Skip to content

Commit f4d4cb1

Browse files
authored
Rearrange PII page
1 parent fbe0bfb commit f4d4cb1

File tree

1 file changed

+5
-14
lines changed
  • src/content/docs/cloudflare-one/insights/logs/gateway-logs

1 file changed

+5
-14
lines changed

src/content/docs/cloudflare-one/insights/logs/gateway-logs/manage-pii.mdx

Lines changed: 5 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,9 @@ sidebar:
55
order: 3
66
---
77

8-
Cloudflare Gateway gives you multiple ways to safely handle your employees' personally identifiable information (PII). You can choose to exclude PII from activity logging, or you can choose to redact PII from everyone except for designated administrators.
8+
Cloudflare Gateway gives you multiple ways to safely handle your employees' personally identifiable information (PII). By default, PII is redacted from Gateway Activity logs for all permission roles except the Super Administrator and users with the [Cloudflare Zero Trust PII role](/cloudflare-one/roles-permissions/#cloudflare-zero-trust-pii) assigned to them. Only the Super Admin can assign roles and determine who has permission to view PII. Redacting PII does not affect the way PII is captured in logs -- the data is simply hidden and no information is lost. To add or remove the Cloudflare Zero Trust PII role for a user, refer to [Account setup](/fundamentals/manage-members/).
9+
10+
Alternatively, you can choose to [exclude PII](#exclude-pii) from Gateway activity logs for all users.
911

1012
## Types of PII
1113

@@ -21,17 +23,6 @@ Cloudflare Gateway can log the following types of PII:
2123

2224
## Exclude PII
2325

24-
Enabling this setting means Cloudflare Gateway will log activity without storing any employee PII. Changes to this setting will not change PII storage of any previous logs. This means if Exclude PII is enabled and then disabled, there will be no PII data for logs captured while Exclude PII was enabled. The PII data will be unavailable to all roles within your Zero Trust organization, including the Super Admin.
25-
26-
To enable or disable this setting, log in to [Zero Trust](https://one.dash.cloudflare.com/) and go to **Settings** > **Network** > **Exclude PII**.
27-
28-
## Redact PII
29-
30-
:::note
31-
32-
This feature is only available on Enterprise plans.
33-
:::
34-
35-
PII is by default redacted from Gateway Activity logs for all permission roles except the Super Admin and users with the [Cloudflare Zero Trust PII role](/cloudflare-one/roles-permissions/#cloudflare-zero-trust-pii) assigned to them. Only the Super Admin can assign roles and determine who has permission to view PII. Redacting PII does not affect the way PII is captured in logs — the data is simply hidden and no information is lost.
26+
Turning on this setting means Cloudflare Gateway will log activity without storing any employee PII. Changes to this setting will not change PII storage of any previous logs. This means if Exclude PII is turned on and then turned off, there will be no PII data for logs captured while Exclude PII was turned on. The PII data will be unavailable to all roles within your Zero Trust organization, including the Super Admin.
3627

37-
To add or remove the Cloudflare Zero Trust PII role for a user, refer to our [Account setup](/fundamentals/manage-members/) documentation.
28+
To turn on this setting, log in to [Zero Trust](https://one.dash.cloudflare.com/) and go to **Settings** > **Network** > **Exclude PII**.

0 commit comments

Comments
 (0)