Skip to main content

Monitor and enforce

ThreatLens runs in one of two modes. Most organizations start in monitor to understand real usage, then switch to enforce to make policy binding.

The two modes

ModeWhat happens
MonitorEvery request is classified and recorded, but nothing is blocked or redacted. Use it to baseline behavior.
EnforcePolicy is binding — content is redacted, routed, or blocked according to the policy matrix.
Monitor still records everything

In monitor mode you get the full audit log — you can see exactly what would have been blocked or redacted before you turn enforcement on.

  1. Start in monitor. Let real traffic flow for a week or two.
  2. Review the audit log. Look at what's being classified as sensitive, and where it's going.
  3. Tune the matrix. Adjust policy-matrix rows so enforcement won't surprise anyone.
  4. Switch to enforce. Now redaction, routing, and blocking are live.

Change the mode

  1. Go to Governance → Deployment (enforcement settings).
  2. Select Monitor or Enforce.
  3. Save.

The Deployment page — the monitor and enforce settings.

What gets recorded

The mode change is written to the audit log, so there's a clear record of when enforcement began.