* Branch.io
* Braze
* Choozle
* Destini
* Friendbuy
* Grin
* Hubspot
* Iterable
* Kaviyo
* Lytics
* Marketo
* Mobiniti
* MovableInk
* mParticle
* One Signal
* Optimizely
* Resci
* Rockerbox
* Sailthru
* Salesforce Marketing Cloud
* Segment
* Simon
* Turnto
* VWO
* Wiland
* Wunderkind
* Yotpo
* Zapier

#### Messaging

* 8x8
* attentive
* Basecamp
* customer.io
* Intrado
* Lob
* Mailchimp
* Mailfloss
* Mailgun
* Mandrill
* Mobiniti
* OneSignal
* Postle
* Resci
* Sendgrid
* Slack
* SurveyMonkey
* Textline
* Twilio

#### Payments

* Affirm
* AfterPay
* Authorize.Net
* Ayden
* Bill.com
* Braintree
* Clover
* Klarna
* Marqueta
* PayPal
* PayPlug
* PaySafe
* ReCharge
* Recurly
* Splitit
* Square
* Stripe
* Vend
* Zuora

#### Observability

* AppDynamics
* Datadog
* Grafana
* New Relic
* Rollbar
* Sentry
* Splunk

#### Sales

* Copper
* Domo
* Microsoft Dynamics 365
* Netsuite
* Optimizely
* Outreach
* Salesforce
* Thanz

#### Scheduling

* Calendly
* SevenRoons
* Timekit
* Waitwhile

#### Surveys

* Alchemer
* CrowdSignal
* Digioh
* Iterate
* Korber
* Qualtrics
* Shipium
* Slido
* SurveyMonkey
* Typeform
* UserInterviews
* UserLeap
* Zappi

#### Productivity

* Asana
* Basecamp
* BitBucket
* Confluence
* Docusign
* Github
* Jira
* Linear
* Notion
* Pandadoc


# Enroll Third Party Integrations


# Adyen

## Requirements

In order to integrate Teleskope with Adyen for DSR requests, you must have

* Your Adyen **API key**. Follow Adyen's docs for [steps to retrieve this key](https://developers.bazaarvoice.com/v1.0-PrivacyAPI/docs/api-key-management#request-api-keys-via-the-api-key-management-application)
* Your Adyen **Merchant Account**.
* Your Adyen **CA Domain** (by default we use <https://ca-live.adyen.com>)
* The dataset reference to the pspReference of the original payment authorization which maps to the desired user identifier (e.g email).

### Integrating with Adyen

To integrate Teleskope with Adyen

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Adyen
2. Enter the required fields for the integration and click Next
3. Choose alternative user identifier and define the mapping to the pspReference

### Enroll Adyen for deletion or access requests

The following endpoints are available for deletion or access requests

| Request Type | Endpoint Name in Adyen                                                                   | Endpoint Name in Teleskope |
| ------------ | ---------------------------------------------------------------------------------------- | -------------------------- |
| **Deletion** | [Data Protection API](https://docs.adyen.com/development-resources/data-protection-api/) | Data Protection API        |

### Parameter Defaults

Teleskope’s Adyen integration uses Adyen’s Data Protection API to request subject erasure. The following parameters are included by default:

| Parameter Name   | Default Value               | Notes                                                        |
| ---------------- | --------------------------- | ------------------------------------------------------------ |
| **forceErasure** | true                        | Always included. Ensures Adyen removes *all* available data. |
| **caDomain**     | <https://ca-live.adyen.com> | Default Adyen CA domain. Can be overridden for testing.      |


# Amplitude

## Requirements

In order to integrate Teleskope with Amplitude for DSR requests, you must have

* Your **Amplitude URL** (Server Endpoint)
  * Typically either <https://amplitude.com/api/2> or <https://analytics.eu.amplitude.com/api/2>
* Your Amplitude project's **API key**. Follow Amplitude's docs for [steps to retrieve this key](https://www.docs.developers.amplitude.com/analytics/find-api-credentials/)
* Your Amplitude project's **secret key**. Follow Amplitude's docs for [steps to retrieve this key](https://www.docs.developers.amplitude.com/analytics/find-api-credentials/)

### Integrating with Amplitude

To integrate Teleskope with Amplitude

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Amplitude
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

* When Teleskope sends a Delete User request to Amplitude, it includes these parameters by default:

  * `delete_from_org`: `true`
  * `ignore_invalid_ids`: `true`

  Refer to Amplitude's [User Privacy Api](https://amplitude.com/docs/apis/analytics/user-privacy?h=delete) documentation
* Default Identifier for Amplitude = `amplitude_ids`


# AskNicely

## Requirements

<table><thead><tr><th width="150.1640625">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>subdomain</strong></td><td>Your company’s AskNicely subdomain. Used to construct the API endpoint URL.</td></tr><tr><td><strong>apiKey</strong></td><td>Your AskNicely API Key. Used for authenticating requests.</td></tr></tbody></table>

### Integrating with AskNicely

To enable the AskNicely integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **AskNicely** from the list of available third-party vendors.
3. Provide the required credentials:

* **Subdomain** (e.g., `yourcompany` if your account is `yourcompany.asknice.ly`)
* **API Key** (from AskNicely’s API settings)

4. Click **Save** to activate the integration.

Once configured, Teleskope can automatically issue deletion requests to AskNicely for qualified data subject rights requests.

### Parameter Defaults

When Teleskope issues a deletion request to AskNicely’s Privacy API, it includes the following parameters by default:

| Parameter Name | Default Value | Notes                                                                                                         |
| -------------- | ------------- | ------------------------------------------------------------------------------------------------------------- |
| **skipnotify** | 1             | Always included in payload. Prevents AskNicely from sending notification emails to the contact being deleted. |

Default Identifier for AskNicely = **Email**


# Bazaar Voice

## Requirements

In order to integrate Teleskope with BazaarVoice for DSR requests, you must have

* A Bazaar Voice **API key**. Follow Bazaar Voice's docs for [steps to retrieve this key](https://developers.bazaarvoice.com/v1.0-PrivacyAPI/docs/api-key-management#request-api-keys-via-the-api-key-management-application)
* Your Bazaar Voice's app **client\_id and client\_secret**. Follow Bazaar Voice's docs for [steps to retrieve this key](https://developers.bazaarvoice.com/v1.0-PrivacyAPI/docs/api-key-management#register-your-application-with-bazaarvoice). We use 2-legged Oauth so you can skip any steps related to 3 legged

### Integrating with Bazaar Voice

To integrate Teleskope with BazaarVoice

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Bazaar Voice
2. Enter the required fields for the integration and click **Save**.

### Enroll Bazaar Voice for deletion or access requests

The following endpoints are available for deletion or access requests

| Request Type | Endpoint Name in Bazaar                                                                 | Endpoint Name in Teleskope |
| ------------ | --------------------------------------------------------------------------------------- | -------------------------- |
| Deletion     | [RTBF](https://developers.bazaarvoice.com/v1.0-PrivacyAPI/reference/post_forgetrequest) | User                       |
| Access       | [ROA](https://developers.bazaarvoice.com/v1.0-PrivacyAPI/reference/post_accessrequests) | User                       |

### Parameter Defaults

Teleskope’s Bazaar Voice integration uses OAuth2 client credentials to authenticate requests, and enforces the following default behavior:

| Parameter Name  | Default Value       | Notes                                                        |
| --------------- | ------------------- | ------------------------------------------------------------ |
| **grant\_type** | client\_credentials | Always used for OAuth2 authentication. Cannot be customized. |

Default Identifier for Bizaar Voice = **Email**


# Braze

## Requirements

<table><thead><tr><th width="124.5">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Braze REST API Key. Used in Bearer authorization header.</td></tr><tr><td><strong>Endpoint</strong></td><td>Braze REST API Endpoint URL (region-specific).</td></tr></tbody></table>

### Integrating with Braze

To enable the Braze integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **Braze** from the list of available third-party vendors.
3. Provide the required credentials:

* **Braze API Key** (Server-side API Key with User Data permissions)
* **Braze Endpoint** (e.g., `https://rest.iad-01.braze.com`)

4. Click **Save** to activate the integration.

Once configured, Teleskope can automatically issue deletion and retrieval requests to Braze for qualified data subject rights requests.

### Parameter Defaults

Teleskope’s Braze integration enforces the following default behavior:

| Parameter Name      | Default Value         | Notes                                                   |
| ------------------- | --------------------- | ------------------------------------------------------- |
| **identifier type** | Email or Phone Number | Only these identifier types are supported for matching. |

The integration automatically selects the correct identifier field in Braze (either `email_address` or `phone`) based on the user’s DSR request.


# Calendly

## Requirements

In order to integrate Teleskope with Calendly for DSR requests, you must have:

* An outbound email configuration in Teleskope (used by the internal EmailHandler).
  * Must be able to send mail to **<privacy@calendly.com>**.
* No API credentials or endpoint URL are required for Calendly (requests are sent by email).
* The user’s **email address** as the identifier for the request.

{% hint style="info" %}
Retrieval is not supported by this integration.
{% endhint %}

### Integrating with Calendly

To integrate Teleskope with Calendly:

1. Navigate to **Data Subject Rights → Third Party Integrations** and pick **Calendly**.
2. Since Calendly uses email, there are no API fields to enter. Ensure your outbound email settings are configured, then click **Save**.

### Parameter Defaults

* When Teleskope sends a **Delete User** request to Calendly, it includes these parameters by default:
  * `to`: `privacy@calendly.com`
  * `method`: `email`
  * `identifier_in_body`: user’s email address
* Default Identifier for Calendly = `email`

> Behind the scenes, the handler uses the EmailHandler to send the deletion request and returns a standard “vendor deletion request submitted” message if the email is sent successfully.

#### Helpful Links

[Calendly: How to delete personal data](https://help.calendly.com/hc/en-us/articles/4412601189911-How-to-delete-personal-data-in-Calendly)

[Calendly Privacy Notice](https://calendly.com/legal/privacy-notice)


# Chargebee

Teleskope integrates with Chargebee’s API to fulfill **Delete User** DSRs by clearing personal data on the customer record.

## Requirements

In order to integrate Teleskope with Chargebee for DSR requests, you must have:

* Your **Chargebee Site Name** (subdomain)
  * The default API base is `https://<site-name>.chargebee.com/api/v2`.
* Your **Chargebee API key** (used for Basic Auth).
* *(Optional)* **API URL override**
  * If you use a non-standard or regional base URL, provide it here. Otherwise Teleskope constructs `https://<site-name>.chargebee.com/api/v2` automatically.
* The user’s **email address** as the identifier (used to look up the customer).

### Integrating with Chargebee

To integrate Teleskope with Chargebee

1. Navigate to **Data Subject Rights → Third Party Integrations** and pick **Chargebee**.
2. Enter the required fields for the integration and click **Save**:
   * **API Key** (required)
   * **Site Name** (required)
   * **API URL** (optional; leave blank to use `https://<site>.chargebee.com/api/v2`)

### Parameter Defaults

* When Teleskope sends a **Delete User** request to Chargebee, it performs these steps by default:
  * **Lookup by email**:\
    `GET /customers?email[is]={email}`
  * If a match is found, **clear personal data** on the first customer returned:\
    `POST /customers/{customerId}/clear_personal_data`
  * **Authentication & headers**:
    * `Authorization`: Basic Auth (API key as username, empty password)
    * `Accept`: `application/json`
    * `Content-Type`: `application/x-www-form-urlencoded`
  * **Expected success codes**: `200` or `204`
* **Default Identifier for Chargebee = `email`**\
  (The handler uses the user’s email to find the customer ID.)

### Behavior and Notes

* If multiple customers are returned for the email lookup, the **first** one in the list is used.
* If **no customer** is found for the provided email, the request fails with an error.
* On success, Teleskope logs the operation and returns a standard “vendor deletion request submitted” message.

#### Helpful Links

[Chargebee: How to delete the personal data of my customers](https://www.chargebee.com/docs/billing/2.0/kb/billing/how-to-delete-the-personal-data-of-my-customers)

[Chargebee API docs](https://apidocs.chargebee.com/docs/api/customers)


# Email Oversight

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to Email Oversight's designated security address.

### Integrating with Email Oversight

To integrate Teleskope with Email Oversight

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Email Oversight
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s Email Oversight integration enforces the following default behavior:

| Parameter Name         | Default Value                | Notes                                                                    |
| ---------------------- | ---------------------------- | ------------------------------------------------------------------------ |
| **targetEmailAddress** | <support@emailoversight.com> | The destination address for all deletion requests. Cannot be customized. |


# GlueLetter

## Requirements

<table><thead><tr><th width="156.3515625">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>Client</strong> <strong>ID</strong></td><td>Required for API requests. Included as a query parameter.</td></tr><tr><td><strong>API Key</strong></td><td>Required for API authorization. Used as a Bearer token.</td></tr></tbody></table>

Teleskope includes these credentials in every deletion request to GlueLetter’s API.

### Integrating with GlueLetter

To enable the GlueLetter integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **GlueLetter** from the list of available third-party vendors.
3. Provide the required credentials:

* **Client ID** (from your GlueLetter account)
* **API Key** (Bearer token with permissions to manage user data)

4. Click **Save** to activate the integration.

Once enabled, Teleskope can automatically issue deletion requests to GlueLetter for qualified data subject rights requests.

### Parameter Defaults

Teleskope’s GlueLetter integration enforces the following default behavior:

| Parameter Name           | Default Value         | Notes                                                       |
| ------------------------ | --------------------- | ----------------------------------------------------------- |
| **identifier type**      | Email                 | Always required. Email is used to match GlueLetter records. |
| **client\_id**           | *(Provided at setup)* | Included in every deletion request as a query parameter.    |
| **Authorization Header** | Bearer {API Key}      | Used for all API calls.                                     |

The integration automatically includes your configured credentials with every request.


# Google Analytics

## Requirements

In order to integrate Teleskope with Google Analytics for DSR requests, you must have:

* Your Google Analytics **Property ID**. Follow Google's [docs](https://developers.google.com/analytics/devguides/reporting/data/v1/property-id#google_analytics) to retrieve the property ID.
* A Google Analytics Admin to perform the integration.
* Permission to grant Teleskope the `https://www.googleapis.com/auth/analytics.edit` OAuth scope. Google requires this scope for the Google Analytics Admin API user deletion endpoint.

### Integrating with Google Analytics

To integrate Teleskope with Google Analytics:

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Google Analytics
2. Enter the Property ID you want to target and click save
3. Complete the Google OAuth flow with a Google Analytics Admin account

{% hint style="info" %}
If the integration was authorized before Google sunset the legacy User Deletion API, reauthorize Google Analytics so Teleskope receives a refresh token with the `analytics.edit` scope. Tokens granted only for the legacy `analytics.user.deletion` scope cannot submit deletion requests through the Google Analytics Admin API.
{% endhint %}

### Enroll Google Analytics for deletion requests <a href="#enroll-google-analytics-for-deletion-requests" id="enroll-google-analytics-for-deletion-requests"></a>

The following endpoint is available for deletion requests:

| Request Type | Endpoint Name GA                                                                                                                   | Endpoint Name in Teleskope |
| ------------ | ---------------------------------------------------------------------------------------------------------------------------------- | -------------------------- |
| **Deletion** | [SubmitUserDeletion](https://developers.google.com/analytics/devguides/config/admin/v1/rest/v1alpha/properties/submitUserDeletion) | User                       |

### Parameter Defaults <a href="#parameter-defaults" id="parameter-defaults"></a>

Teleskope's Google Analytics integration deletes users across all specified GA4 properties.

| Parameter Name      | Default Value    | Notes                                                                                                                                             |
| ------------------- | ---------------- | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Property ID**     | *(Required)*     | Comma-separated list of GA4 Property IDs; no system default. The property ID is used in the Admin API request path as `properties/{property_id}`. |
| **Delete Strategy** | Split & Iterate  | Each property ID in the list receives an individual request.                                                                                      |
| **OAuth Scope**     | `analytics.edit` | Required by Google for `properties.submitUserDeletion`.                                                                                           |

Default Identifier for Google Analytics = **Client ID**


# HubSpot

## Requirements

<table><thead><tr><th width="183.58203125">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>Access Token</td><td>HubSpot Private App token or OAuth access token. Used as a Bearer token in the Authorization header. Must have <strong>Users API</strong> scope.</td></tr></tbody></table>

### Integrating with HubSpot

To enable the HubSpot integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **HubSpot** from the list of available third-party vendors.
3. Provide the required credential:

* **Access Token** (Private App token with permissions to manage users)

4. Click **Save** to activate the integration.

Once enabled, Teleskope can automatically issue deletion requests to HubSpot for qualified data subject rights requests.

### Parameter Defaults

Teleskope’s HubSpot integration enforces the following default behavior:

| Parameter Name      | Default Value | Notes                                                           |
| ------------------- | ------------- | --------------------------------------------------------------- |
| **identifier type** | Email         | Always required. Used to match HubSpot users.                   |
| **idProperty**      | EMAIL         | Hard-coded in the API request. Ensures lookup by email address. |

The integration automatically uses `idProperty=EMAIL` in all deletion requests.


# Impacttech

Teleskope integrates with Impact Tech’s API to fulfill **Delete User** DSRs by removing a participant (identified by email) from an Advocate Program.

## Requirements

In order to integrate Teleskope with Impact Tech for DSR requests, you must have:

* Your **Impact Account SID** (used as the Basic Auth username).
* Your **Impact Auth Token** (used as the Basic Auth password).
* Your **Advocate Program ID**.
* *(Optional)* **API URL override**
  * Defaults to `https://api.impact.com`. Provide a custom base URL only if your environment requires it.
* The user’s **email address** as the identifier.

{% hint style="info" %}
Retrieval is not supported by this integration.
{% endhint %}

### Integrating with Impacttech

To integrate Teleskope with Impact Tech:

1. Navigate to **Data Subject Rights → Third Party Integrations** and pick **Impact Tech**.
2. Enter the required fields for the integration and click **Save**:
   * **Account SID** (required)
   * **Auth Token** (required)
   * **Program ID** (required)
   * **API URL** (optional; leave blank to use `https://api.impact.com`)

### Parameter Defaults

* When Teleskope sends a **Delete User** request to Impact Tech, it includes these parameters by default:
  * **HTTP Method**: `DELETE`
  * **Endpoint**:

    ```
    {apiUrl}/Mediapartners/{accountSid}/Advocate/Programs/{programId}/Participants
    ```
  * **Authentication**: Basic Auth
    * username = `accountSid`
    * password = `authToken`
  * **Headers**:
    * `Content-Type: application/json`
    * `Accept: application/json`
  * **Request Body**:

    ```json
    { "email": "<identifier.email>" }
    ```
  * **Expected success codes**: `200` or `204`
* **Default Identifier for Impact Tech = `email`**

### Behavior and Notes

* The handler sends a **single DELETE** call to remove the participant tied to the provided **email** in the specified **Program ID**.
* If the API response is not `200`/`204`, the error (including response body) is surfaced for troubleshooting.
* On success, Teleskope logs the operation and returns a standard “vendor deletion request submitted” message.

#### Helpful Links

[impact.com: Delete participants from your Adovcate program](https://help.impact.com/en/support/solutions/articles/155000000318-delete-participants-from-your-advocate-program)

[Impact Advocate API](https://integrations.impact.com/impact-brand/reference/opendeleteuser)


# InEvent

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to InEvent’s designated privacy address.

### Integrating with InEvent

To enable the InEvent integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **InEvent** from the list of available third-party vendors.
3. Confirm the integration.

*No API keys or tokens are required.*

Once enabled, Teleskope can automatically send deletion requests to InEvent on behalf of the data subject.

### Parameter Defaults

Teleskope’s InEvent integration enforces the following default behavior:

| Parameter Name         | Default Value         | Notes                                                                    |
| ---------------------- | --------------------- | ------------------------------------------------------------------------ |
| **targetEmailAddress** | <privacy@inevent.com> | The destination address for all deletion requests. Cannot be customized. |


# Intercom

## Requirements

* A Service Account with Admin privileges
* An Intercom Admin
  * Intercom relies on a user-tied API token. If the user that enrolls Intercom for DSR is deactivated, any future DSRs will fail.

### Integrating with Intercom

To integrate Teleskope with Intercom

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Intercom
2. Enter your API Key and click **Save**.

### Enroll the User endpoint for deletion

| Endpoint | Default Identifier |
| -------- | ------------------ |
| User     | Email              |

*Intercom users are always matched using their email address. Deletion and retrieval requests require providing this identifier.*

### Parameter Defaults

Teleskope’s Intercom integration enforces the following default behavior:

| Parameter Name      | Default Value      | Notes                                                |
| ------------------- | ------------------ | ---------------------------------------------------- |
| **identifier type** | Email              | Required. Always used to search for Intercom users.  |
| **Deletion Target** | intercom\_user\_id | Must be resolved from email before issuing deletion. |

The integration always maps the provided email to the user’s Intercom ID before issuing deletion.<br>


# Knotch

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to Knotch’s designated security address.

### Integrating with Knotch

To integrate Teleskope with Knotch

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Knotch
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s Knotch integration enforces the following default behavior:

| Parameter Name         | Default Value         | Notes                                                                    |
| ---------------------- | --------------------- | ------------------------------------------------------------------------ |
| **targetEmailAddress** | <security@knotch.com> | The destination address for all deletion requests. Cannot be customized. |


# Qualtrics

## Requirements

<table><thead><tr><th width="223.0625">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Qualtrics API Token (X-API-TOKEN). Used in request headers.</td></tr><tr><td><strong>Domain</strong></td><td>Your Qualtrics subdomain (e.g. <code>yourbrand.qualtrics.com</code>).</td></tr></tbody></table>

### Integrating with Qualtrics

To integrate Teleskope with Qualtrics

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Qualtrics
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s Qualtrics integration enforces the following default behavior:

<table><thead><tr><th>Parameter Name</th><th width="178.40625">Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>identifier type</strong></td><td>Email</td><td>Required. Always used to search for Qualtrics users.</td></tr><tr><td><strong>Deletion Target</strong></td><td>Qualtrics User ID</td><td>Resolved automatically by listing users and matching on email.</td></tr></tbody></table>

The integration always maps the provided email to the Qualtrics User ID before issuing deletion.


# Quantum Metric

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to Quantum Metric designated security address.

### Integrating with Quantum Metric

To integrate Teleskope with Quantum Metric

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Quantum Metric
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s Quantum Metric integration enforces the following default behavior:

| Parameter Name         | Default Value               | Notes                                                                    |
| ---------------------- | --------------------------- | ------------------------------------------------------------------------ |
| **targetEmailAddress** | <support@quantummetric.com> | The destination address for all deletion requests. Cannot be customized. |


# Rockerbox

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to Rockerbox's designated security address.

### Integrating with Rockerbox

To integrate Teleskope with Rockerbox

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Rockerbox
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s EmailOversight integration enforces the following default behavior:

| Parameter Name         | Default Value                       | Notes                                                                    |
| ---------------------- | ----------------------------------- | ------------------------------------------------------------------------ |
| **targetEmailAddress** | <privacydatarequests@rockerbox.com> | The destination address for all deletion requests. Cannot be customized. |

### Supported Endpoints & Identifiers

| Endpoint | Default Identifier |
| -------- | ------------------ |
| User     | Email              |

*Rockerbox user records are always matched using the user’s email address. Deletion requests require providing this identifier.*


# Sailthru

## Requirements

<table><thead><tr><th width="148.9609375">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Sailthru API Key. Included in all requests.</td></tr><tr><td><strong>Secret</strong></td><td>Used to generate MD5 signatures for request authentication.</td></tr></tbody></table>

### Integrating with Sailthru

To enable the Sailthru integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **Sailthru** from the list of available third-party vendors.
3. Provide the required credentials:

* **API Key** (from your Sailthru account)
* **API Secret** (used to sign requests)

4. Click **Save** to activate the integration.

Once enabled, Teleskope can automatically issue deletion and retrieval requests to Sailthru for qualified data subject rights requests.

### Parameter Defaults

Teleskope’s Sailthru integration enforces the following default behavior:

<table><thead><tr><th width="179.12109375">Parameter Name</th><th>Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>identifier type</strong></td><td>Email</td><td>Required. Used to match Sailthru user records.</td></tr><tr><td><strong>format</strong></td><td>json</td><td>Always included in all requests.</td></tr><tr><td><strong>Signature</strong></td><td>MD5(secret + api_key + "json" + payload)</td><td>Automatically calculated for every request.</td></tr></tbody></table>

Refer to [Sailthru's](https://getstarted.meetmarigold.com/engagebysailthru/Content/developers/api/user.html) User API documentation.


# Salesforce

## Requirements

* A Salesforce account with the **System Administrator** profile — this ensures Teleskope can access all relevant objects
* Your org can be **Production** or **Sandbox**

{% hint style="warning" %}
**Service account recommended.** The OAuth token is tied to the authorizing user. If that user is deactivated, all future automated actions will fail. Use a dedicated Teleskope service account with System Administrator access.
{% endhint %}

### Integrating with Salesforce

Teleskope uses OAuth 2.0 to connect to Salesforce. To authorize the integration:

1. Navigate to **Settings → Connectors → Salesforce**
2. Click **Enroll New** and select your environment (Production or Sandbox)
3. You will be redirected to Salesforce — sign in with the service account and click **Allow**
4. After authorizing, you are returned to Teleskope and the integration is active


# Segment

## Requirements

<table><thead><tr><th width="152.25390625">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Segment Bearer Token. Used in the Authorization header. Must have permissions to use the Deletion and Suppression API.</td></tr></tbody></table>

### Integrating with Segment

To integrate Teleskope with Segment

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Segment
2. Enter the required fields for the integration and click **Save**.

### Supported Endpoints & Identifiers

| Endpoint | Default Identifier |
| -------- | ------------------ |
| **User** | USER\_ID           |

*Segment users are matched using your system’s internal User ID. Deletion requests require providing this identifier.*

### Parameter Defaults

Teleskope’s Segment integration enforces the following default behavior:

<table><thead><tr><th>Parameter Name</th><th width="238.3203125">Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>regulationType</strong></td><td>SUPPRESS_WITH_DELETE_INTERNAL</td><td>Hard-coded. Instructs Segment to delete and suppress all user data.</td></tr><tr><td><strong>subjectType</strong></td><td>USER_ID</td><td>Required. Only USER_ID is supported as the subject type.</td></tr></tbody></table>

The integration always uses these values when creating regulation jobs.


# Sprinklr

Teleskope integrates with Sprinklr’s GDPR API to fulfill **Delete User** DSRs by creating a redact request for the data subject.

## Requirements

In order to integrate Teleskope with Sprinklr for DSR requests, you must have:

* Your **Sprinklr API Key**
* Your **Sprinklr API Secret**
* *(Optional)* **API URL override**
  * Defaults to `https://api.sprinklr.com`. Provide a custom base URL only if your environment requires it.
* The data subject’s **identifier**:
  * **email** (default), or
  * **phone** (if the identifier name is `phone`)

### Integrating with Sprinklr

To integrate Teleskope with Sprinklr:

1. Navigate to **Data Subject Rights → Third Party Integrations** and pick **Sprinklr**.
2. Enter the required fields for the integration and click **Save**:
   * **API Key** (required)
   * **API Secret** (required)
   * **API URL** (optional; leave blank to use `https://api.sprinklr.com`)

### Parameter Defaults

* When Teleskope sends a **Delete User** request to Sprinklr, it includes these parameters by default:
  * **HTTP Method**: `POST`
  * **Endpoint**:

    ```
    {apiUrl}/v1/gdpr/delete
    ```
  * **Headers**:
    * `api-key: <API Key>`
    * `api-secret: <API Secret>`
    * `Content-Type: application/json`
    * `Accept: application/json`
  * **Request Body**:

    ```json
    {
      "dataSubjectIds": [
        {
          "channelType": "EMAIL" | "PHONE",
          "value": "<identifier.value>"
        }
      ],
      "redactOptions": {
        "redactPersonalInformation": true,
        "redactContent": true
      }
    }
    ```

    * `channelType` defaults to **EMAIL** unless the identifier name is `phone`, in which case **PHONE** is used.
  * **Expected success codes**: `200` or `201`
* **Default Identifier for Sprinklr = `email`**\
  (You may also use `phone` by passing an identifier named `phone`.)

### Behavior and Notes

* The handler constructs the GDPR delete request for a single data subject and submits it with your API key/secret.
* If the API response is not `200`/`201`, the error (including response body) is surfaced for troubleshooting.
* On success, Teleskope logs the operation and returns a standard “vendor deletion request submitted” message.

#### Helpful Links

[Sprinklr: GDPR and Privacy Cloud](https://www.sprinklr.com/help/articles/privacy-guides/gdpr-and-privacy-cloud/633c5c2359534970b26f96bd)

[Sprinklr Privacy Workflows](https://www.sprinklr.com/help/articles/privacy-guides/privacy-workflows/64679cc730f12540268fb606)


# Stripe

## Requirements

<table><thead><tr><th width="190.3125">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Stripe Secret API Key. Used in all authenticated Stripe client calls.</td></tr></tbody></table>

### Integrating with Stripe

To enable the Stripe integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **Stripe** from the list of available third-party vendors.
3. Provide the required credentials:

* **Select API Key** (your Stripe account’s live secret key)

4. Click **Save** to activate the integration.

Once enabled, Teleskope can automatically issue deletion and retrieval requests to Stripe for qualified data subject rights requests.

### **Supported Endpoints & Identifiers**

| Endpoint                       | Default Identifier Types |
| ------------------------------ | ------------------------ |
| CUSTOMER                       | Email, Phone Number      |
| BANK\_ACCOUNT                  | Email                    |
| CARD                           | Email                    |
| PAYMENT\_METHOD                | Email                    |
| SUBSCRIPTION                   | Email                    |
| TAX\_ID                        | Email                    |
| INVOICE                        | Email                    |
| CREDIT\_NOTE                   | Email                    |
| CHARGE                         | Email                    |
| PAYMENT\_INTENT                | Email                    |
| SETUP\_INTENT                  | Email                    |
| CUSTOMER\_BALANCE\_TRANSACTION | Email                    |

### Parameter Defaults

Teleskope’s Stripe integration enforces the following default behavior:

<table><thead><tr><th width="228.78515625">Parameter Name</th><th width="149.98828125">Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>identifier type</strong></td><td>Email</td><td>Always used for Customer Search in Stripe. Supports Phone Number.</td></tr><tr><td><strong>pagination limit</strong></td><td>100</td><td>Max Stripe API page size.</td></tr></tbody></table>

Refer to Stripe's [deletion](https://docs.stripe.com/api/customers/delete) documentation.


# Tealium

Teleskope integrates with Tealium’s APIs to fulfill **Delete User** DSRs by deleting a visitor from a given **account** and **profile**.

## Requirements

In order to integrate Teleskope with Tealium for DSR requests, you must have:

* Your **Tealium Account ID**
* Your **Tealium Profile ID**
* Your **Tealium API Key** (Bearer token)
* *(Optional)* **API URL override**
  * Defaults to `https://api.tealiumiq.com/v2`. Provide a custom base URL only if your environment requires it.
* The data subject’s **Visitor ID** (passed directly in the endpoint path)

{% hint style="info" %}
Retrieval is not supported by this integration.
{% endhint %}

### Integrating with Tealium

To integrate Teleskope with Tealium:

1. Navigate to **Data Subject Rights → Third Party Integrations** and pick **Tealium**.
2. Enter the required fields for the integration and click **Save**:
   * **Account ID** (required)
   * **Profile ID** (required)
   * **API Key** (required)
   * **API URL** (optional; leave blank to use `https://api.tealiumiq.com/v2`)

### Parameter Defaults

* When Teleskope sends a **Delete User** request to Tealium, it includes these parameters by default:
  * **HTTP Method**: `DELETE`
  * **Endpoint**:

    ```
    {apiUrl}/accounts/{accountId}/profiles/{profileId}/visitors/{visitorId}
    ```
  * **Headers**:
    * `Authorization: Bearer <API Key>`
    * `Content-Type: application/json`
  * **Expected success codes**: `200` or `204`
* **Default Identifier for Tealium = `visitor_id`**\
  (The identifier value is sent as `{visitorId}` in the URL path.)

### Behavior and Notes

* The handler issues a single **DELETE** call against the visitors endpoint using your **Account ID**, **Profile ID**, and the subject’s **Visitor ID**.
* If the API response is not `200`/`204`, the error (including response body) is surfaced for troubleshooting.
* On success, Teleskope logs the operation and returns a standard “vendor deletion request submitted” message.

#### Helpful Links

[Tealium Visitor Privacy API Endpoints](https://docs.tealium.com/api/v3/visitor-privacy/endpoints/)


# The Trade Desk

## Requirements

* No vendor credentials are required for this integration.
* Teleskope uses its internal email service to deliver deletion requests to The Trade Desk's designated security address.

### Integrating with The Trade Desk

To integrate Teleskope with The Trade Desk

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick The Trade Desk
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s The Trade Desk integration enforces the following default behavior:

<table><thead><tr><th width="199.5546875">Parameter Name</th><th>Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>targetEmailAddress</strong></td><td>privacy@thetradedesk.com</td><td>The destination address for all deletion requests. Cannot be customized.</td></tr></tbody></table>


# Twilio

## Requirements

In order to integrate Teleskope with Twilio for DSR requests, you must have:

* A SendGrid Admin to provision an API Key

### Integrating with Twilio

To integrate Teleskope with Amplitude

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Twilio.
2. Enter `usused` for the Account SID (no longer needed). Also enter an API Key and click save.
   1. The API Key can be created under `app.sendgrid.com` -> Settings -> API Keys. Note that this is the Secret Key that is only copyable at the time of creation, not the API Key ID.
3. Enable the correct variable or mapping to submit in the call.

### Enroll Twilio for deletion or access requests <a href="#enroll-salesforce-for-deletion-or-access-requests" id="enroll-salesforce-for-deletion-or-access-requests"></a>

The following endpoints are available for deletion or access requests:

| Request Type | Endpoint Name                                                                                                          | Endpoint Name in Teleskope |
| ------------ | ---------------------------------------------------------------------------------------------------------------------- | -------------------------- |
| Deletion     | [EraseJob](https://www.twilio.com/docs/sendgrid/api-reference/recipients-data-erasure-api/erase-recipients-email-data) | User                       |

### Parameter Defaults <a href="#enroll-salesforce-for-deletion-or-access-requests" id="enroll-salesforce-for-deletion-or-access-requests"></a>

Teleskope’s Twilio integration requires specific parameters to process Data Subject Requests (DSRs).

| Parameter Name | Default Value | Notes                                     |
| -------------- | ------------- | ----------------------------------------- |
| **identifier** | Email         | Required. Used to find records to delete. |


# Typeform

## Requirements

<table><thead><tr><th width="191.33984375">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>API Key</strong></td><td>Typeform Personal Access Token. Used in Bearer Authorization header.</td></tr><tr><td><strong>Account ID</strong></td><td>Your Typeform account or workspace ID. Used in the RTBF endpoint URL.</td></tr></tbody></table>

### Integrating with Typeform

To enable the Typeform integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **Typeform** from the list of available third-party vendors.
3. Provide the required credentials:

* **API Key** (Bearer token from Typeform)
* **Account ID** (your Typeform workspace/account ID)

4. Click **Save** to activate the integration.

Once configured, Teleskope can automatically issue deletion requests to Typeform for qualified data subject rights requests.

### Parameter Defaults

Teleskope’s Typeform integration enforces the following default behavior:

<table><thead><tr><th width="183.6953125">Parameter Name</th><th>Default Value</th><th>Notes</th></tr></thead><tbody><tr><td><strong>identifier type</strong></td><td>Email</td><td>Required. Used to match user responses for deletion.</td></tr><tr><td><strong>deletion endpoint</strong></td><td>/rtbf/{accountID}/responses</td><td>Typeform’s RTBF API path.</td></tr></tbody></table>

Refer to Typeform's [DSR](https://developer.typeform.com/responses/rtbf/) documentation.


# Zephr

## Requirements

<table><thead><tr><th width="205.68359375">Parameter</th><th>Description</th></tr></thead><tbody><tr><td><strong>Tenant ID</strong></td><td>Zephr Tenant ID. Used to scope API requests.</td></tr><tr><td><strong>Access Key</strong></td><td>Zephr API Access Key. Used for authentication.</td></tr><tr><td><strong>Secret Key</strong></td><td>Zephr API Secret Key. Used for request signing.</td></tr></tbody></table>

Teleskope securely stores these credentials and uses them for all Zephr API calls.

### Integrating with Zephr

To integrate Teleskope with Zephr

1. Navigate to **Data Subject Rights** → **Third Party Integrations** and pick Zephr
2. Enter the required fields for the integration and click **Save**.

### Parameter Defaults

Teleskope’s Zephr integration enforces the following default behavior:

| Parameter Name      | Default Value | Notes                                               |
| ------------------- | ------------- | --------------------------------------------------- |
| **identifier type** | Email         | Required. Always used to look up the Zephr User ID. |


# Zuora

## Requirements

<table><thead><tr><th width="192.671875">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>Client ID</td><td>OAuth 2.0 Client ID for Zuora API access.</td></tr><tr><td>Client Secret</td><td>OAuth 2.0 Client Secret for Zuora API access.</td></tr><tr><td>Base API URL</td><td>Zuora’s REST API endpoint (US, EU, etc.).</td></tr></tbody></table>

Teleskope securely obtains and manages Bearer tokens using OAuth 2.0 Client Credentials flow.

### Integrating with Zuora

To enable the Zuora integration in Teleskope:

1. Navigate to **Integrations** in the Teleskope UI.
2. Select **Zuora** from the list of available third-party vendors.
3. Provide the required credentials:

* **Client ID** (from Zuora OAuth setup)
* **Client Secret**
* **Base API URL** (e.g. `https://rest.apis.zuora.com`)

4. Click **Save** to activate the integration.

Once configured, Teleskope can automatically issue deletion and retrieval requests to Zuora for qualified data subject rights requests.

### Supported Endpoints & Identifiers

| Endpoint        | Default Identifier |
| --------------- | ------------------ |
| Account         | Email              |
| Contacts        | Email              |
| Payment Methods | Email              |
| Subscriptions   | Email              |
| Invoices        | Email              |
| Usage           | Email              |

*Zuora objects are always matched using the user’s email address (Contact.WorkEmail).*\
Deletion and retrieval requests require providing this identifier.

### Parameter Defaults

Teleskope’s Zuora integration enforces the following default behavior:

| Parameter Name      | Default Value       | Notes                                                       |
| ------------------- | ------------------- | ----------------------------------------------------------- |
| **identifier type** | Email               | Required. Always used to search Contacts to find AccountId. |
| **OAuth2 Scope**    | client\_credentials | Always used for authentication.                             |

Refer to Zuora's REST API [documentation](https://developer.zuora.com/v1-api-reference/introduction/) for more.


# Enroll Structured Databases

Teleskope can automatically enforce data subject rights on your structured databases, by automatically deleting, anonymizing, or retrieving customer data via queries

For each structured data store type that you would like to enroll for data deletion or access requests:

{% stepper %}
{% step %}
**Select the data store type**

Navigate to Data Subject Rights Request > Data Store Integrations, and select the data store type you want to enroll
{% endstep %}

{% step %}
**Determine the list of tables to enroll**

Under unenrolled tables, select the table you would like to enroll. You can also filter the set of unenrolled tables by classification to get suggestions of tables you should enroll for deletion

<figure><img src="/files/uRYZmXOVWiHvFO5cHXHa" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Enroll a table**

For each table, select a subset or all columns you would like to enroll, and whether you'd like to enroll them for access or deletion requests

<figure><img src="/files/bd5A4XrxU1Ko9pROJiOD" alt=""><figcaption></figcaption></figure>
{% endstep %}

{% step %}
**Point to an identifier**

In Step 2, point Teleskope to an identifier.

1. If the table contains an identifier, point us to the column that stores it

<figure><img src="/files/Pkfw6JjGOGANm63dyFoh" alt=""><figcaption></figcaption></figure>

2. If the table does not contain an identifier, select Define a Query, and join the table with a mapping table that contains the identifier.
3. Once your query is defined, validate the query and ensure that Teleskope parsed the correct dependencies. Otherwise, edit the dependency and point it to the right table

<figure><img src="/files/1XcoXwqBjenJhO9msJZr" alt=""><figcaption></figcaption></figure>
{% endstep %}
{% endstepper %}


# Deletion Methods

Teleskope offers a range of deletion options depending on the capabilities of the target platform or tool. Efficiently manage Data Subject Request (DSR) deletions by enrolling each Database table and 3rd party SaaS tool with an appropriate deletion method.

## Relational Databases

To service DSR deletions in an instance, Teleskope must first have read access to crawl its databases, tables, and columns. After identifying its schema, you can determine the Deletion Method during the enrollment process. To automate DSR deletions, Teleskope performs queries that can:

* Anonymize the cell
* Delete the entire row

Upon request, Teleskope can enable alternative [redaction methodologies](/specifications/redaction-methodologies) like those used in our Scrub API.

## Third Party Integrations and Unstructured Databases

To service DSR deletions for third party integrations, Teleskope depends on recommendations and APIs made available by the developer. Often, integrations contain multiple resources (like User, Invoices, Address) that must be deleted to fully scrub a customer's information; in these circumstances, Teleskope allows you to choose the resources and endpoints it relies on.

After enrolling the 3rd party integration, navigate to **DSR -> Third Party Integrations -> Edit -> Enrollments** to specify which endpoints are used for a DSR Deletion requests.

For third party integrations that store **documents** or long form text, Teleskope relies primarily on native redactions or deletion API, but may also *redact from files* directly as a user or admin.

For third party integrations that store **relational user data**, Teleskope relies primarily on available API.

For third party integrations that **do not provide publicly available API**, Teleskope can submit a DSR Deletion Request email on your behalf.

For **unstructured databases**, Teleskope replaces the object with a redacted version, scrubbed of any user data.


# Access Requests


# Policy Maker

Policy Maker is Teleskope's declarative policy engine for defining and enforcing automated governance across scanned or crawled data sources. It allows organizations to create rules based on data sensitivity, accessibility, and staleness, tailored to the capabilities of each connector and data store. Policies can be configured to send alerts, open tickets, or remediate findings, supporting use cases such as audits, compliance, and operational guardrails.

***

## What's in a Policy?

A policy workflow is a visual representation of your policy's logic. Each policy is made up of:

* **Triggers** — the conditions that detect a finding, based on data sensitivity, accessibility, or data age (staleness). You can stack multiple trigger conditions together and set instance thresholds (e.g. trigger only when 3 or more SSNs are found in a resource).
* **Filters** *(optional)* — narrow the scope of the policy to specific subsets of data, such as a particular drive, file type, path, owner, tag, or domain. Use "Ignored Domains" to exempt specific domains from policy enforcement.
* **Alerts** — notifications sent when a finding is detected, via Slack, email, or Jira. You can alert a specific channel, a specific person, or the data owner directly — on both Slack and email.
* **Actions** — automated remediations taken in response to a finding, such as revoking access, redacting data, quarantining a file, unquarantining a file, or tagging a resource.
* **Status** *(optional)* — add a status node to set the outcome state of the finding (e.g. "Resolved"). Recommended for tracking purposes but not required.

***

## Capabilities

### Building Policies

* **Visual workflow builder** — build your policy as a drag-and-connect node graph
* **Connector selection** — each policy is scoped to one connector (e.g. Google Drive, OneDrive, S3, SharePoint, Snowflake, Slack, Zendesk, and more)
* **Trigger configuration** — define what constitutes a finding based on sensitivity, accessibility, or staleness; set minimum instance counts for data element triggers
* **Filter nodes** — scope your policy to specific resources or data subsets; exempt specific domains using "Ignored Domains"
* **Alert Groups** — group multiple alert destinations (e.g. notify a channel and the data owner simultaneously) before continuing to a single action path
* **Delay nodes** — add a time delay between nodes; the workflow pauses and resumes automatically once the delay expires
* **Multi-select data elements** — pick multiple data elements at once when configuring triggers
* **Inline validation** — the builder only shows actions and alerts valid for the selected connector
* **Version history** — changes to a policy are tracked and visible from the policy detail view. Click into a policy and open the Version History tab to see a full audit trail of edits — what changed, who made the change, and when. This includes changes to triggers, workflow nodes, and policy settings.
* **Save, edit, archive** — policies can be saved, edited, duplicated, and archived at any time
* **Immediate execution** — when a policy is saved or created, it runs immediately so findings are surfaced right away
* **Policy detail view** — click any policy to see its trigger description, finding counts, enabled/disabled status, connector, severity, framework, and a read-only workflow canvas

### Alert Types

* **Slack alerts** — notify a specific channel or the resource data owner directly via Slack DM
* **Email alerts** — send email notifications when findings are detected; supports notifying the data owner directly (same as Slack) and action buttons for end-user responses
* **Jira alerts** — create Jira tickets for findings

### Actions

Available actions vary by connector. Commonly supported actions include revoking access, redacting data elements, tagging resources, quarantining files, unquarantining files, and reporting false positives or business justifications via Slack.

### Findings View

The Findings View gives you a rich, unified picture of everything your policies are detecting across all connectors.

* **Findings overview tab** — a summary of all findings across your policies, with severity, policy type, and framework tagging
* **Finding status** — findings move through four states: **Open** (detected, no action yet), **In Progress** (workflow is running — e.g. awaiting a user response before the next step), **Resolved**, and **Ignored**
* **Findings Progress Dashboard** — a bar chart showing the running total of open findings over an adjustable time range. Each bar reflects the number of open findings in that period, calculated as findings that were open at the start of the period plus newly opened findings, minus those resolved or ignored. Use the time range selector to zoom in or out across your findings history.
* **Data Store view** — see findings organized by the data stores where they were detected
* **Resource view** — drill into individual resources that are in findings, with full details including data elements, permissions, and a Prism summary
* **Resource details modal** — a rich detail panel showing the overview, permissions, and all findings for that resource
* **Instance count** — findings show how many times each sensitive data element was found within the triggering resource (e.g. SSN (3))

From the Findings view you can:

* Mark findings as **Ignored** (with a required reason, such as a false positive or business justification) or **Resolved**
* Take **ad-hoc remediation actions** directly from findings — redact, revoke access, remove shared links, quarantine, or tag — individually or in bulk
* Manage findings individually or in bulk with flexible filters
* **Auto-archiving:** when a policy is edited and a finding no longer matches the updated trigger conditions, it is automatically archived and removed from the active findings view

***

## How to Use Policy Workflows

{% stepper %}
{% step %}
**Navigate to Policies**

In the left-hand navigation, find and click **Policies**.
{% endstep %}

{% step %}
**Create a New Policy**

Click **Create policy** to open the workflow builder.
{% endstep %}

{% step %}
**Select a Connector**

Choose the connector this policy will apply to — for example, Google Drive, OneDrive, S3, SharePoint, or Snowflake. Each policy is tied to one connector, and the available triggers, filters, and actions will update based on your selection.
{% endstep %}

{% step %}
**Add Triggers**

Add one or more trigger conditions that define what constitutes a finding. Triggers fall into three categories:

* **Sensitivity** — triggered when classified data (e.g., PII, PHI, financial data) is detected
* **Accessibility** — triggered by access findings (e.g., a file shared externally or publicly)
* **Staleness** — triggered by data age (e.g., last accessed more than 90 days ago)

For data element triggers, you can also set a minimum instance count — for example, trigger only when 3 or more credit card numbers appear in a resource.

You can combine multiple trigger conditions within a single policy.
{% endstep %}

{% step %}
**Build Your Workflow**

After adding at least one trigger, the workflow graph unlocks. From here, you can add nodes by clicking the **+** button and selecting the node type:

* Add a **Filter** node to narrow down which resources the policy applies to; use "Ignored Domains" to exempt trusted domains
* Add an **Alert** node to send notifications (Slack, email, or Jira) when a finding is detected
* Use an **Alert Group** to send multiple alerts simultaneously before continuing to a single action path
* Add a **Delay** node to pause the workflow before the next step
* Add an **Action** node to take automated remediation steps
* Add a **Status** node to set the outcome state of the finding (optional but recommended for tracking)
  {% endstep %}

{% step %}
**Save and Activate**

Click **Save** to store the policy. It will appear in the Policies list and will run immediately. From there you can:

* Click the policy name to open the policy detail view
* Edit the policy at any time by clicking its name
* Enable or disable automated execution via the toggle
* Duplicate or archive the policy from the policy detail view
  {% endstep %}
  {% endstepper %}

***

## Tips for Getting the Most Out of Policy Workflows

* **Use filters to reduce noise.** If a policy is catching too many things, add a filter node to narrow the scope — for example, scope to a specific drive, site, or file type.
* **Alert before you act.** A good pattern is to start with alerts only, monitor for a week or two, then add automated actions once you're confident in the policy's accuracy.
* **Stack multiple trigger conditions.** You can add multiple trigger conditions to a single policy, which gives you more precise control over what gets flagged.

## Common Policies to Get Started

Not sure where to begin? Here are the most common policy types we tend to see, organized by use case. These cover the scenarios that matter most to security, compliance, and data governance teams.

### 🔓 Data Exposure & Access Control

These policies detect sensitive data that has been shared too broadly.

**Externally shared files with sensitive data**\
Detect files containing PII, financial data, or credentials that are shared with external users or domains.

* *Trigger:* Sensitivity (High or Critical) + Accessibility (external users have access)
* *Actions:* Slack alert to data owner → revoke external access

**Public link access**\
Detect sensitive files accessible via "anyone with the link."

* *Trigger:* Accessibility (public/anonymous link) + Sensitivity (any)
* *Actions:* Slack alert to a security channel → disable public link

**Domain-wide access**\
Detect sensitive files shared with your entire organization — files that anyone in the company can access.

* *Trigger:* Accessibility (org-wide or domain-wide sharing) + Sensitivity (High or Critical)
* *Actions:* Slack alert to a security channel → restrict access to specific users or groups

**Personal email sharing**\
Detect files shared with personal email domains (Gmail, Yahoo, etc.).

* *Trigger:* Accessibility (shared with personal domains) + Sensitivity (High or Critical)
* *Actions:* Alert data owner via Slack or email

### Data Retention & Stale Data

Enforce data lifecycle requirements and help reduce data sprawl.

**Stale files with sensitive data**\
Find old files that still contain sensitive data and haven't been accessed in years.

* *Trigger:* Staleness (last accessed > 3 years) + Sensitivity (Medium or above)
* *Actions:* Email alert to data owner → archive or delete

**Dormant database tables**\
Identify database tables (Snowflake, RDS) that haven't been accessed in 90+ days.

* *Trigger:* Staleness (last accessed > 90 days)
* *Actions:* Slack alert to data owner

***

### PII & Sensitive Data Detection

Policies focused on finding specific sensitive data elements, regardless of sharing status.

**SSN / Government ID detection**\
Find resources containing Social Security Numbers, driver's licenses, or passports.

* *Trigger:* Data element is SSN, Driver's License, or Passport
* *Actions:* Slack or email alert → tag resource for review

**Financial data detection**\
Detect credit card numbers, bank account numbers, or financial documents.

* *Trigger:* Data element is Credit Card Number, Bank Account, or Financial category
* *Actions:* Alert security channel

**Credentials & secrets**\
Find API keys, passwords, tokens, or PEM files stored in files or code.

* *Trigger:* Data element is Password, API Key, or Secret category
* *Actions:* Slack alert → quarantine or redact

***

### Automated Remediation

For teams ready to move beyond detection, these policies take direct action when findings are found. We recommend starting with alerts-only and running a dry run before enabling automated actions.

**Auto-quarantine sensitive messages (Slack)**\
Automatically quarantine Slack messages containing government IDs, SSNs, or credit card numbers.

* *Trigger:* Data element is SSN, CCN, or Government ID
* *Actions:* Quarantine message → notify user via Slack DM

**Redact PII in support tickets (Zendesk)**\
Automatically redact customer PII from closed or solved support tickets.

* *Trigger:* Data element category is Profile or Financial
* *Filter:* Ticket status is Closed or Solved
* *Actions:* Redact data elements

**Revoke access on externally shared sensitive files**\
Automatically remove external access on files containing critical data.

* *Trigger:* Accessibility (external users) + Sensitivity (Critical)
* *Actions:* Revoke external access → notify data owner

***

### Compliance Framework Policies

Policies tied to specific regulatory requirements.

**SOC 2 — Access control monitoring**\
Detect sensitive data with overly permissive access, supporting SOC 2 access control criteria.

* *Trigger:* Accessibility (public or external) + Sensitivity (High or Critical)
* *Actions:* Alert security team

**HIPAA — PHI in unauthorized locations**\
Detect protected health information stored outside approved systems.

* *Trigger:* Data category is Medical/PHI
* *Filter:* Exclude approved storage locations
* *Actions:* Alert compliance team

**PCI DSS — Credit card data handling**\
Monitor for credit card data appearing in unapproved connectors or locations.

* *Trigger:* Data element is Credit Card Number or CVV
* *Actions:* Alert security channel → redact or quarantine


# Identity View

## What is Identity View?

Identity View gives you a centralized, searchable view of every identity that has access to your data — across all connected sources. Instead of hunting through individual connectors to understand who can access what, Identity View brings all of that context into one place.

An identity is any user, service account, or external party that has been granted access to a resource that Teleskope has scanned. Identity View lets you understand the scope of that access — what data they can reach, how sensitive it is, and whether that access carries any risk.

Identity View covers two types of identities:

* **Human identities** — users identified by email address across SaaS connectors (Google Drive, SharePoint, Slack, etc.)
* **Non-Human Identities (NHIs)** — service accounts, bots, and integrations that have access to your data but aren't associated with a person's email

***

## Navigating to Identity View

1. In the left-hand navigation, click **Identities**
2. You'll land on the **Identities overview page**, which gives a high-level summary of your identity landscape
3. From there you can drill into the **Identities list**, the **Non-Human Identities tab**, or the **Domains list**

***

## The Overview Page

When you first land in Identity View, you'll see a summary of key signals across all your identities:

* **Trust level breakdown** — a chart showing how many identities fall into each trust category (Internal, External, Personal, Non-Human)
* **Top identities** — the identities with the broadest or most sensitive data access
* **Top external or personal domains** — the external domains (e.g. gmail.com, contractor organizations) that have the most access to your data

This overview is designed to help you quickly spot areas of elevated risk — for example, a high number of external identities with access to critical data.

***

## The Identities List

The Identities list shows every human identity that has access to data in your connected sources. For each identity you can see:

* **Email / identifier** — the identity's email address
* **Type** — whether the identity is Internal, External, or Personal
* **Trust level** — a classification of how trusted the identity is based on its relationship to your organization
* **Max sensitivity** — the highest sensitivity level of any resource this identity has access to
* **Resource count** — the number of resources the identity can access

You can **search** for a specific identity by name or email, **filter** by type, trust level, or sensitivity level, and **sort** by any column to quickly surface the highest-risk identities.

***

## Identity Details

Clicking any identity in the list opens a detail page with a deeper view of that specific identity's access. This includes:

* **Sensitivity rollup** — a breakdown of how many resources the identity can access at each sensitivity level (Critical, High, Medium, Low)
* **Data elements** — the types of sensitive data the identity has access to (e.g. SSN, credit card numbers, email addresses)
* **Data categories** — the broader data categories covered (e.g. PII, PHI, PCI)
* **Document types** — the types of files or resources in scope
* **Data resources table** — a full list of every resource this identity has access to, with connector, sensitivity, and file path shown for each row

From the data resources table you can search, filter, and export the list as a CSV.

***

## Organization Identity Settings

Identity View's trust level classifications — Internal, External, and Personal — are determined by your **Internal Domains** configuration. This is what controls whether an identity shows up as a trusted internal user or as an external party in the overview chart, the identities list, and all access rollups.

To view or update your internal domains:

1. Go to **Settings** in the left-hand navigation
2. Open **Organization Identity** and select the **Internal domains** tab
3. Add or remove the email domains that belong to your organization (e.g. `yourcompany.com`)

Any identity whose email matches a configured internal domain is classified as **Internal**. Identities with personal email domains (e.g. `gmail.com`, `outlook.com`) are classified as **Personal**. All others are classified as **External**.

If a colleague is showing up as External, it's likely because their email domain hasn't been added to your internal domains list. Updating this setting will re-classify all affected identities.

This page is admin-only.

***

## Non-Human Identities (NHI)

The **Non-Human Identities tab** surfaces service accounts, integrations, and AWS IAM principals — identities that have access to your data but aren't tied to a specific person's email address.

### What counts as a Non-Human Identity?

NHIs fall into two groups:

* **Registered identities** — service accounts and integrations that your team registers manually via the **Organization Identity** page in Settings. Once registered, an identity moves out of the human identities list and appears in the NHI tab instead.
* **AWS IAM principals** — IAM roles and users with access to your AWS data. Available as a premium add-on — see below.

### What you can see for each NHI

For each NHI, the tab shows:

* **Display name / identifier** — how the identity is identified
* **Type** — Role, User, or Service
* **Max sensitivity** — the highest sensitivity level of any resource this identity can access
* **Resource count** — the number of resources in scope

Clicking an NHI opens a detail page with its full data resources table.

### Registering a Non-Human Identity

To register a service account or integration:

1. Go to **Settings** in the left-hand navigation
2. Open **Organization Identity** page and select the **Non-Human Identities** tab
3. Click **Register** and enter the identity's email address or identifier
4. Select the appropriate subtype (Service Account, Bot, Integration, Shared Mailbox)
5. Save — the identity will appear in the NHI tab and be excluded from the human identities list

> Reach out to your Technical Account Manager to help identify existing NHIs within your account!

## AWS IAM Identity Coverage

> AWS IAM Identity Coverage is available as a premium add-on. To learn more or get it enabled for your environment, reach out to your Technical Account Manager.

Teleskope can surface AWS IAM roles and users alongside your SaaS identities, giving you a unified view of who — and what — has access to your sensitive data across both cloud infrastructure and SaaS applications.

With AWS IAM coverage enabled, the Non-Human Identities tab will include your AWS principals, showing:

* **IAM roles and users** with access to your AWS data sources (e.g. S3)
* **Max sensitivity** — the highest sensitivity level of any resource the principal can reach
* **Resource count** — the number of AWS resources in scope

AWS IAM principals are identified by ARN and appear separately from email-keyed identities, since they aren't tied to a specific person without an AWS Organizations or Identity Center connection.

***

## The Domains List

The Domains list groups human identities by email domain, giving you a view of access by organization or domain rather than by individual user. This is particularly useful for understanding the scope of external or contractor access.

For each domain you can see the number of identities associated with it and the count of resources those identities can access. Clicking a domain opens a **Domain Detail** page showing the individual identities within that domain and their access.

***

## Things to Know

**Connector coverage**

Identity View surfaces access data from Google Drive and SharePoint. Not all connectors may be enabled for your environment — check with your admin or Customer Engineer to confirm which sources are in scope for your organization.

**Data freshness**

Identity View reflects access data as of the last connector sync. If a permission was recently granted or revoked, it may not appear immediately. For questions about when data was last refreshed, reach out to your Customer Engineer.

**Role-based access**

Identity View requires the Identities role permission (Settings → Roles) and must be enabled for your environment. If you don't see Identities in your navigation, check with your admin, or reach out to your Customer Engineer to confirm it's enabled.

***

## Feedback

Identity View is new and actively improving. If you run into unexpected results, have suggestions, or want to share what's working well, please reach out to your Technical Account Manager.


# Document Type Manager

## What is Document Type Manager?

**Document Type Manager** is a settings feature in Teleskope that lets you view, customize, and create the document types used to classify your data. Document types are the content-based labels Teleskope applies to your files — things like "Financial Forecast", "Health Insurance Information", "Contract", or "Employee Record" — that go beyond basic sensitivity levels to describe what a file actually contains.

These labels appear across the platform in the Data Catalog, Data Explorer, and Policy Maker, and can be used as filters when browsing your data or as triggers and conditions in policies. Document Type Manager is where you control what those labels are and how they work.

***

## What Would You Use It For?

Out of the box, Teleskope ships with a set of built-in document types that cover common content categories. Document Type Manager lets you go further by tailoring document types to your organization's specific needs.

Common use cases include:

* **Adding custom document types** — define categories that are specific to your business, such as "Retention Schedule", "Merger Agreement", or "Diabetic Information"
* **Editing existing document types** — update the display name, description, or the underlying queries that determine what gets classified as that type
* **Reviewing what's been classified** — see how many resources have been tagged with each document type and when tags were last applied
* **Generating new document types with AI** — describe a document type in plain English and let Teleskope generate a full definition, including a description, summary, and detection queries, which you can review and adjust before committing
* **Previewing suggested document types** — Teleskope can analyze a sample of your data and surface document types it hasn't seen you define yet, so you can quickly discover gaps in your classification coverage
* **Running a dry run** — test a document type against your data before applying it broadly, to see how many resources it would match and whether the results look accurate
* **Deleting document types** — remove document types that are no longer relevant or were created in error

***

## Navigating to Document Type Manager

Document Type Manager lives in the **Settings** section of the platform.

1. Click **Settings** in the left-hand navigation
2. Select **Document Type Manager**
3. You'll land on the **Overview tab**, which shows a table of all document types currently configured in your environment

***

## The Overview Tab

The Overview tab is the main table view of all document types. For each document type you can see:

* **Display name** — the label shown across the platform
* **Description** — a plain-language explanation of what this type covers
* **Tagged resources** — the number of resources currently classified as this type
* **Last generated** — the last time tags were applied for this document type

Clicking any row opens a **side panel** with more detail on that document type, including its underlying detection queries and options to edit or delete it.

***

## Creating a New Document Type

You can create a new document type manually or use the AI generator to build one from a description.

1. Click **Auto-generate a type** and describe the document type you want in plain English — for example, "internal memos about company restructuring" or "documents related to employee compensation"
2. Teleskope will generate a proposed display name, description, and detection queries based on your input
3. Review and edit any field before confirming
4. Optionally, run a **dry run** to preview how many resources it would match before committing
5. Click **Create** to save and begin applying it to your data

You can also create a document type manually by entering a display name, description, and detection queries directly — but the AI generator is the recommended starting point for most cases.

***

## Editing a Document Type

1. Click any document type row to open the side panel
2. Click **Edit display name** or **Edit description** to update those fields
3. To modify detection queries, use the query editor in the side panel — you can add, remove, or adjust queries
4. Changes are saved immediately

***

## Suggested Document Types

Teleskope can analyze a sample of your scanned data and surface document types it thinks you may want to define. These suggestions appear in the Document Type Manager UI and are based on patterns in your actual content.

Clicking a suggestion pre-populates the AI generator with the proposed type, which you can then review, edit, and commit — or discard if it's not relevant.

***

## Dry Run

Before committing a new or edited document type to production, you can run a **dry run** to preview which resources it would match. Dry run results are not written to the database — they're a safe, read-only preview.

To run a dry run:

1. Open the document type (or a proposed type you've just generated)
2. Click **Dry run**
3. Review the results — you'll see a count and sample of matching resources
4. If the results look right, proceed to commit; if not, adjust your queries and try again

***

## Using Document Types Across the Platform

Once document types are configured, they appear throughout Teleskope:

* **Data Catalog & Data Explorer** — filter and search by document type to find specific categories of content
* **AI Search** — query for document types in natural language, e.g., `show me all Contracts with PII in SharePoint`
* **Policy Maker** — use document types as triggers or filter conditions in policies, e.g., trigger a policy when a file classified as "Financial Forecast" is shared externally


# API Service

## API

#### Classification

* **Classify** - Detect personal or sensitive information within a given payload
* **Classify Collection** - Detect personal or sensitive information within a structured data set

#### Redaction

* **Scrub** - Redact sensitive information from a given payload with any redaction methodology

#### Data Subject Rights

* **Get** - Retrieve DSR requests
* **Post** - Submit a DSR request

#### Metadata

Teleskope's Metadata API surfaces classification records for each of your connected datastores.

## Use Cases

<details>

<summary>Guard Agent</summary>

Teleskope's Classify and Classify Collection endpoints empower custom agents to detect personal or sensitive information as it is processed; for instance, data entered into an internal chat application, forum, or customer support tool. Instead of relying solely on regex or static filtering, integrate Teleskope to handle the identification and then redaction of sensitive information by leveraging our Scrub API. The Scrub API can incorporate a variety of [<mark style="color:purple;">redaction methodologies</mark>](/specifications/redaction-methodologies) to anonymize, encrypt, or redact sensitive data-in-transit.

</details>

<details>

<summary><strong>Data Subject Rights Automation</strong></summary>

By leveraging the Data Subject Rights API, businesses can automate deletion and access requests under regulations like GDPR or CCPA. Through the submission and retrieval of DSR tasks, you can streamline compliance workflows and reduce the manual effort required in managing requests across all of your datastores, repositories, and SaaS applications.

</details>

<details>

<summary>Clean Machine Learning Training Data</summary>

Use Teleskope's Scrub endpoint to redact personal or sensitive information from datasets intended for machine learning model training to ensure that your test data is compliant with privacy laws, reducing the risk of data breaches, and enhancing the ethical use of data in your AI applications. Scrubbing production data allows for a larger, more accurate, and less bias dataset for training models; instead of deleting your customer data entirely, mask it with synthetic data of the same type for fidelity.

</details>

<details>

<summary>Data Element Trend Analysis</summary>

Organizations can manually record classifications created by the Classify API through an agent or, if leveraging official Teleskope Connectors, call the Metadata API to retrieve your classifications by level (column, table, schema, or database). Then ingest the results into your business intelligence platform of choice to evaluate changes in PII frequency over time.

</details>


# Scanning API


# v1/classify

Detect personal or sensitive information in a payload without modifying it. Use the body fields below to control which elements are reported. To redact rather than detect, use [v1/scrub](/the-platform/api-service/redaction-api/v1-scrub).

{% openapi src="/files/cGyOSqpybs6wM3Oy8JMJ" path="/v1/classify" method="post" %}
[{"openapi":"3.12.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2Fgit-blob-8868525e0357b58fd3f49b11e1b4d888773e49fc%2F%7B%22openapi%22%3A%223.12.json?alt=media)
{% endopenapi %}

## Body options

| Field               | Type      | Description                                                                                                                                                            |
| ------------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `content`           | string    | Text to classify. Required.                                                                                                                                            |
| `filters`           | string\[] | Allow-list of element labels to report. Omit to report every supported element.                                                                                        |
| `excludeFilters`    | string\[] | Deny-list of element labels to skip. Takes precedence over `filters`.                                                                                                  |
| `sensitivityLevels` | string\[] | Restrict results to these tiers: `low`, `medium`, `high`, `critical`. Elements with no assigned tier are always included.                                              |
| `useML`             | boolean   | Enable ML-based detection in addition to rules. Defaults to `true`.                                                                                                    |
| `treatAsJSON`       | boolean   | Treat `content` as a JSON string: classify only inside string values. Use for JSON payloads. The root must be an object; wrap a top-level array as `{"items": [...]}`. |

## Response fields

Each entry in `classifications` describes one detected element.

| Field       | Type      | Description                                                                             |
| ----------- | --------- | --------------------------------------------------------------------------------------- |
| `index`     | integer   | Position of this result within `classifications`.                                       |
| `class`     | string    | Element label, for example `email`. Use this value with `filters` and `excludeFilters`. |
| `category`  | string\[] | Categories the element belongs to.                                                      |
| `startChar` | integer   | Character offset of the match within `content`.                                         |
| `charSize`  | integer   | Length of the match in characters.                                                      |
| `startByte` | integer   | Byte offset of the match within `content`.                                              |
| `byteSize`  | integer   | Length of the match in bytes.                                                           |
| `version`   | integer   | Taxonomy version used for this result.                                                  |

Use `startChar` and `charSize` in languages with character-indexed strings, and `startByte` and `byteSize` when slicing raw bytes. The two differ whenever the payload contains multi-byte characters.

The response also carries `scanner_version`, `ml_classifier_used`, and `timing`.

{% hint style="warning" %}
Earlier revisions of this page showed `data_element`, `star_char`, and `char_size`. The API has never emitted those names. Code written against them parses a valid response and finds nothing. Read `class`, `startChar`, and `charSize`.
{% endhint %}

## Element labels

`filters` and `excludeFilters` accept element labels from the [Entity Taxonomy](/specifications/data-elements/entity-taxonomy-v2).

Names and email addresses are `medium` tier. Setting `sensitivityLevels` to `["high", "critical"]` alone excludes them; use `["medium", "high", "critical"]` to cover everyday personal data.

## Related

* [v1/classifyCollection](/the-platform/api-service/scanning-api/v1-classifycollection) — classify multiple values in one request.
* [v1/scrub](/the-platform/api-service/redaction-api/v1-scrub) — redact instead of detect.
* [Redaction Methodologies](/specifications/redaction-methodologies) — how each redaction style transforms a detected value.


# v1/classifyCollection

{% openapi src="/files/cGyOSqpybs6wM3Oy8JMJ" path="/v1/classifyCollection" method="post" %}
[{"openapi":"3.12.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2Fgit-blob-8868525e0357b58fd3f49b11e1b4d888773e49fc%2F%7B%22openapi%22%3A%223.12.json?alt=media)
{% endopenapi %}


# v1/scan

{% openapi src="/files/cGyOSqpybs6wM3Oy8JMJ" path="/v1/scan" method="post" %}
[{"openapi":"3.12.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2Fgit-blob-8868525e0357b58fd3f49b11e1b4d888773e49fc%2F%7B%22openapi%22%3A%223.12.json?alt=media)
{% endopenapi %}


# Redaction API


# v1/scrub

Redact personal or sensitive information from a payload. Set the redaction style with the `redactionStyle` query parameter and control which elements are redacted with the body fields below.

{% openapi src="/files/cGyOSqpybs6wM3Oy8JMJ" path="/v1/scrub" method="post" %}
[{"openapi":"3.12.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2Fgit-blob-8868525e0357b58fd3f49b11e1b4d888773e49fc%2F%7B%22openapi%22%3A%223.12.json?alt=media)
{% endopenapi %}

## Redaction styles

Set `?redactionStyle=` on the request. The value is case-insensitive, and an unrecognized value falls back to `class`. See [Redaction Methodologies](/specifications/redaction-methodologies) for the underlying methods.

| Style            | Result                                                                                                                                    |
| ---------------- | ----------------------------------------------------------------------------------------------------------------------------------------- |
| `class`          | Replaces the value with its entity label, e.g. `<EMAIL>`. Default.                                                                        |
| `class_numbered` | Numbered labels, e.g. `<email_1>`. Identical values share a number.                                                                       |
| `empty`          | Drops the matched value.                                                                                                                  |
| `masked`         | Replaces characters with `*`.                                                                                                             |
| `encrypted`      | AES-SIV, reversible. Always pass a `key` (32, 48, or 64 bytes) — it is not enforced, and output produced without one cannot be decrypted. |
| `tokenized`      | Format-preserving tokens for email, IPv4, IPv6, MAC, and phone. All other elements fall back to `<CLASS>`.                                |

## Body options

| Field               | Type      | Description                                                                                                                                    |
| ------------------- | --------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| `content`           | string    | Text to scrub. Required.                                                                                                                       |
| `filters`           | string\[] | Allow-list of element labels to redact. Omit to redact every supported element.                                                                |
| `excludeFilters`    | string\[] | Deny-list of element labels to skip. Takes precedence over `filters`.                                                                          |
| `sensitivityLevels` | string\[] | Restrict redaction to these tiers: `low`, `medium`, `high`, `critical`. Elements with no assigned tier are always included.                    |
| `useML`             | boolean   | Enable ML-based detection in addition to rules. Defaults to `true`.                                                                            |
| `treatAsJSON`       | boolean   | Treat `content` as a JSON string: classify only inside string values and preserve structure so the output still parses. Use for JSON payloads. |


# Data Subject Rights


# GET v1/dsr/requests

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/dsr/requests" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# POST v1/dsr/requests

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/dsr/requests" method="post" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Metadata

Teleskope's Metadata API surfaces classification records for each of your connected data stores. Use these endpoints to programmatically retrieve data element classifications, user permissions, and resource inventories across all enrolled connectors.

All Metadata API requests require an `X-API-KEY` header for authentication.

## Supported Connectors

| Provider      | Endpoints                                 |
| ------------- | ----------------------------------------- |
| **AWS**       | RDS, S3, Redshift, DynamoDB, Users        |
| **GCP**       | Cloud SQL, BigQuery, Cloud Storage, Users |
| **Azure**     | SQL, Blob Storage                         |
| **Snowflake** | Metadata, Users                           |

## Common Parameters

All metadata endpoints support the following query parameters:

| Parameter                 | Type    | Description                                                 |
| ------------------------- | ------- | ----------------------------------------------------------- |
| `limit`                   | integer | Maximum number of records to return per page (default: 100) |
| `page`                    | integer | Page number for pagination (default: 1)                     |
| `data_element_categories` | string  | Filter by data element category                             |
| `data_elements`           | string  | Filter by specific data elements                            |

Each connector may support additional connector-specific filter parameters documented on the individual endpoint pages.


# AWS

Teleskope's Metadata API surfaces classification records for your connected AWS data stores.

Available endpoints:

* **RDS** - Retrieve classification metadata for RDS clusters, databases, tables, and columns
* **S3** - Retrieve classification metadata for S3 buckets and objects
* **Redshift** - Retrieve classification metadata for Redshift clusters, databases, schemas, and tables
* **DynamoDB** - Retrieve classification metadata for DynamoDB tables
* **Users** - Retrieve user permissions and access records for AWS resources


# RDS


# RDS Metadata API

## GET /aws/rds/clusters

> List RDS Clusters

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsClustersResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsCluster"}},"total_count":{"type":"integer"}}},"RdsCluster":{"type":"object","properties":{"id":{"type":"integer"},"region":{"type":"string"},"engine_type":{"type":"string"},"engine_version":{"type":"string"},"identifier":{"type":"string"},"write_endpoint":{"type":"string"},"read_endpoint":{"type":"string"},"encrypted":{"type":"boolean"},"publicly_accessible":{"type":"boolean"},"open_to_the_world":{"type":"boolean"},"multi_az":{"type":"boolean"},"deletion_protection":{"type":"boolean"},"iam_authentication_enabled":{"type":"boolean"},"backup_retention_period":{"type":"integer"},"database_count":{"type":"integer"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/clusters":{"get":{"summary":"List RDS Clusters","operationId":"getRdsClusters","parameters":[{"in":"query","name":"aws_account_ids","description":"Comma-separated list of AWS Account IDs","schema":{"type":"string"}},{"in":"query","name":"data_elements","description":"Comma-separated list of data elements","schema":{"type":"string"}},{"in":"query","name":"data_categories","description":"Comma-separated list of data categories","schema":{"type":"string"}},{"in":"query","name":"search","description":"Search clusters by identifier, append the search key with \"identifier:<name>\"","schema":{"type":"string"}},{"in":"query","name":"sort_by","schema":{"type":"string"}},{"in":"query","name":"asc","schema":{"type":"boolean"}},{"in":"query","name":"limit","schema":{"type":"integer"}},{"in":"query","name":"offset","schema":{"type":"integer"}}],"responses":{"200":{"description":"List of RDS clusters","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsClustersResponse"}}}}}}}}}
```

## GET /aws/rds/clusters/{id}

> Get a specific RDS cluster

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsCluster":{"type":"object","properties":{"id":{"type":"integer"},"region":{"type":"string"},"engine_type":{"type":"string"},"engine_version":{"type":"string"},"identifier":{"type":"string"},"write_endpoint":{"type":"string"},"read_endpoint":{"type":"string"},"encrypted":{"type":"boolean"},"publicly_accessible":{"type":"boolean"},"open_to_the_world":{"type":"boolean"},"multi_az":{"type":"boolean"},"deletion_protection":{"type":"boolean"},"iam_authentication_enabled":{"type":"boolean"},"backup_retention_period":{"type":"integer"},"database_count":{"type":"integer"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/clusters/{id}":{"get":{"summary":"Get a specific RDS cluster","operationId":"getRdsCluster","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"integer"}}],"responses":{"200":{"description":"RDS cluster details","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsCluster"}}}}}}}}}
```

## GET /aws/rds/databases

> Get a list of RDS databases

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsDatabasesResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsDatabase"}},"total_count":{"type":"integer"}}},"RdsDatabase":{"type":"object","properties":{"id":{"type":"integer"},"database_name":{"type":"string"},"schema_name":{"type":"string"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/databases":{"get":{"summary":"Get a list of RDS databases","operationId":"getRdsDatabases","parameters":null,"responses":{"200":{"description":"List of RDS databases","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsDatabasesResponse"}}}}}}}}}
```

## GET /aws/rds/databases/{id}

> Get a specific RDS database

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsDatabase":{"type":"object","properties":{"id":{"type":"integer"},"database_name":{"type":"string"},"schema_name":{"type":"string"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/databases/{id}":{"get":{"summary":"Get a specific RDS database","operationId":"getRdsDatabase","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"integer"}}],"responses":{"200":{"description":"RDS database details","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsDatabase"}}}}}}}}}
```

## GET /aws/rds/tables

> List RDS tables

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsTablesResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsTable"}},"total_count":{"type":"integer"}}},"RdsTable":{"type":"object","properties":{"id":{"type":"integer"},"table_name":{"type":"string"},"data_size":{"type":"integer"},"row_count":{"type":"integer"},"last_scanned":{"type":"string","format":"date-time"},"dsr_query":{"type":"string"},"column_count":{"type":"integer"},"access_enabled":{"type":"boolean"},"deletion_enabled":{"type":"boolean"},"dsr_enabled":{"type":"boolean"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/tables":{"get":{"summary":"List RDS tables","operationId":"getRdsTables","parameters":null,"responses":{"200":{"description":"List of RDS tables","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsTablesResponse"}}}}}}}}}
```

## GET /aws/rds/tables/{id}

> Get a specific RDS table

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsTable":{"type":"object","properties":{"id":{"type":"integer"},"table_name":{"type":"string"},"data_size":{"type":"integer"},"row_count":{"type":"integer"},"last_scanned":{"type":"string","format":"date-time"},"dsr_query":{"type":"string"},"column_count":{"type":"integer"},"access_enabled":{"type":"boolean"},"deletion_enabled":{"type":"boolean"},"dsr_enabled":{"type":"boolean"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/tables/{id}":{"get":{"summary":"Get a specific RDS table","operationId":"getRdsTable","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"integer"}}],"responses":{"200":{"description":"RDS table details","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsTable"}}}}}}}}}
```

## GET /aws/rds/columns

> Get a list of RDS columns

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsColumnsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsColumn"}},"total_count":{"type":"integer"}}},"RdsColumn":{"type":"object","properties":{"id":{"type":"string"},"column_name":{"type":"string"},"column_type":{"type":"string"},"identifier_id":{"type":"string"},"identifier_name":{"type":"string"},"access_enabled":{"type":"boolean"},"custom_access_label":{"type":"string"},"deletion_enabled":{"type":"boolean"},"deletion_algorithm":{"type":"string"},"no_data":{"type":"boolean"},"table_last_scanned":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"rds_table_id":{"type":"integer"},"rds_table_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/columns":{"get":{"summary":"Get a list of RDS columns","operationId":"getRdsColumns","parameters":null,"responses":{"200":{"description":"List of RDS columns","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsColumnsResponse"}}}}}}}}}
```

## GET /aws/rds/columns/{id}

> Get a specific RDS column

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"RdsColumn":{"type":"object","properties":{"id":{"type":"string"},"column_name":{"type":"string"},"column_type":{"type":"string"},"identifier_id":{"type":"string"},"identifier_name":{"type":"string"},"access_enabled":{"type":"boolean"},"custom_access_label":{"type":"string"},"deletion_enabled":{"type":"boolean"},"deletion_algorithm":{"type":"string"},"no_data":{"type":"boolean"},"table_last_scanned":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"rds_table_id":{"type":"integer"},"rds_table_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}},"paths":{"/aws/rds/columns/{id}":{"get":{"summary":"Get a specific RDS column","operationId":"getRdsColumn","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"RDS column details","content":{"application/json":{"schema":{"$ref":"#/components/schemas/RdsColumn"}}}}}}}}}
```


# Models

## The Persona object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsCluster object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsCluster":{"type":"object","properties":{"id":{"type":"integer"},"region":{"type":"string"},"engine_type":{"type":"string"},"engine_version":{"type":"string"},"identifier":{"type":"string"},"write_endpoint":{"type":"string"},"read_endpoint":{"type":"string"},"encrypted":{"type":"boolean"},"publicly_accessible":{"type":"boolean"},"open_to_the_world":{"type":"boolean"},"multi_az":{"type":"boolean"},"deletion_protection":{"type":"boolean"},"iam_authentication_enabled":{"type":"boolean"},"backup_retention_period":{"type":"integer"},"database_count":{"type":"integer"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsDatabase object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsDatabase":{"type":"object","properties":{"id":{"type":"integer"},"database_name":{"type":"string"},"schema_name":{"type":"string"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsTable object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsTable":{"type":"object","properties":{"id":{"type":"integer"},"table_name":{"type":"string"},"data_size":{"type":"integer"},"row_count":{"type":"integer"},"last_scanned":{"type":"string","format":"date-time"},"dsr_query":{"type":"string"},"column_count":{"type":"integer"},"access_enabled":{"type":"boolean"},"deletion_enabled":{"type":"boolean"},"dsr_enabled":{"type":"boolean"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsColumn object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsColumn":{"type":"object","properties":{"id":{"type":"string"},"column_name":{"type":"string"},"column_type":{"type":"string"},"identifier_id":{"type":"string"},"identifier_name":{"type":"string"},"access_enabled":{"type":"boolean"},"custom_access_label":{"type":"string"},"deletion_enabled":{"type":"boolean"},"deletion_algorithm":{"type":"string"},"no_data":{"type":"boolean"},"table_last_scanned":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"rds_table_id":{"type":"integer"},"rds_table_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsClustersResponse object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsClustersResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsCluster"}},"total_count":{"type":"integer"}}},"RdsCluster":{"type":"object","properties":{"id":{"type":"integer"},"region":{"type":"string"},"engine_type":{"type":"string"},"engine_version":{"type":"string"},"identifier":{"type":"string"},"write_endpoint":{"type":"string"},"read_endpoint":{"type":"string"},"encrypted":{"type":"boolean"},"publicly_accessible":{"type":"boolean"},"open_to_the_world":{"type":"boolean"},"multi_az":{"type":"boolean"},"deletion_protection":{"type":"boolean"},"iam_authentication_enabled":{"type":"boolean"},"backup_retention_period":{"type":"integer"},"database_count":{"type":"integer"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsDatabasesResponse object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsDatabasesResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsDatabase"}},"total_count":{"type":"integer"}}},"RdsDatabase":{"type":"object","properties":{"id":{"type":"integer"},"database_name":{"type":"string"},"schema_name":{"type":"string"},"table_count":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsTablesResponse object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsTablesResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsTable"}},"total_count":{"type":"integer"}}},"RdsTable":{"type":"object","properties":{"id":{"type":"integer"},"table_name":{"type":"string"},"data_size":{"type":"integer"},"row_count":{"type":"integer"},"last_scanned":{"type":"string","format":"date-time"},"dsr_query":{"type":"string"},"column_count":{"type":"integer"},"access_enabled":{"type":"boolean"},"deletion_enabled":{"type":"boolean"},"dsr_enabled":{"type":"boolean"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```

## The RdsColumnsResponse object

```json
{"openapi":"3.0.3","info":{"title":"RDS Metadata API","version":"1.0.0"},"components":{"schemas":{"RdsColumnsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/RdsColumn"}},"total_count":{"type":"integer"}}},"RdsColumn":{"type":"object","properties":{"id":{"type":"string"},"column_name":{"type":"string"},"column_type":{"type":"string"},"identifier_id":{"type":"string"},"identifier_name":{"type":"string"},"access_enabled":{"type":"boolean"},"custom_access_label":{"type":"string"},"deletion_enabled":{"type":"boolean"},"deletion_algorithm":{"type":"string"},"no_data":{"type":"boolean"},"table_last_scanned":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"aws_account_name":{"type":"string"},"rds_cluster_id":{"type":"integer"},"rds_cluster_identifier":{"type":"string"},"rds_database_id":{"type":"integer"},"rds_database_name":{"type":"string"},"rds_schema_name":{"type":"string"},"rds_table_id":{"type":"integer"},"rds_table_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"data_element_categories":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"$ref":"#/components/schemas/Persona"}}}},"Persona":{"type":"object","properties":{"name":{"type":"string"}}}}}}
```


# S3


# AWS S3 API

## GET /aws/s3/buckets

> Get S3 buckets

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"S3BucketsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/S3Bucket"}},"total_count":{"type":"integer"}}},"S3Bucket":{"type":"object","properties":{"id":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"bucket_name":{"type":"string"},"region":{"type":"string"},"versioning":{"type":"boolean"},"server_side_encryption":{"type":"boolean"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/aws/s3/buckets":{"get":{"summary":"Get S3 buckets","operationId":"getS3Buckets","parameters":[{"in":"query","name":"s3_bucket_ids","schema":{"type":"string"}},{"in":"query","name":"s3_bucket_names","schema":{"type":"string"}},{"in":"query","name":"aws_account_ids","schema":{"type":"string"}},{"in":"query","name":"data_elements","schema":{"type":"string"}},{"in":"query","name":"data_categories","schema":{"type":"string"}},{"in":"query","name":"last_accessed","schema":{"type":"string"}},{"in":"query","name":"last_modified","schema":{"type":"string"}},{"in":"query","name":"created_at","schema":{"type":"string"}},{"in":"query","name":"limit","schema":{"type":"integer"}},{"in":"query","name":"offset","schema":{"type":"integer"}}],"responses":{"200":{"description":"List of S3 buckets","content":{"application/json":{"schema":{"$ref":"#/components/schemas/S3BucketsResponse"}}}}}}}}}
```

## GET /aws/s3/buckets/{id}

> Get S3 bucket by ID

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"S3Bucket":{"type":"object","properties":{"id":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"bucket_name":{"type":"string"},"region":{"type":"string"},"versioning":{"type":"boolean"},"server_side_encryption":{"type":"boolean"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/aws/s3/buckets/{id}":{"get":{"summary":"Get S3 bucket by ID","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"integer"}}],"responses":{"200":{"description":"S3 bucket object","content":{"application/json":{"schema":{"$ref":"#/components/schemas/S3Bucket"}}}}}}}}}
```

## GET /aws/s3/objects

> Get S3 objects

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"S3ObjectsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/S3Object"}}}},"S3Object":{"type":"object","properties":{"id":{"type":"integer"},"key":{"type":"string"},"size":{"type":"integer"},"mime_type":{"type":"string"},"file_type":{"type":"string"},"storage_class":{"type":"string"},"last_modified":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"s3_bucket_id":{"type":"integer"},"s3_bucket_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/aws/s3/objects":{"get":{"summary":"Get S3 objects","operationId":"getS3Objects","parameters":[{"in":"query","name":"s3_object_ids","schema":{"type":"string"}},{"in":"query","name":"s3_object_keys","schema":{"type":"string"}},{"in":"query","name":"s3_bucket_ids","schema":{"type":"string"}},{"in":"query","name":"s3_bucket_names","schema":{"type":"string"}},{"in":"query","name":"aws_account_ids","schema":{"type":"string"}},{"in":"query","name":"data_elements","schema":{"type":"string"}},{"in":"query","name":"data_categories","schema":{"type":"string"}},{"in":"query","name":"data_subject","schema":{"type":"string"}},{"in":"query","name":"last_accessed","schema":{"type":"string"}},{"in":"query","name":"last_modified","schema":{"type":"string"}},{"in":"query","name":"created_at","schema":{"type":"string"}},{"in":"query","name":"limit","schema":{"type":"integer"}},{"in":"query","name":"offset","schema":{"type":"integer"}}],"responses":{"200":{"description":"List of S3 objects","content":{"application/json":{"schema":{"$ref":"#/components/schemas/S3ObjectsResponse"}}}}}}}}}
```

## GET /aws/s3/objects/{id}

> Get S3 object by ID

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"servers":[{"url":"https://api.metadata.demo-001.teleskope.ai/v1"}],"security":[{"ApiKeyAuth":[]}],"components":{"securitySchemes":{"ApiKeyAuth":{"type":"apiKey","in":"header","name":"X-API-Key"}},"schemas":{"S3Object":{"type":"object","properties":{"id":{"type":"integer"},"key":{"type":"string"},"size":{"type":"integer"},"mime_type":{"type":"string"},"file_type":{"type":"string"},"storage_class":{"type":"string"},"last_modified":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"s3_bucket_id":{"type":"integer"},"s3_bucket_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}},"paths":{"/aws/s3/objects/{id}":{"get":{"summary":"Get S3 object by ID","parameters":[{"name":"id","in":"path","required":true,"schema":{"type":"integer"}}],"responses":{"200":{"description":"S3 object","content":{"application/json":{"schema":{"$ref":"#/components/schemas/S3Object"}}}}}}}}}
```


# Models

## The S3Bucket object

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"components":{"schemas":{"S3Bucket":{"type":"object","properties":{"id":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"bucket_name":{"type":"string"},"region":{"type":"string"},"versioning":{"type":"boolean"},"server_side_encryption":{"type":"boolean"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}}}
```

## The S3Object object

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"components":{"schemas":{"S3Object":{"type":"object","properties":{"id":{"type":"integer"},"key":{"type":"string"},"size":{"type":"integer"},"mime_type":{"type":"string"},"file_type":{"type":"string"},"storage_class":{"type":"string"},"last_modified":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"s3_bucket_id":{"type":"integer"},"s3_bucket_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}}}
```

## The S3BucketsResponse object

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"components":{"schemas":{"S3BucketsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/S3Bucket"}},"total_count":{"type":"integer"}}},"S3Bucket":{"type":"object","properties":{"id":{"type":"integer"},"aws_account_id":{"type":"integer"},"aws_account_identifier":{"type":"string"},"bucket_name":{"type":"string"},"region":{"type":"string"},"versioning":{"type":"boolean"},"server_side_encryption":{"type":"boolean"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}}}
```

## The S3ObjectsResponse object

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"components":{"schemas":{"S3ObjectsResponse":{"type":"object","properties":{"data":{"type":"array","items":{"$ref":"#/components/schemas/S3Object"}}}},"S3Object":{"type":"object","properties":{"id":{"type":"integer"},"key":{"type":"string"},"size":{"type":"integer"},"mime_type":{"type":"string"},"file_type":{"type":"string"},"storage_class":{"type":"string"},"last_modified":{"type":"string","format":"date-time"},"aws_account_id":{"type":"integer"},"s3_bucket_id":{"type":"integer"},"s3_bucket_name":{"type":"string"},"data_elements":{"type":"array","items":{"type":"string"}},"personas":{"type":"array","items":{"type":"string"}}}}}}}
```

## The S3ObjectCountResponse object

```json
{"openapi":"3.0.3","info":{"title":"AWS S3 API","version":"1.0.0"},"components":{"schemas":{"S3ObjectCountResponse":{"type":"object","properties":{"data":{"type":"integer"}}}}}}
```


# Redshift

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/aws/redshift" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# DynamoDB

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/aws/dynamo" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Users

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/aws/users" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# GCP

Teleskope's Metadata API surfaces classification records for your connected GCP data stores.

Available endpoints:

* **Cloud SQL** - Retrieve classification metadata for Cloud SQL instances, databases, tables, and columns
* **BigQuery** - Retrieve classification metadata for BigQuery datasets and tables
* **Cloud Storage** - Retrieve classification metadata for Cloud Storage buckets and objects
* **Users** - Retrieve user permissions and access records for GCP resources


# Cloud SQL

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/gcp/cloud-sql" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# BigQuery

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/gcp/big-query" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Cloud Storage

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/gcp/cloud-storage" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Users

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/gcp/users" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Azure

Teleskope's Metadata API surfaces classification records for your connected Azure data stores.

Available endpoints:

* **SQL** - Retrieve classification metadata for Azure SQL databases and tables
* **Blob Storage** - Retrieve classification metadata for Azure Blob Storage accounts, containers, and blobs


# SQL

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/azure/sql" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Blob Storage

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/azure/storage" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Snowflake

Teleskope's Metadata API surfaces classification records for your connected Snowflake accounts.

Available endpoints:

* **Snowflake** - Retrieve classification metadata across your Snowflake accounts, databases, schemas, and tables
* **Users** - Retrieve user permissions and access records for Snowflake resources


# Snowflake Metadata

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/snowflake" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Users

{% openapi src="/files/1WU8nBmktgOxfVM1PzuK" path="/v1/snowflake/users" method="get" %}
[{"openapi":"3.1.json](https://2383928706-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FgO8NOoWqwRd6MduHoEy7%2Fuploads%2FW41zmclymhqYbWzijIL7%2F%7B%22openapi%22%3A%223.1.json?alt=media\&token=8fbbb685-a910-41f0-b149-f505bb18cc7e)
{% endopenapi %}


# Policy Maker API


# /v1/policy-maker/policies/?/add-email

## Add an email to a policy that targets individual users

<mark style="color:green;">`POST`</mark> `/v1/policy-maker/policies/?/add-email`

Targeting a policy ID as a query parameter, this API adds an email to a policy with the `select emails` trigger condition. Policy IDs may be retrieved from the URL for a given policy.

**Headers**

| Name      | Value     |
| --------- | --------- |
| x-api-key | `<token>` |

**Body**

| Name    | Type   | Description                                 |
| ------- | ------ | ------------------------------------------- |
| `email` | string | The e-mail to add to the trigger condition. |

**Response**

{% tabs %}
{% tab title="200" %}

```
OK
```

{% endtab %}

{% tab title="500" %}

```
unexpected condition structure or lacking revoke access condition
```

{% endtab %}
{% endtabs %}


# Deployment

Teleskope offers fast, secure, and flexible deployment models tailored to meet your operational, compliance, and security needs. Choose between our **SaaS**, **Self-Hosted (Teleskope-Managed or Self-Managed)**, and **On-Premise** models based on your cloud, DevOps, and data locality requirements.

{% hint style="info" %}
**First sign-in uses a guided onboarding flow.** However you deploy, your first administrator finishes setup in the browser — naming the workspace, choosing an identity provider (or verifying by email), selecting connectors, and inviting teammates. To start, Teleskope just needs the email address of your first admin (your "onboarding user"); that person receives a one-time setup link to begin.
{% endhint %}

***

## Single-Tenant SaaS

#### Hosted & Operated entirely by Teleskope in an isolated AWS account.

* Fully managed by Teleskope with zero infra overhead
* Each customer gets a dedicated AWS instance and account
* Rapid onboarding with minimal DevOps involvement
* All upgrades, monitoring, and scaling handled by Teleskope
* Ideal for teams that want a hands-off, turnkey deployment

## Self-Hosted

#### Deploy into your own AWS, GCP, or Azure environment for greater control.

#### *Teleskope-Managed*

* Hosted in your isolated cloud environment (AWS, GCP, Azure)
* Fully managed by Teleskope (scaling, upgrades, monitoring)
* Ideal for cloud tenancy compliance needs
* No operational overhead for your internal teams

#### *Self-Managed*

* Fully operated and maintained by your internal DevOps/SRE teams
* Teleskope provides Helm charts, artifacts, and deployment docs
* Supports isolated environments and air-gapped deployments
* Full control over data, security, and deployment timelines

### On-Premise

**Run Teleskope within your internal datacenter** to scan **on-premise SQL databases** and **file shares** without exfiltration costs back to the cloud.

***

If your needs are not met by either model, reach out to your Teleskope rep, or email us at <contact@teleskope.ai>.


# Outpost

An Outpost is a worker-only Teleskope deployment that runs inside your network and scans data sources your Teleskope environment cannot reach directly, such as on-premise SQL databases and SMB file shares. This page covers what runs where, host and network requirements, and how to install and update the Outpost bundle.

## How It Works

The Outpost runs Teleskope's crawler and scanner workers on a single VM you provide, on k3s (a lightweight Kubernetes distribution) installed by the bundle. It connects outbound to your Teleskope environment to receive work and report results.

* File contents never leave your network. Workers read and classify data locally; only classification results and metadata are sent to your Teleskope environment.
* All connections are outbound from the Outpost. Teleskope requires no inbound access to your network.
* Container images ship inside the install bundle. The VM needs no access to a container registry.

## Prerequisites

* A dedicated VM running Ubuntu 22.04 LTS with root access
* 4 vCPU and 16 GB RAM minimum (32 GB recommended), 100 GB disk
* Outbound network access per the table below
* An install bundle URL from your Teleskope team (a time-limited download link)

## Network Requirements

All connections are outbound. No inbound rules are required.

| Destination                             | Port          | Purpose                                             |
| --------------------------------------- | ------------- | --------------------------------------------------- |
| `api.metadata.<your-env>.teleskope.ai`  | 443           | Work coordination and result reporting              |
| `sqs.<region>.amazonaws.com`            | 443           | Job queueing                                        |
| `secretsmanager.<region>.amazonaws.com` | 443           | Connector credential retrieval                      |
| Bundle download URL host                | 443           | One-time bundle download                            |
| `processing.<your-env>.teleskope.ai`    | 6380          | ML classification, when enabled for your deployment |
| Your file servers                       | 445           | SMB file share scanning                             |
| Your database servers                   | Database port | On-premise SQL scanning                             |

Your Teleskope team confirms the exact hostnames, region, and ports for your deployment before install.

{% hint style="warning" %}
**Warning:** The installer downloads public packages over HTTPS while it runs, so general outbound access on port 443 must be open during installation. After install completes, egress can be restricted to the destinations above.
{% endhint %}

## Install

1. Download the bundle. Single-quote the URL — it contains `&` characters that break the shell otherwise:

   ```bash
   curl -o teleskope-k3s.tar '<bundle-url>'
   ```
2. Extract the bundle:

   ```bash
   tar xf teleskope-k3s.tar && cd teleskope-k3s
   ```
3. Run the installer with the flags your Teleskope team provides:

   ```bash
   sudo ./install-k3s.sh --no-gpu
   ```

   The installer sets up k3s, imports the bundled container images, and starts the Teleskope workers.
4. Verify the node and workers are up:

   ```bash
   systemctl status k3s
   sudo k3s kubectl get pods -n teleskope
   ```

   All pods reach `Running` within a few minutes.

## Update

Teleskope provides a new bundle URL for each update. On the Outpost VM:

```bash
sudo ./update.sh '<new-bundle-url>'
```

Updates replace container images and configuration. Scan state and connector credentials live in your Teleskope environment and are unaffected.

## Troubleshooting

| Symptom                                         | Cause and fix                                                                                    |
| ----------------------------------------------- | ------------------------------------------------------------------------------------------------ |
| k3s node not `Ready`                            | Check `systemctl status k3s` and `journalctl -u k3s -f`.                                         |
| `x509: certificate signed by unknown authority` | Install CA certificates: `sudo apt-get install -y ca-certificates`.                              |
| `dial tcp ...:445: i/o timeout` in worker logs  | The VM cannot reach the file server. Check firewall rules between the Outpost VM and the target. |
| Pods stuck in `CrashLoopBackOff`                | Usually a bundle configuration issue. Contact your Teleskope team.                               |

For anything else, reach out to your Teleskope rep or email <contact@teleskope.ai>.


# Role Based Access Control

## What is RBAC?

RBAC or **R**ole **B**ased **A**ccess **C**ontrol is a mechanism you can use as an admin to limit the access of your users in Teleskope.

RBAC is based on the following principles:

* Each role grants access to a collection of features and connectors
* Each user can be assigned one or more roles
* A user's permissions in the Teleskope app are the aggregate of all permissions granted by their roles

## Configuring RBAC as an admin

By default, admins are granted full access to your Teleskope instance, able to view and interact with every feature and connector. Admins are also the only users who can create/update/delete roles, and assign/un-assign roles from users.

Admins can navigate to the RBAC page by selecting the `Users and Roles` option under `Settings` on the sidebar in the Teleskope app. Then they can:

* Create/edit/delete roles in the `Roles` tab
* Assign/unassign roles for each user in the `Users` tab
* View a user's aggregate permissions to see what their roles have collectively granted them so far

## The 3 pre-existing RBAC roles

There are 3 starting roles that come by-default in your Teleskope instance, and each is unique:

* The `admin` role, which is immutable and gives full access to the Teleskope app while also unlocking admin features like configuring RBAC or inviting new users.
* The `default` role which all users have, and holds any permissions admins would like *all* users to have no matter what. This `default` role is given full permissions to start with, so it is up to admins to *opt in* to RBAC by downgrading any of these default role permissions. While the `default` role has S3 access, so do all users, etc.
* The `teleskope-support` role which is a special case, only assigned to Teleskope employees who have been given access to your instance for support or maintenance purposes.

### The 3 corresponding user types

These roles also determine what **User Type** a user is in the app. Users with the `admin` role are considered an **Admin** type user, users with the `teleskope-support` role are considered a **Teleskope Support** type user, and everyone else is just a regular **Standard** user.

## RBAC use case suggestions

It's ultimately up to the admin to use RBAC as they see fit and design their own rules. However, there are a few common themes and strategies Admins may want to employ with RBAC:

* Want to limit particularly sensitive data or features to only select users?
  * Limit access to these in a role, and only assign that role to select users.
* Onboarding a new employee to a specific team?
  * That user can be assigned a role for that team that includes all the permissions they may need.
* Off-boarding an employee from a team, but still keeping them at the company?
  * If that team had a custom role with their needed permissions, unassign that role from the off-boarded user.
* Want all new users to start with some level of basic permissions?
  * Add these permissions to the `default` role to automatically give new users this access.
* Don't care about restricting access at all?
  * You can give the `default` role full permissions, so any non-admin user can also see everything by default.


# Teleskope Helm Charts

Once you have provided Teleskope with your AWS ID, you will have the permissions to pull the helm chart you need.

## Usage

### teleskope-self-hosted

This helm chart configuration is for deploying Teleskope in your kubernetes cluster.

```
# Default values for teleskope-fullstack.
# This is a YAML-formatted file.
# Declare variables to be passed into your templates.

awsAccountID: <your_aws_account_id>

crawler:
  enable: true
  servicePort: 80
  configmapData:

crawlerDispatcher:
  enable: true
  servicePort: 80
  configmapData:

mlClassifier:
  enable: true
  servicePort: 80
  configmapData:
    tokenizer_count: 2
    api_count: 1
    collection_count: 1
    sbd_count: 2

scanner:
  enable: true
  servicePort: 80
  configmapData:

scannerDispatcher:
  enable: true
  servicePort: 80
  configmapData:
```


# SSO

Teleskope currently supports:

* [Okta](/setup/sso/implementing-okta-for-sso-in-teleskope)
* [Microsoft Entra](/setup/sso/microsoft-entra)
* [Google Auth](/setup/sso/google-auth).

{% hint style="info" %}
For a new deployment, you choose and configure your identity provider as part of the guided onboarding flow. The pages below are the per-provider reference details.
{% endhint %}

If your primary IDP or SSO provider is not included in this list, please reach out to your Teleskope representative.


# Implementing Okta for SSO in Teleskope

## Setup

Before you can implement authorization, you need to register the Teleskope application in Okta by creating an app integration from the **Admin Console**.

1. Open the **Admin Console** for your org.
2. Choose **Applications** to view the current app integrations.
3. Click **Create App Integration**.
4. Select **OIDC - OpenID Connect** as the **Sign-in method**.
5. Select **Web Application** as the **Application type**, then click Next.
6. Enter **Teleskope** for the **App integration name**.
7. In the **Sign-in redirect URIs** box, enter the callback location where Okta returns the browser. Example: **<https://api.mission-control.\\><DOMAIN>/auth/okta/callback**.
   1. **\<DOMAIN>** is typically **CompanyName.teleskope.ai**
   2. Optionally:
      1. Set the **Sign-out redirect URIs** to your Teleskope Dashboard URI.\
         Example: **<https://observatory.\\><DOMAIN>**
      2. Change **Login initiated by** to "Either App or Okta" and check **Display application icon to users** to populate an Okta tile
      3. Set **Initiate login URI** to **<https://api.mission-control.\\><DOMAIN>/login?authType=okta**
8. Fill in the remaining details for your app integration, then click Save.
   1. To brand the Okta tile, download the Teleskope app icon and upload it as the **Application logo**:

{% file src="/files/stZOEuMboR0ShAx1vf6x" %}

9. From the **General tab** of your app integration, gather **Client ID** and **Client secret**&#x20;
10. Click on your email in the top right of the UI, and copy **Issuer** value. 1. The Issuer is typically **CompanyName.okta.com/oauth2**
11. Provide these credentials to your Teleskope Representative

## Provisioning

Teleskope supports JIT provisioning by default, so be cognizant of what users and groups are assigned to the Teleskope-Okta App.


# Microsoft Entra

To rely on Entra for SSO, you need to register an application in your tenant and provide Teleskope a **Client Id**, **Client Secret,** and your **Tenant ID.**

## Setup

1. Navigate to <https://entra.microsoft.com/> and sign into your enterprise's Microsoft dashboard
2. Select **Overview** from the sidebar.
   1. Collect your **Tenant** **ID:** `xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx`
3. On your side bar, select **Applications,** then **App registrations**
4. Select **New registration**, and name your Teleskope SSO app.
   1. There will be a few authentication options, we recommend `Accounts in this organizational directory only (Single tenant)` as the simplest option
5. On your side bar, select **Applications,** **App registrations,** then select your newly created app.
   1. Collect your `Application (client) ID`
6. In your app's registration page, under **Certificates & Secrets**, select **New client secret.** Set a name and expiry
   1. Collect the resulting value as your `client_secret` .
7. In your app's registration page, select **API Permissions** and click **Add a Permission**.
   1. Set up `delegated` permissions for Microsoft Graph, `admin consent` not required. You will need the `email`, `openid` and `profile` permissions set.
   2. **Note:** if your tenant disables user consent for apps, you will need to grant `admin consent`.
8. In your app's registration page, select **Authentication,** **+ Add a Platform, Web,** then enter your Redirect URI:
   1. Example: **<https://api.mission-control.\\><DOMAIN>/auth/microsoft/callback**
   2. **\<DOMAIN>** is typically **CompanyName.teleskope.ai**

## Provisioning

1. Assign users to your new Teleskope Entra app.
2. A first/last name in Entra is required for any user logging into Teleskope.


# Google Auth

Google Auth is supported by default for all net-new Teleskope tenants.


# Data Store Coverage

### Data Stores

| Cloud/Third Party      | Data Store      |
| ---------------------- | --------------- |
| AWS                    | S3              |
| AWS                    | RDS             |
| AWS                    | Dynamo DB       |
| AWS                    | Redshift        |
| AWS                    | SQS             |
| AWS                    | OpenSearch      |
| AWS                    | EC2             |
| AWS                    | Cassandra       |
| AWS                    | EFS             |
| AWS                    | Athena          |
| GCP                    | CloudSQL        |
| GCP                    | Cloud Storage   |
| GCP                    | BigQuery        |
| Azure                  | Blob            |
| Azure                  | SQL             |
| Azure                  | CosmosDB        |
| Azure                  | Files           |
| Snowflake              | Snowflake       |
| Box                    | Box             |
| Google Workspace       | Google Docs     |
| Google Workspace       | Google Sheets   |
| Google Workspace       | Google Slides   |
| Google Workspace       | Google Drive    |
| Zendesk                | Zendesk         |
| Atlassian              | Jira            |
| Atlassian              | Confluence      |
| Salesforce             | Salesforce      |
| Github                 | Github          |
| Slack                  | Slack           |
| Databricks             | Databricks      |
| Microsoft              | Microsoft Teams |
| Microsoft              | Sharepoint      |
| Microsoft              | OneDrive        |
| Microsoft              | Exchange Online |
| On-Premise SQL         | MySQL           |
| On-Premise SQL         | Postgres        |
| On-Premise SQL         | MsSQL           |
| On-Premise File Shares | Net Apps        |
| On-Premise File Shares | SMB             |
| OpenAI                 | OpenAI          |

### Coming Soon

| Cloud/Third Party | Data Store    |
| ----------------- | ------------- |
| AWS               | SNS           |
| AWS               | Elasticache   |
| AWS               | Kinesis       |
| AWS               | EBS           |
| GCP               | Cloud Logging |
| GCP               | PubSub        |
| GCP               | MemoryStore   |
| GCP               | DataFlow      |
| Azure             | DataLake      |
| Azure             | Cache         |
| Azure             | TableStorage  |
| Azure             | EventHub      |
| Dropbox           | Dropbox       |
| Atlassian         | Bitbucket     |
| Microsoft         | PowerBI       |
| Workday           | Workday       |
| Grafana           | Loki          |
| Sentry            | Sentry        |
| DataDog           | DataDog       |
| Honeycomb         | Honeycomb     |

### File Formats

<table><thead><tr><th>Type</th><th>Format</th><th width="250">Parsed As</th></tr></thead><tbody><tr><td>Columnar</td><td>parquet</td><td>Columnar</td></tr><tr><td>Columnar</td><td>avro</td><td>Columnar</td></tr><tr><td>Columnar</td><td>orc</td><td>Columnar</td></tr><tr><td>Columnar</td><td>thrift</td><td>Columna</td></tr><tr><td>Columnar</td><td>csv</td><td>Columnar</td></tr><tr><td>Columnar</td><td>tsv</td><td>Columnar</td></tr><tr><td>Columnar</td><td>xls</td><td>Columnar</td></tr><tr><td>Document</td><td>pdf</td><td>Text/Image</td></tr><tr><td>Text</td><td>txt</td><td>Text</td></tr><tr><td>Text</td><td>doc</td><td>Text</td></tr><tr><td>Text</td><td>docx</td><td>Text</td></tr><tr><td>Text</td><td>log</td><td>Text</td></tr><tr><td>Compressed</td><td>gzip</td><td></td></tr><tr><td>Compressed</td><td>gz</td><td></td></tr><tr><td>Compressed</td><td>tar</td><td></td></tr><tr><td>Compressed</td><td>zip</td><td></td></tr><tr><td>Image</td><td>png</td><td>Text</td></tr><tr><td>Image</td><td>jpeg</td><td>Text</td></tr><tr><td>Image</td><td>bnp</td><td>Text</td></tr><tr><td>Image</td><td>pnm</td><td>Text</td></tr><tr><td>Image</td><td>jfif</td><td>Text</td></tr><tr><td>Image</td><td>tiff</td><td>Text</td></tr><tr><td>Audio</td><td>wave</td><td></td></tr><tr><td>Audio</td><td>x-wave</td><td></td></tr><tr><td>Audio</td><td>mp3</td><td></td></tr><tr><td>Audio</td><td>mp4</td><td></td></tr><tr><td>Object</td><td>xml</td><td>Text</td></tr><tr><td>Object</td><td>html</td><td>Text</td></tr><tr><td>Object</td><td>yml</td><td>Text</td></tr><tr><td>Object</td><td>json</td><td>Text</td></tr><tr><td>Code</td><td>js</td><td>Text</td></tr><tr><td>Code</td><td>java</td><td>Text</td></tr><tr><td>Code</td><td>go</td><td>Text</td></tr><tr><td>Code</td><td>ruby</td><td>Text</td></tr></tbody></table>


# Compliance Frameworks

Teleskope offers out of the box Issues and actions for the following regulatory and compliance frameworks:

* AWS FSBP
* CIS v1.2.0
* CIS v1.4.0
* NIST 800-53
* PCI DSS
* ISO 27001
* HIPAA
* GDPR
* E-privacy Regulation
* UK GDPR
* California CPRA
* Taiwan PDPA
* Virginia CDPA
* Canada CCPA
* New Zealand Privacy Act
* Brazil LGPD
* Singapore PDPA
* German TTDSG
* Thailand PDPA
* China PIPL
* Switzerland NFADP
* India IT Act and SPDIA
* Mexico IT Act
* SOC 2 Standard
* CIS 1.0
* CIS 1.1
* CIS 1.2
* CIS 1.3


# Redaction Methodologies

Every detected element can be replaced by one of six styles. Select one with the `redactionStyle` query parameter on [v1/scrub](/the-platform/api-service/redaction-api/v1-scrub).

| `redactionStyle` | Replaces the value with                                                               |
| ---------------- | ------------------------------------------------------------------------------------- |
| `CLASS`          | The element label in angle brackets. The default.                                     |
| `CLASS_NUMBERED` | The element label plus an occurrence number, stable across repeats of the same value. |
| `EMPTY`          | An empty string.                                                                      |
| `MASKED`         | Asterisks, preserving a short leading prefix.                                         |
| `ENCRYPTED`      | Reversible AES-SIV ciphertext, deterministic for a given key.                         |
| `TOKENIZED`      | A format-preserving surrogate of the same shape as the original.                      |

{% hint style="warning" %}
An unrecognised `redactionStyle` is ignored rather than rejected. A misspelled value returns `200` with `CLASS` output. If a style appears not to apply, check the spelling first.
{% endhint %}

## Examples

All examples below use the same input:

```
Contact Ana Torres at ana@example.com or +1-415-555-0199
```

| Style            | Output                                                                                                               |
| ---------------- | -------------------------------------------------------------------------------------------------------------------- |
| `CLASS`          | `Contact <GIVEN> <FAMILY> at <EMAIL> or <PHONE>`                                                                     |
| `CLASS_NUMBERED` | `Contact <given_1> <family_1> at <email_1> or <phone_1>`                                                             |
| `EMPTY`          | `Contact at or`                                                                                                      |
| `MASKED`         | `Contact A** To**** at an************* or +1*************`                                                           |
| `ENCRYPTED`      | `Contact <GIVEN(3):9ec716841ed1…> <FAMILY(6):662205980d01…> at <EMAIL(15):cb7901d656e3…> or <PHONE(15):e2efe94111…>` |
| `TOKENIZED`      | `Contact <GIVEN> <FAMILY> at <EMAIL> or +1-415-256-9091`                                                             |

Ciphertext is truncated above for readability; real output carries the full hex string.

Element labels come from the [Entity Taxonomy](/specifications/data-elements/entity-taxonomy-v2). `CLASS` upper-cases them, `CLASS_NUMBERED` does not.

## CLASS and CLASS\_NUMBERED

`CLASS` writes `<LABEL>` for every match, so two different email addresses become two identical `<EMAIL>` tokens.

`CLASS_NUMBERED` appends an occurrence number and reuses it for repeated values, which preserves the structure of the data without revealing it:

```
Write to ana@example.com, then ana@example.com, then bo@example.com
->
Write to <email_1>, then <email_1>, then <email_2>
```

Numbering is scoped to a single response. The same address in a later request is not guaranteed the same number. For a value that stays stable across requests, use `ENCRYPTED` or `TOKENIZED`.

## EMPTY

Removes the value entirely. Surrounding characters, including the spaces on either side of the removed value, are left in place, so output can contain runs of whitespace.

## MASKED

Replaces each character with `*`, preserving a leading prefix that depends on the length of the value:

| Value length | Characters preserved |
| ------------ | -------------------- |
| 1–2          | none                 |
| 3            | first character      |
| 4 or more    | first two characters |

Length is always preserved, so a masked value still discloses how long the original was.

## ENCRYPTED

Encrypts the value with AES-SIV and emits `<LABEL(length):ciphertext>`, where `length` is the byte length of the original and `ciphertext` is hex-encoded.

```
ana@example.com  ->  <EMAIL(15):cb7901d656e33a4682eace4480bd50d72d47efa150cd8585b9d90af95db3f2>
```

Encryption is deterministic: the same input under the same key always produces the same ciphertext, which supports joins and deduplication on redacted data. It is also reversible, so treat the output as sensitive and the key as the control that makes it safe.

{% hint style="danger" %}
**Always pass your own `key`.** The `key` query parameter is not enforced, and omitting it does not fail. The service falls back to a key generated randomly when the process starts, which is never stored anywhere. Output encrypted that way cannot be decrypted by anyone, including us, and stops being reproducible as soon as the service restarts. Treat a response produced without `key` as discarded data, not as recoverable ciphertext.
{% endhint %}

Supply the key as a `key` query parameter of 32, 48, or 64 bytes, selecting AES-128, AES-192, or AES-256 respectively. Use the same key on every request whose outputs need to match.

{% hint style="warning" %}
A key of any other length returns `500`, not `400`, with a message of the form `incorrect size of key 8`.
{% endhint %}

## TOKENIZED

Replaces the value with a surrogate of the same shape: a phone number becomes a different valid phone number, an email a different well-formed email. Downstream systems that validate format continue to work on redacted data. Tokenization is deterministic for a given key, so a value maps to the same surrogate every time.

Format preservation applies to these labels only:

| Label   | v1 label       |
| ------- | -------------- |
| `email` | `EMAIL`        |
| `phone` | `PHONE_NUMBER` |
| `ip`    | `IPV4`, `IPV6` |
| `mac`   | `MAC_ADDRESS`  |

Every other element falls back to `CLASS` output. That is why `Ana Torres` appears as `<GIVEN> <FAMILY>` in the example above while the phone number is tokenized. `TOKENIZED` is not a drop-in replacement for `ENCRYPTED` when every element needs to round-trip.

Very short values cannot be tokenized either: format-preserving encryption requires a minimum input length for the character set in use, and values below it fall back to `CLASS` output.

`TOKENIZED` requires a tokenization key on the deployment. Without one, requests using this style return an error rather than unredacted content.

## Choosing a style

* Discarding the data: `EMPTY` or `CLASS`.
* Keeping shape for human review: `MASKED`.
* Counting or correlating distinct values in one payload: `CLASS_NUMBERED`.
* Joining or deduplicating across payloads, or recovering originals later: `ENCRYPTED` with your own `key`.
* Feeding redacted data to systems that validate format: `TOKENIZED`.

## Related

* [v1/scrub](/the-platform/api-service/redaction-api/v1-scrub) — the endpoint that applies these styles.
* [v1/classify](/the-platform/api-service/scanning-api/v1-classify) — detect without redacting.
* [Entity Taxonomy](/specifications/data-elements/entity-taxonomy-v2) — the element labels used in output.


# Data Elements

Elements supported by the Teleskope Engine form the taxonomy described below. The representation follows an element name and parent element link.

For environments using the newer hierarchical taxonomy, see [Entity Taxonomy v2](/specifications/data-elements/entity-taxonomy-v2).

{% hint style="info" %}
Teleskope environments are being migrated to Entity Taxonomy v2 in phases. Some environments may continue to return the labels shown on this page until their migration is complete.
{% endhint %}

Different categories of elements are separated into tables and optional descriptions are provided for ambiguous element names.

### Personal Information

| Element Parent | Element Name        |
| -------------- | ------------------- |
| Personal       | First Name          |
| Personal       | Middle Name         |
| Personal       | Last Name           |
| Personal       | Full Name           |
| Personal       | Birthdate           |
| Personal       | Title               |
| Personal       | Age                 |
| Personal       | Address             |
| Address        | Street              |
| Address        | Zipcode/Postal Code |
| Address        | State               |
| Address        | City                |
| Address        | Country             |
| Personal       | Email               |
| Personal       | Phone Number        |
| Personal       | Employer / Company  |
| Personal       | Religion            |
| Personal       | Political Party     |
| Personal       | Ethnicity           |
| Personal       | Nationality         |
| Personal       | Height              |
| Personal       | Weight              |
| Personal       | Gender              |
| Personal       | Currency            |
| Personal       | Password            |
| Personal       | UserID              |
| Personal       | Latitude            |
| Personal       | Longitude           |

### Network Information

| Parent Element | Element Name |
| -------------- | ------------ |
| Network        | MAC Address  |
| Network        | IP Address   |
| Network        | Device ID    |
| Network        | URL          |

### Government Information

The government information below branches out into individual countries and subdivisions. For brevity, we have omitted this detail, but elements will be identified for international patterns.

| Parent Element | Element Name                  |
| -------------- | ----------------------------- |
| Government     | Passport Number               |
| Government     | Government ID Number          |
| Government     | Social Security Number        |
| Government     | Social Security Number Last 4 |
| Government     | Drivers License Number        |
| Government     | License Plate                 |
| Government     | Vehicle ID Number (VIN)       |
| Government     | Employer ID Number (EIN)      |
| Government     | Taxpayer ID Number (TIN)      |

### Payments Information (PCI)

| Parent Element | Element Name                |
| -------------- | --------------------------- |
| Payment        | Bank Account Number         |
| Payment        | IBAN                        |
| Payment        | Routing Number              |
| Payment        | SWIFT Code                  |
| Payment        | Credit Card Number          |
| Payment        | Credit Card Expiration Date |
| Payment        | Credit Card CVV             |
| Payment        | Credit Card Last 4          |

### Health Information (PHI)

Health information below varies country by country, region by region, and even within an organization. The localized health information is also supported but omitted for brevity.

| Parent Element | Element Name                          |
| -------------- | ------------------------------------- |
| Health         | Blood Type                            |
| Health         | Diagnosis Description                 |
| Health         | Diagnosis Code                        |
| Health         | Treatment                             |
| Health         | Medical Procedure                     |
| Health         | Health Insurance Member ID            |
| Health         | Health Insurance Plan Type/Name       |
| Health         | Medical Record Number                 |
| Health         | Medicare Beneficiary Identifier (MBI) |
| Health         | National Provider Identifier (NPI)    |
| Health         | Health Insurance Claim Number (HICN)  |
| Health         | Prescription Number (RX#)             |
| Health         | Marital Status                        |

### Secrets

| Parent Element | Element Name                    |
| -------------- | ------------------------------- |
| Secret         | API Key                         |
| Secret         | GCP Secret Key                  |
| Secret         | GCP Access Key                  |
| Secret         | AWS Secret Key                  |
| Secret         | AWS Access Key                  |
| Secret         | Salesforce Key ID               |
| Secret         | Salesforce Key Secret           |
| Secret         | Notion API Key                  |
| Secret         | Slack Bot Token                 |
| Secret         | Slack User Token                |
| Secret         | Slack App Token                 |
| Secret         | Paypal Client ID                |
| Secret         | Paypal Client Secret            |
| Secret         | Paypal Access Token             |
| Secret         | Stripe API Key                  |
| Secret         | DataDog API Key                 |
| Secret         | DataDog Client Token            |
| Secret         | Twilio API Key                  |
| Secret         | Github API Token                |
| Secret         | JIRA API Token                  |
| Secret         | Confluence API Token            |
| Secret         | Google Maps API Key             |
| Secret         | Twitter API Access Token        |
| Secret         | Twitter API Access Token Secret |
| Secret         | Zendesk API Token               |
| Secret         | MuleSoft Access Token           |
| Secret         | Tableau Personal Access Token   |
| Secret         | Apple Developer Token           |
| Secret         | New Relic API Key               |
| Secret         | Pager Duty API Token            |
| Secret         | Artifactory Access Token        |
| Secret         | Cloudflare API Token            |
| Secret         | Quip API Key                    |
| Secret         | Dyn API Key                     |
| Secret         | Alibaba Access Key Id           |
| Secret         | Alibaba Access Key Secret       |
| Secret         | One Login Client Id             |
| Secret         | One Login Client Secret         |
| Secret         | Duo Secret Key                  |
| Secret         | DocuSign Secret Key             |
| Secret         | Akamai Client Secret            |

### Cryptocurrency

| Parent Element | Element Name                         | Description       |
| -------------- | ------------------------------------ | ----------------- |
| Cryptocurrency | Signing Key                          |                   |
| Cryptocurrency | Wallet Address                       | Bitcoin, Ethereum |
| Cryptocurrency | BIP 39 Wordlist                      | 'Seed Phrase'     |
| Cryptocurrency | Wallet Balance                       |                   |
| Cryptocurrency | Transaction                          |                   |
| Cryptocurrency | Invoice                              |                   |
| Cryptocurrency | Cold Card Primary Pin                |                   |
| Cryptocurrency | Cold Card Secondary Pin              |                   |
| Cryptocurrency | Cold Card Full Pin                   |                   |
| Cryptocurrency | Bitcoin Brokerage Account Id         |                   |
| Cryptocurrency | Bitcoin Mining Pool Console API Keys |                   |
| Cryptocurrency | Bitcoin Mining Facility Info         |                   |


# Create a Custom Data Element

Custom data elements let you detect organization-specific identifiers and other sensitive values directly from the Teleskope UI.

## Create an element

1. Go to **Settings > Elements and Categories > Data elements**, then select **Create custom element**.
2. In **Details**:
   * Enter a display name. Teleskope generates the internal label and `custom.<label>` URI.
   * Select at least one data category and a sensitivity level.
3. In **Detection**:
   * Add one or more [RE2](https://github.com/google/re2/wiki/Syntax) regular expression patterns.
   * Leave **Requires context** on when a pattern should match only with a related keyword. Turn it off only when the pattern is specific enough to classify on its own.
   * Choose whether to scan all data types or structured data only.
   * **Avoid `^` and `$` anchors.** Scanned content usually contains surrounding text, so patterns anchored to the entire input rarely match. Use boundaries such as `\b` or explicit delimiters instead.
4. In **Context**, add keywords that typically appear near the value. Enable **Case-insensitive matching** if capitalization should not matter.
5. In **Test**, paste sample text and select **Preview classifications**. Review the highlighted matches, match count, and context status, then refine the patterns or keywords as needed.
6. Select **Create**, review the confirmation, and select **Confirm create**.

{% hint style="info" %}
If every pattern requires context, add at least one keyword. Those patterns will not classify without a matching keyword.
{% endhint %}

After you save, Teleskope reloads the scanner rules so the element can be used by subsequent scans.

## Example

To detect a four-digit employee badge number only when the word `badge` is nearby:

* **Display name:** `Employee Badge`
* **Pattern:** `\b\d{4}\b`
* **Requires context:** On
* **Keyword:** `badge`
* **Sample text:** `Employee badge 4821 was issued today.`

The preview highlights `4821` and confirms that the context keyword was found.


# Entity Taxonomy v2

Entity Taxonomy v2 organizes **65 entity labels** into **10 hierarchical families** using dot notation. For example, `PERSONAL.name.given` is the v2 label for a given name.

{% hint style="info" %}
Teleskope environments are being migrated to Entity Taxonomy v2 in phases. Some environments may continue to return v1 labels until their migration is complete.
{% endhint %}

## Label Structure

| Level | Description | Example               |
| ----- | ----------- | --------------------- |
| L1    | Family      | `PERSONAL`            |
| L2    | Category    | `PERSONAL.name`       |
| L3    | Subcategory | `PERSONAL.name.given` |

Different categories of elements are separated into tables and optional descriptions are provided for ambiguous element names.

### Personal Information

Core personal identifiers. `PERSONAL.dob` captures full and partial dates of birth.

| Parent Label       | Element Label             | Description                            |
| ------------------ | ------------------------- | -------------------------------------- |
| `PERSONAL`         | `PERSONAL.name`           | Full or unspecified person name        |
| `PERSONAL.name`    | `PERSONAL.name.given`     | Given or first name                    |
| `PERSONAL.name`    | `PERSONAL.name.family`    | Family or last name                    |
| `PERSONAL`         | `PERSONAL.email`          | Email address                          |
| `PERSONAL`         | `PERSONAL.phone`          | Phone number                           |
| `PERSONAL`         | `PERSONAL.dob`            | Date of birth, including partial dates |
| `PERSONAL`         | `PERSONAL.username`       | Username or handle                     |
| `PERSONAL`         | `PERSONAL.address`        | Full or unspecified address            |
| `PERSONAL.address` | `PERSONAL.address.street` | Street address                         |
| `PERSONAL.address` | `PERSONAL.address.unit`   | Apartment, suite, or unit              |
| `PERSONAL.address` | `PERSONAL.address.po_box` | Post office box                        |

### Protected Information

Protected class attributes relevant to Title VII and related regulations.

| Parent Label    | Element Label               | Description                                                      |
| --------------- | --------------------------- | ---------------------------------------------------------------- |
| `PROTECTED`     | `PROTECTED.race_ethnicity`  | Race or ethnicity                                                |
| `PROTECTED`     | `PROTECTED.religion`        | Religious affiliation                                            |
| `PROTECTED`     | `PROTECTED.sex`             | Sex-related attribute when a more specific label is not returned |
| `PROTECTED.sex` | `PROTECTED.sex.pregnancy`   | Pregnancy status                                                 |
| `PROTECTED.sex` | `PROTECTED.sex.orientation` | Sexual orientation                                               |
| `PROTECTED.sex` | `PROTECTED.sex.gender`      | Gender or gender identity                                        |
| `PROTECTED`     | `PROTECTED.national_origin` | National origin                                                  |
| `PROTECTED`     | `PROTECTED.age`             | Age                                                              |
| `PROTECTED`     | `PROTECTED.disability`      | Disability status                                                |
| `PROTECTED`     | `PROTECTED.genetic_info`    | Genetic information                                              |

### Government Information

Government-issued identifiers. Country-specific passport variants are consolidated into `GOVERNMENT.passport`.

| Parent Label | Element Label                | Description                                                      |
| ------------ | ---------------------------- | ---------------------------------------------------------------- |
| `GOVERNMENT` | `GOVERNMENT.ssn`             | Social Security Number, including partial SSNs                   |
| `GOVERNMENT` | `GOVERNMENT.ein`             | Employer Identification Number or Taxpayer Identification Number |
| `GOVERNMENT` | `GOVERNMENT.passport`        | Passport number                                                  |
| `GOVERNMENT` | `GOVERNMENT.drivers_license` | Driver's license number                                          |
| `GOVERNMENT` | `GOVERNMENT.license_plate`   | License plate number                                             |
| `GOVERNMENT` | `GOVERNMENT.national_id`     | National identity number                                         |
| `GOVERNMENT` | `GOVERNMENT.vin`             | Vehicle Identification Number                                    |

### Payments Information (PCI)

Payment card and banking identifiers. Partial card numbers share the same label as full card numbers; the classifier detects partial values contextually.

| Parent Label | Element Label              | Description                                        |
| ------------ | -------------------------- | -------------------------------------------------- |
| `FINANCIAL`  | `FINANCIAL.card_number`    | Credit card number, including partial card numbers |
| `FINANCIAL`  | `FINANCIAL.card_expiry`    | Credit card expiration date                        |
| `FINANCIAL`  | `FINANCIAL.cvv`            | Credit card CVV                                    |
| `FINANCIAL`  | `FINANCIAL.routing_number` | Routing number                                     |
| `FINANCIAL`  | `FINANCIAL.iban`           | IBAN                                               |
| `FINANCIAL`  | `FINANCIAL.swift`          | SWIFT code                                         |
| `FINANCIAL`  | `FINANCIAL.bank_account`   | Bank account number                                |

### Health Information (PHI)

Protected health information.

| Parent Label | Element Label          | Description                        |
| ------------ | ---------------------- | ---------------------------------- |
| `MEDICAL`    | `MEDICAL.diagnosis`    | Diagnosis                          |
| `MEDICAL`    | `MEDICAL.medication`   | Medication                         |
| `MEDICAL`    | `MEDICAL.procedure`    | Medical procedure                  |
| `MEDICAL`    | `MEDICAL.insurance_id` | Health insurance member identifier |
| `MEDICAL`    | `MEDICAL.mrn`          | Medical record number              |
| `MEDICAL`    | `MEDICAL.medical_code` | Medical code                       |
| `MEDICAL`    | `MEDICAL.provider_id`  | Medical provider identifier        |

### Secrets

Authentication credentials and cryptographic material.

| Parent Label | Element Label         | Description                            |
| ------------ | --------------------- | -------------------------------------- |
| `SECRETS`    | `SECRETS.password`    | Password                               |
| `SECRETS`    | `SECRETS.api_key`     | API key or service access key          |
| `SECRETS`    | `SECRETS.private_key` | Private key or certificate-like secret |
| `SECRETS`    | `SECRETS.seed_phrase` | Seed phrase                            |
| `SECRETS`    | `SECRETS.token`       | Authentication token                   |

### Technical Information

System and network identifiers.

| Parent Label | Element Label            | Description                            |
| ------------ | ------------------------ | -------------------------------------- |
| `TECHNICAL`  | `TECHNICAL.ip`           | IP address                             |
| `TECHNICAL`  | `TECHNICAL.mac`          | MAC address                            |
| `TECHNICAL`  | `TECHNICAL.url`          | URL or website                         |
| `TECHNICAL`  | `TECHNICAL.account_id`   | Account or device identifier           |
| `TECHNICAL`  | `TECHNICAL.hostname`     | Hostname                               |
| `TECHNICAL`  | `TECHNICAL.imei`         | IMEI or device serial-style identifier |
| `TECHNICAL`  | `TECHNICAL.telemetry_id` | Telemetry identifier                   |

### Location Information

Geographic and coordinate data.

| Parent Label | Element Label          | Description                                    |
| ------------ | ---------------------- | ---------------------------------------------- |
| `LOCATION`   | `LOCATION.country`     | Country                                        |
| `LOCATION`   | `LOCATION.state`       | State or province                              |
| `LOCATION`   | `LOCATION.city`        | City                                           |
| `LOCATION`   | `LOCATION.postal_code` | Postal code or ZIP code                        |
| `LOCATION`   | `LOCATION.coordinates` | Latitude, longitude, or geographic coordinates |

### Organization Information

Business and team entity identifiers.

| Parent Label   | Element Label            | Description                             |
| -------------- | ------------------------ | --------------------------------------- |
| `ORGANIZATION` | `ORGANIZATION.org_name`  | Organization, employer, or company name |
| `ORGANIZATION` | `ORGANIZATION.team_name` | Team name                               |

### Reference Identifiers

Universal reference identifiers.

| Parent Label | Element Label           | Description                             |
| ------------ | ----------------------- | --------------------------------------- |
| `REFERENCE`  | `REFERENCE.case_id`     | Case identifier                         |
| `REFERENCE`  | `REFERENCE.document_id` | Document identifier                     |
| `REFERENCE`  | `REFERENCE.locator`     | Transaction or locator-style identifier |
| `REFERENCE`  | `REFERENCE.product_id`  | Product identifier                      |

## V1 Mapping Reference

| V1 Label                                                                                   | V2 Label                     | Change                  |
| ------------------------------------------------------------------------------------------ | ---------------------------- | ----------------------- |
| `email`                                                                                    | `PERSONAL.email`             | Renamed                 |
| `phone_number`                                                                             | `PERSONAL.phone`             | Renamed                 |
| `first_name`                                                                               | `PERSONAL.name.given`        | Renamed                 |
| `last_name`                                                                                | `PERSONAL.name.family`       | Renamed                 |
| `name`                                                                                     | `PERSONAL.name`              | Renamed                 |
| `birthday`, `birthday_year`, `birthday_month`, `birthday_day`                              | `PERSONAL.dob`               | Consolidated            |
| `street_address`                                                                           | `PERSONAL.address.street`    | Renamed                 |
| `us_address`                                                                               | `PERSONAL.address`           | Consolidated            |
| `us_ssn`, `us_ssn_last_four`                                                               | `GOVERNMENT.ssn`             | Consolidated            |
| `passport` variants                                                                        | `GOVERNMENT.passport`        | Consolidated            |
| `drivers_license`                                                                          | `GOVERNMENT.drivers_license` | Exact match             |
| `ein`, `tin`                                                                               | `GOVERNMENT.ein`             | Consolidated            |
| `vin`                                                                                      | `GOVERNMENT.vin`             | Exact match             |
| `license_plate`, `license_plate_number`                                                    | `GOVERNMENT.license_plate`   | Renamed                 |
| `credit_card`, `cc_last_four`                                                              | `FINANCIAL.card_number`      | Consolidated            |
| `cc_expiration`                                                                            | `FINANCIAL.card_expiry`      | Renamed                 |
| `cvv`                                                                                      | `FINANCIAL.cvv`              | Exact match             |
| `aba_routing`                                                                              | `FINANCIAL.routing_number`   | Renamed                 |
| `iban`                                                                                     | `FINANCIAL.iban`             | Exact match             |
| `swift_code`                                                                               | `FINANCIAL.swift`            | Renamed                 |
| `us_bank`                                                                                  | `FINANCIAL.bank_account`     | Renamed                 |
| `zipcode`                                                                                  | `LOCATION.postal_code`       | Renamed                 |
| `country`                                                                                  | `LOCATION.country`           | Exact match             |
| `state`                                                                                    | `LOCATION.state`             | Exact match             |
| `city`                                                                                     | `LOCATION.city`              | Exact match             |
| `latitude`, `longitude`, `geo_coordinates`, `location`                                     | `LOCATION.coordinates`       | Consolidated            |
| `organization`, `employer`                                                                 | `ORGANIZATION.org_name`      | Consolidated            |
| `website`                                                                                  | `TECHNICAL.url`              | Renamed                 |
| `ip_address`, `ipv4`, `ipv6`                                                               | `TECHNICAL.ip`               | Consolidated            |
| `mac_address`                                                                              | `TECHNICAL.mac`              | Renamed                 |
| `device_id`, `account_id`                                                                  | `TECHNICAL.account_id`       | Consolidated            |
| `password`                                                                                 | `SECRETS.password`           | Exact match             |
| `api_key`, `aws_access_key_id`, `aws_secret_access_key`, `gitapp_key`, `gcp_auth_cert_url` | `SECRETS.api_key`            | Consolidated            |
| `github_auth_token`, `gitlab_key`, `jira_token`, `stripe_token`, `marqeta_token`           | `SECRETS.token`              | Consolidated            |
| `certificate`                                                                              | `SECRETS.private_key`        | Approximate             |
| `race`                                                                                     | `PROTECTED.race_ethnicity`   | Renamed                 |
| `gender`                                                                                   | `PROTECTED.sex.gender`       | Renamed and moved to L3 |
| `religion`                                                                                 | `PROTECTED.religion`         | Exact match             |
| `age`                                                                                      | `PROTECTED.age`              | Exact match             |
| `origin`                                                                                   | `PROTECTED.national_origin`  | Renamed                 |
| `transaction_id`                                                                           | `REFERENCE.locator`          | Approximate             |
| `prescription_number`                                                                      | `MEDICAL.mrn`                | Approximate             |

## Labels No Longer Detected

The following v1 labels do not have a v2 equivalent and are not returned by the classifier after migration:

| V1 Label                                                                               | Reason                                    |
| -------------------------------------------------------------------------------------- | ----------------------------------------- |
| `height`, `weight`                                                                     | Not PII-relevant                          |
| `date`, `timestamp`, `calendar`, `appointment_date`                                    | Too generic; dates are contextual         |
| `death_date`                                                                           | Insufficient training signal              |
| `transaction`, `transaction_amount`, `transaction_date`                                | Not PII-relevant                          |
| `transaction_vendor`                                                                   | Use `ORGANIZATION.org_name` instead       |
| `monetary_amount`, `currency`, `salary`, `account_balance`, `loan_number`, `bank_name` | Not PII-relevant                          |
| `cc_type`                                                                              | Not PII-relevant                          |
| `blood_type`, `diagnosis_date`, `admission_date`, `discharge_date`                     | Replaced by the expanded `MEDICAL` family |
| `marital_status`, `language`, `occupation`                                             | Not PII-relevant                          |
| `middle_name`, `initials`, `title`                                                     | Covered by `PERSONAL.name`                |


# AWS

## Requirements

For each AWS Account you'd like to enroll

| Name           | Description                                                                                                                                                                    |
| -------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Teleskope Role | Create an IAM role for Teleskope to assume using [Terraform](#create-a-teleskope-role-using-terraform) or on the [AWS Console](#create-a-teleskope-role-using-the-aws-console) |

### Create a Teleskope Role using Terraform

| Variable                 | Description                                                                                         | Example        |
| ------------------------ | --------------------------------------------------------------------------------------------------- | -------------- |
| origin\_aws\_account\_id | (Required) AWS Account ID where Teleskope is deployed that the Teleskope team will provide you with | "012345678912" |

```
##################################################################
# The role Teleskope will assume from the origin AWS account. #
##################################################################

resource "aws_iam_role" "teleskope" {
  name               = "TeleskopeRole"
  assume_role_policy = data.aws_iam_policy_document.assume_role_policy.json
}

data "aws_iam_policy_document" "assume_role_policy" {
  statement {
    actions = ["sts:AssumeRole"]

    principals {
      type        = "AWS"
      identifiers = ["arn:aws:iam::{origin_aws_account_id}:root"]
    }
  }
}

resource "aws_iam_role_policy" "account_policy" {
  role   = aws_iam_role.teleskope.id
  policy = <<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "ec2:DescribeRegions",
        "ec2:DescribeSecurityGroups"
      ],
      "Resource": "*"
    }
  ]
}
EOF
}
```

### Create a Teleskope Role using the AWS Console

1. Sign in to the AWS Management Console and open the IAM console at <https://console.aws.amazon.com/iam/>
2. In the navigation pane of the console, choose Roles and then choose Create role
3. Choose Custom Trust Policy as the Trusted Entity Type
4. Replace the custom trust policy with:

   ```json
   {    
       "Version": "2012-10-17",
       "Statement": [
           {
               "Effect": "Allow",
               "Principal": {
                   "AWS": "arn:aws:iam::{origin_aws_account_id}:root"
               },
               "Action": "sts:AssumeRole"
           }
       ]
   }
   ```
5. Create a custom inline policy with:

   ```json
   {
     "Version": "2012-10-17",
     "Statement": [
       {
         "Effect": "Allow",
         "Action": [
           "ec2:DescribeRegions",
           "ec2:DescribeSecurityGroups"
         ],
         "Resource": "*"
       }
     ]
   }
   ```

## Enrollment

In Teleskope, enroll the AWS account:

1. Provide the AWS Account ID
2. Provide a name for your AWS Account
3. Provide the previously created role name exactly as it appears


# Athena

## Requirements

| Name           | Description                                                                       |
| -------------- | --------------------------------------------------------------------------------- |
| Teleskope Role | Attach Athena read and/or write permissions to the Teleskope IAM role you created |

{% stepper %}
{% step %}
**Grant Teleskope Read Access to Athena**

Teleskope needs read access to scan and classify your data stored in Athena.

Attach a custom AmazonAthenaReadOnlyAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "sns_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonAthenaReadOnlyAccess"
}
```

Custom AmazonAthenaReadOnlyAccess:

```json
{
  "Version" : "2012-10-17",
  "Statement" : [
    {
      "Sid" : "AthenaReadOnlyPermissions",
      "Effect" : "Allow",
      "Action" : [
        "athena:*"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BaseGluePermissions",
      "Effect" : "Allow",
      "Action" : [
        "glue:GetDatabase",
        "glue:GetDatabases",
        "glue:GetTable",
        "glue:GetTables",
        "glue:GetPartition",
        "glue:GetPartitions",
        "glue:BatchGetPartition",
        "glue:StartColumnStatisticsTaskRun",
        "glue:GetColumnStatisticsTaskRun",
        "glue:GetColumnStatisticsTaskRuns"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BaseQueryResultsPermissions",
      "Effect" : "Allow",
      "Action" : [
        "s3:GetBucketLocation",
        "s3:GetObject",
        "s3:ListBucket",
        "s3:ListBucketMultipartUploads",
        "s3:ListMultipartUploadParts",
        "s3:AbortMultipartUpload",
      ],
      "Resource" : [
        "arn:aws:s3:::aws-athena-query-results-*"
      ]
    },
    {
      "Sid" : "BaseAthenaExamplesPermissions",
      "Effect" : "Allow",
      "Action" : [
        "s3:GetObject",
        "s3:ListBucket"
      ],
      "Resource" : [
        "arn:aws:s3:::athena-examples*"
      ]
    },
    {
      "Sid" : "BaseS3BucketPermissions",
      "Effect" : "Allow",
      "Action" : [
        "s3:ListBucket",
        "s3:GetBucketLocation",
        "s3:ListAllMyBuckets"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BaseSNSPermissions",
      "Effect" : "Allow",
      "Action" : [
        "sns:ListTopics",
        "sns:GetTopicAttributes"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BaseLakeFormationPermissions",
      "Effect" : "Allow",
      "Action" : [
        "lakeformation:GetDataAccess"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BaseDataZonePermissions",
      "Effect" : "Allow",
      "Action" : [
        "datazone:ListDomains",
        "datazone:ListProjects",
        "datazone:ListAccountEnvironments"
      ],
      "Resource" : [
        "*"
      ]
    },
    {
      "Sid" : "BasePricingPermissions",
      "Effect" : "Allow",
      "Action" : [
        "pricing:GetProducts"
      ],
      "Resource" : [
        "*"
      ]
    }
  ]
}
```

{% endstep %}

{% step %}
**Grant Teleskope Read & Write Access to Athena (Optional)**

Teleskope needs write access take enforce remediation policies such as tagging, redaction, deletion, etc.

Attach the AmazonAthenaFullAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "AmazonAthenaFullAccess" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonAthenaFullAccess"
}
```

{% endstep %}
{% endstepper %}


# DynamoDB

## Requirements

| Name           | Description                                                                         |
| -------------- | ----------------------------------------------------------------------------------- |
| Teleskope Role | Attach DynamoDB read and/or write permissions to the Teleskope IAM role you created |

{% stepper %}
{% step %}
**Grant Teleskope Read Access to DynamoDB**

Teleskope needs read access to scan and classify your data stored in DynamoDB.

Attach the AmazonDynamoDBReadOnlyAccess to the Teleskope role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "dynamodb_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonDynamoDBReadOnlyAccess"
}
```

{% endstep %}

{% step %}
**Grant Teleskope Read & Write Access to DynamoDB (optional)**

Teleskope needs write access take enforce remediation policies such as tagging, redaction, deletion, etc.

Attach the AmazonDynamoDBReadOnlyAccess to the Teleskope role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "dynamodb_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonDynamoDBFullAccess"
}
```

{% endstep %}
{% endstepper %}


# EFS

Teleskope's EFS connector scans Amazon Elastic File System (EFS) for sensitive data. Because EFS filesystems are mounted over NFS within a VPC, scanning requires a Teleskope **Outpost** — a lightweight agent deployed inside the same VPC as your EFS mount target. The Outpost handles all file I/O locally and reports findings back to the Teleskope hub over HTTPS.

## Requirements

| Requirement            | Details                                                                                                    |
| ---------------------- | ---------------------------------------------------------------------------------------------------------- |
| Teleskope Role         | An IAM role in your AWS account with the EFS control-plane permissions below, trusted by the Teleskope hub |
| Teleskope Outpost      | A Teleskope Outpost deployed in the same VPC as your EFS mount target — required for filesystem access     |
| Network access         | The Outpost node must be able to reach the EFS mount target on port `2049` (NFS)                           |
| Teleskope account role | Admin role in the Teleskope platform                                                                       |

***

{% stepper %}
{% step %}

#### Grant Teleskope Read Access to EFS

Attach the following least-privilege policy to the Teleskope IAM role in your account. This allows the Teleskope hub to discover EFS filesystems via the AWS control plane — no VPC access is required for this step.

**Terraform**

```
resource "aws_iam_policy" "teleskope_efs_policy" {
  name        = "TeleskopeEFSPolicy"
  description = "Grants Teleskope read access to discover EFS filesystems"

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Action = [
          "elasticfilesystem:DescribeFileSystems",
          "elasticfilesystem:DescribeMountTargets",
          "elasticfilesystem:DescribeMountTargetSecurityGroups",
          "elasticfilesystem:DescribeTags",
          "elasticfilesystem:ListTagsForResource"
        ]
        Resource = "*"
      }
    ]
  })
}

resource "aws_iam_role_policy_attachment" "teleskope_efs" {
  role       = "TeleskopeRole"
  policy_arn = aws_iam_policy.teleskope_efs_policy.arn
}
```

{% endstep %}

{% step %}

#### Deploy a Teleskope Outpost in your VPC

EFS filesystems are accessed over NFS and require a node in the same VPC as the mount target. Teleskope uses an Outpost — a self-managed agent deployed in your environment — to handle all file access locally.

* Follow the **Outpost setup guide** to deploy the Outpost in the same VPC and availability zone as your EFS mount target
* Ensure the Outpost node's security group allows outbound access on port `2049` to the EFS mount target security group
* The EFS filesystem is mounted at `/mnt/efs` on the Outpost via the EFS CSI driver — the Outpost crawler walks the directory tree over the local mount
* The Outpost communicates results back to the Teleskope hub via HTTPS — ensure the Outpost has outbound internet access or a VPC endpoint to the Teleskope API

Currently, each Outpost supports one EFS filesystem. If you have multiple filesystems, deploy one Outpost per filesystem.
{% endstep %}

{% step %}

#### Enroll the EFS Connector in Teleskope

Once the IAM role and Outpost are in place, enroll the connector from the Teleskope settings page.

* Navigate to **Settings → Connectors → AWS**
* Click **Enroll+**
* Enter your **AWS Account ID** and the **IAM role ARN** for the Teleskope role you configured
* Navigate to **EFS** and enroll the desired accounts
* Teleskope will call `DescribeFileSystems` to discover filesystems in your account and display them in the connector settings
* Your Outpost will begin crawling the assigned filesystem according to the set crawling schedule
  {% endstep %}
  {% endstepper %}


# RDS

## Requirements

<table><thead><tr><th width="214.3515625">Name</th><th>Description</th></tr></thead><tbody><tr><td>IAM Edit Permission</td><td>To attach RDS read and/or write permissions to the Teleskope IAM role</td></tr><tr><td>Database Admin User</td><td>To create a read and/or write database user for each RDS cluster you'd like us to scan</td></tr><tr><td>Network Access</td><td>Teleskope must be able to reach each instance endpoint on its database port. See <a href="#network-access">Network Access</a> for the public and private subnet paths.</td></tr></tbody></table>

####

{% stepper %}
{% step %}

#### Grant Teleskope AWS scopes

**Grant the TeleskopeRole read permission**

Teleskope requires read access to automatically discover all of your RDS clusters and instances.

Attach the `AmazonRDSReadOnlyAccess` permission to the TeleskopeRole identity you created.

{% code title="RDS Read Only Terraform" %}

```json
resource "aws_iam_role_policy_attachment" "rds_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonRDSReadOnlyAccess"
}
```

{% endcode %}

**Grant the TeleskopeRole Read and Write IAM Access to RDS (Optional)**

Teleskope requires write access to perform remediation actions like tagging.

Attach the `AmazonRDSFullAccess` to the Teleskope role you created.

{% code title="RDS Read/Write Terraform" %}

```
resource "aws_iam_role_policy_attachment" "rds_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonRDSFullAccess"
}
```

{% endcode %}
{% endstep %}

{% step %}
**Create a Database User for Teleskope**

For each RDS cluster you would like to scan using Teleskope, you will need to:

1. Create a database user for authentication with [Username and Password](/connectors/aws/rds/username-and-password), or [IAM Auth](/connectors/aws/rds/iam-auth).
2. Grant the user permission to read/write in the cluster
   {% endstep %}

{% step %}
**Confirm network access**

Set up the network path that matches your deployment — see [Network Access](#network-access) below.
{% endstep %}

{% step %}
**Enroll the Cluster in the Teleskope UI**
{% endstep %}
{% endstepper %}

## Network Access

The IAM role covers discovery only: Teleskope lists your clusters and instances through the AWS API. Crawling and scanning open a database connection to each instance endpoint, so Teleskope must be able to reach that endpoint on its database port. Which path applies depends on whether the instance is publicly accessible.

### Publicly accessible instances

Allow inbound traffic on the database port from Teleskope's egress IP addresses in the instance's security group. Teleskope provides the full IP set.

{% hint style="warning" %}
**Warning:** Allowlist the entire IP set, not a single address. Individual egress IPs can change during infrastructure updates.
{% endhint %}

### Instances in private subnets

A private endpoint is not reachable from outside your VPC. Choose one of the following paths.

{% tabs %}
{% tab title="VPC Peering" %}
Teleskope connects to the instance endpoint directly over a VPC peering connection.

1. Provide Teleskope the VPC ID containing your RDS instances. Teleskope initiates a peering request from its VPC and shares its AWS account ID and VPC CIDR.
2. Accept the peering connection in your console (VPC → Peering connections).
3. In the route tables used by your RDS subnets, add a route to the Teleskope VPC CIDR via the peering connection.
4. In the instance's security group, allow inbound traffic on the database port from the Teleskope VPC CIDR.

Peering requires non-overlapping CIDRs between your VPC and Teleskope's. Teleskope confirms this before sending the request.
{% endtab %}

{% tab title="SSH Tunnel (Bastion)" %}
Teleskope connects through a bastion host you operate in a public subnet.

1. Launch an EC2 instance in a public subnet to serve as the SSH tunnel bastion host.
2. Place the Teleskope-provided public key in `~/.ssh/authorized_keys` on the bastion user:

   ```bash
   echo "<TELESKOPE_PUBLIC_KEY>" >> ~/.ssh/authorized_keys
   chmod 700 ~/.ssh
   chmod 600 ~/.ssh/authorized_keys
   ```
3. Allow inbound SSH (port 22) from Teleskope's egress IP addresses in the bastion's security group. Teleskope provides the IP set.
4. Assign an Elastic IP (EIP) to the bastion host.
5. Adjust route tables and security groups so the bastion can reach the RDS instances on their database ports.
6. Provide Teleskope with the bastion username and the bastion Elastic IP.
   {% endtab %}
   {% endtabs %}


# IAM Auth

{% stepper %}
{% step %}
**Create the IAM Database User**

**MySQL or MariaDB**

```sql
CREATE USER teleskope IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS';
```

**Postgres**

```sql
CREATE USER teleskope; 
GRANT rds_iam TO teleskope;
```

{% endstep %}

{% step %}
**Grant DB User Permissions**

{% tabs %}
{% tab title="Read Access" %}
**MySQL or MariaDB**

```sql
GRANT SHOW DATABASES, SELECT ON *.* TO teleskope
```

**Postgres versions 14+**

```sql
GRANT pg_read_all_data TO teleskope
```

**Postgres versions < 14**

```sql
SELECT format('GRANT CONNECT ON DATABASE %I TO teleskope;', datname) FROM pg_database \gexec
SELECT format('GRANT USAGE ON SCHEMA %I TO teleskope;', nspname) FROM pg_namespace \gexec
SELECT format('GRANT SELECT ON ALL TABLES IN SCHEMA %I TO teleskope;', nspname) FROM pg_namespace \gexec
```

{% endtab %}

{% tab title="Write Access" %}
**MySQL or MariaDB**

```sql
GRANT UPDATE, DELETE on *.* TO teleskope
```

**Postgres versions 14+**

```sql
GRANT pg_write_all_data TO teleskope
```

**Postgres versions < 14**

```sql
SELECT format('GRANT UPDATE, DELETE ON ALL TABLES IN SCHEMA %I TO teleskope;', nspname) FROM pg_namespace \gexec
```

{% endtab %}
{% endtabs %}
{% endstep %}

{% step %}
**Enable IAM Auth**

1. [Enable IAM Auth](https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.IAMDBAuth.Enabling.html) for the RDS Cluster.
2. Provide the Teleskope IAM role in the AWS account with the following permission for your database:

{% code fullWidth="true" %}

```json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "rds-db:connect"
      ],
      "Resource": [
        "arn:aws:rds-db:{REGION}:{ACCOUNT_ID}:dbuser:{DB_RESOURCE_ID}/{DB_USER}"
      ]
    }
  ]
}
```

{% endcode %}
{% endstep %}

{% step %}
**Submit the&#x20;**<mark style="color:purple;">**Username**</mark>**&#x20;in the Teleskope interface**
{% endstep %}
{% endstepper %}


# Username and Password

{% stepper %}
{% step %}

#### Create the Database User

**MySQL or MariaDB or Oracle**

```sql
CREATE USER teleskope_ro IDENTIFIED BY '****PASSWORD****'
```

**MS SQL**

```sql
CREATE LOGIN teleskope_ro WITH PASSWORD = '****PASSWORD****';
```

**Postgres**

```sql
CREATE USER teleskope_ro WITH PASSWORD  '****PASSWORD****'
```

{% endstep %}

{% step %}

#### Grant DB User Permissions

{% tabs %}
{% tab title="Read Access" %}
**MySQL or MariaDB**

```sql
GRANT SHOW DATABASES, SELECT ON *.* TO teleskope_ro
```

**Postgres versions 14+**

```sql
GRANT pg_read_all_data TO teleskope_ro
```

**Postgres versions < 14**

```sql
SELECT format('GRANT CONNECT ON DATABASE %I TO teleskope_ro;', datname)
FROM pg_database WHERE datname NOT IN ('template0','template1') \gexec
SELECT format('GRANT USAGE ON SCHEMA %I TO teleskope_ro;', nspname)
FROM pg_namespace WHERE nspname NOT IN ('pg_toast','pg_catalog','information_schema') \gexec
SELECT format('GRANT SELECT ON ALL TABLES IN SCHEMA %I TO teleskope_ro;', nspname)
FROM pg_namespace WHERE nspname NOT IN ('pg_toast','pg_catalog','information_schema') \gexec
```

**Oracle SQL**

```sql
GRANT CONNECT TO teleskope_ro;
GRANT SELECT ANY TABLE TO teleskope_ro;
GRANT SELECT_CATALOG_ROLE TO teleskope_ro;
```

**MS SQL**

```sql
GRANT VIEW ANY DATABASE TO teleskope_ro;
DECLARE @sql NVARCHAR(MAX);
SET @sql = '';
SELECT @sql += 
    'USE [' + name + ']; 
    CREATE USER teleskope_ro FOR LOGIN teleskope_ro;
    GRANT SELECT TO teleskope_ro;
    GRANT VIEW DATABASE STATE TO teleskope_ro;' + CHAR(13)
FROM sys.databases
WHERE state = 0 AND name NOT IN ('tempdb', 'model', 'msdb', 'rdsadmin');
EXEC sp_executesql @sql;
```

{% endtab %}

{% tab title="Write Access" %}
**MySQL or MariaDB**

```sql
GRANT UPDATE, DELETE on *.* TO teleskope_ro
```

**Postgres versions 14+**

```sql
GRANT pg_write_all_data TO teleskope_ro
```

**Postgres versions < 14**

```sql
SELECT format('GRANT UPDATE, DELETE ON ALL TABLES IN SCHEMA %I TO teleskope_ro;', nspname)
FROM pg_namespace WHERE nspname NOT IN ('pg_toast','pg_catalog','information_schema') \gexec
```

{% endtab %}
{% endtabs %}

Databases created after these grants are not covered automatically. Re-run the grants, or set default privileges so future tables are readable:

```sql
ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT SELECT ON TABLES TO teleskope_ro;
```

{% endstep %}

{% step %}
**Submit the&#x20;**<mark style="color:purple;">**Username and Password**</mark>**&#x20;in the Teleskope interface**
{% endstep %}
{% endstepper %}


# Redshift

## Requirements

| Name                | Description                                                                                                                                              |
| ------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Teleskope Role      | Attach Redshift read and/or write permissions to the Teleskope IAM role you created                                                                      |
| Database Admin User | Create a read and/or write database user for each Redshift cluster you'd like us to scan                                                                 |
| Network Access      | If your Redshift clusters are in private subnets and you do not want to peer VPCs, create a bastion host for us to use to access your Redshift clusters. |

{% stepper %}
{% step %}
**Grant Teleskope IAM Access to Redshift**

Attach the AmazonRedshiftDataFullAccess and AmazonRedshiftReadOnlyAccess to the Teleskope role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "redshift_read_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonRedshiftReadOnlyAccess"
}

resource "aws_iam_role_policy_attachment" "redshift_data_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonRedshiftDataFullAccess"
}

# Optional: required if using Redshift IAM database authentication (no stored password).
data "aws_caller_identity" "current" {}

resource "aws_iam_policy" "redshift_iam_auth" {
  name = "teleskope-redshift-iam-auth"
  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Sid    = "RedshiftIamAuth"
        Effect = "Allow"
        Action = [
          "redshift:GetClusterCredentials",
          "redshift:GetClusterCredentialsWithIAM"
        ]
        Resource = [
          "arn:aws:redshift:${var.aws_region}:${data.aws_caller_identity.current.account_id}:cluster:${var.redshift_cluster_identifier}",
          "arn:aws:redshift:${var.aws_region}:${data.aws_caller_identity.current.account_id}:dbuser:${var.redshift_cluster_identifier}/teleskope"
        ]
      }
    ]
  })
}

resource "aws_iam_role_policy_attachment" "redshift_iam_auth" {
  role       = "TeleskopeRole"
  policy_arn = aws_iam_policy.redshift_iam_auth.arn
}
```

{% endstep %}

{% step %}
**Teleskope Database User**

For each Redshift cluster you would like to scan using Teleskope, you will need to create a database user, and grant that user read permissions.

**Create Database User**

**If using username and password:**

```sql
CREATE USER teleskope WITH PASSWORD  '****PASSWORD****'
```

**If using IAM Authentication:**

```sql
CREATE USER teleskope WITH SYSLOG ACCESS UNRESTRICTED;
```

* Then **associate the IAM role to the Redshift cluster** using:

  ```powershell
  aws redshift associate-iam-roles \
    --cluster-identifier my-redshift-cluster \
    --iam-role-arn arn:aws:iam::<account-id>:role/TeleskopeRole
  ```

**Grant Read Access**

```sql
GRANT SELECT ON svv_all_schemas TO teleskope_ro;
GRANT SELECT ON svv_table_info TO teleskope_ro;
GRANT SELECT ON ALL TABLES IN SCHEMA pg_catalog


-- Grant select to each Redshift schema
GRANT USAGE ON SCHEMA {schema} TO teleskope;
GRANT SELECT ON ALL TABLES IN SCHEMA {schema} TO teleskope;
```

**Grant Write Access**

For each redshift schema:

```sql
GRANT UPDATE, DELETE ON ALL TABLES IN SCHEMA {schema} TO teleskope;
```

{% endstep %}

{% step %}
**Enroll in Teleskope UI**

To enroll your Redshift cluster:

1. Navigate to **Settings**-> **Connector Settings** -> **AWS** -> **Redshift**
2. Click the radial button next to each cluster, **Edit,** and enter:
   1. If using **username/password**, the username and password of the cluster
   2. If using **IAM Auth**, the username (leave password field blank)
      {% endstep %}
      {% endstepper %}

## SSH Tunnel (Optional)

1. Launch an EC2 instance in a public subnet to serve as the SHH tunnel Bastion Host.
   1. The public key for the key-pair parameter will be provided by Teleskope: teleskope-bastion-key.
   2. Place the public key in `~/.ssh/authorized_keys` .<br>

      ```bash
      echo "<TELESKOPE_PUBLIC_KEY>" >> ~/.ssh/authorized_keys
      ```
   3. Update the permissions on the file and directory.<br>

      ```bash
      chmod 700 ~/.ssh
      chmod 600 ~/.ssh/authorized_keys
      ```
   4. Designate Teleskope AWS account access within your security group(s). IP addresses will be provided by Teleskope.
   5. Assign an Elastic IP (EIP) to the bastion host.
2. Adjust route tables and security groups as needed to provide access to the Redshift cluster through the bastion host.
3. Provide Teleskope with the bastion username, and the bastion elastic IP.


# S3

## Requirements

| Name           | Description                                                                   |
| -------------- | ----------------------------------------------------------------------------- |
| Teleskope Role | Attach S3 read and/or write permissions to the Teleskope IAM role you created |

***

{% stepper %}
{% step %}
**Grant Teleskope Read Access to S3**

Teleskope needs read access to scan and classify your data stored in S3.

Attach the AmazonS3ReadOnlyAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "s3_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonS3ReadOnlyAccess"
}
```

Or create a least-privilege policy, and specify bucket restrictions under resource, and attach that policy to the role

**Terraform**

```
resource "aws_iam_policy" "teleskope_s3_policy" {
  name        = "TeleskopeS3Policy"
  description = "Policy to grant various read permissions for S3 resources."

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Effect = "Allow"
        Action = [
          "s3:GetBucketPolicyStatus",
          "s3:GetBucketPublicAccessBlock",
          "s3:GetLifecycleConfiguration",
          "s3:GetBucketTagging",
          "s3:GetInventoryConfiguration",
          "s3:GetBucketWebsite",
          "s3:GetBucketLogging",
          "s3:ListBucket",
          "s3:GetBucketVersioning",
          "s3:GetBucketAcl",
          "s3:GetBucketNotification",
          "s3:GetBucketPolicy",
          "s3:GetReplicationConfiguration",
          "s3:GetBucketObjectLockConfiguration",
          "s3:GetEncryptionConfiguration",
          "s3:PutBucketTagging",
          "s3:GetBucketCORS",
          "s3:GetBucketLocation"
        ]
        Resource = "arn:aws:s3:::*"
      },
      {
        Effect = "Allow"
        Action = [
          "s3:GetObjectAcl",
          "s3:GetObject",
          "s3:GetObjectTagging",
          "s3:PutObjectTagging",
          "s3:GetObjectVersion"
        ]
        Resource = "arn:aws:s3:::*/*"
      },
      {
        Effect = "Allow"
        Action = [
          "s3:GetAccountPublicAccessBlock",
          "s3:ListAllMyBuckets",
          "s3:GetBucketInventoryConfiguration"
        ]
        Resource = "*"
      }
    ]
  })
}
```

{% endstep %}

{% step %}
**Grant Teleskope Read & Write Access to S3 (Optional)**

Teleskope needs write access take enforce remediation policies such as tagging, redaction, deletion, etc.

Attach the AmazonS3FullAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "s3_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonS3FullAccess"
}
```

{% endstep %}
{% endstepper %}

### Inventory Reports (optional)

We highly recommend enabling inventory reports on your buckets. Teleskope could use those reports to efficiently list objects and reduce cost on your cloud.\
When enabling inventory reports, please make sure to add the following fields:

1. Bucket
2. Key
3. Size
4. Last Modified Date
5. Storage Class


# SNS

## Requirements

| Name           | Description                                                                    |
| -------------- | ------------------------------------------------------------------------------ |
| Teleskope Role | Attach SNS read and/or write permissions to the Teleskope IAM role you created |

{% stepper %}
{% step %}
**Grant Teleskope Read Access to SNS**

Teleskope needs read access to scan and classify your data stored in SNS.

Attach the AmazonSNSReadOnlyAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "sns_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonSNSReadOnlyAccess"
}
```

{% endstep %}

{% step %}
**Grant Teleskope Read & Write Access to SNS (optional)**

Teleskope needs write access take enforce remediation policies such as tagging, redaction, deletion, etc.

Attach the AmazonSNSFullAccess to the Teleskope IAM role you created.

**Terraform**

```
resource "aws_iam_role_policy_attachment" "sns_policy" {
  role       = "TeleskopeRole"
  policy_arn = "arn:aws:iam::aws:policy/AmazonSNSFullAccess"
}
```

{% endstep %}
{% endstepper %}




---

[Next Page](/llms-full.txt/1)

