Policy: GCP > Model Armor > Floor Setting > Settings > Detection > Sensitive Data Protection
Whether the floor's filterConfig.sdpSettings.basicConfig.filterEnforcement must be ENABLED — the Basic mode of Sensitive Data Protection, which detects a fixed set of common PII categories (e.g. credit-card numbers, US social security numbers, email addresses) in prompts and responses without a customer-provided DLP inspect template.
When Enabled, the Settings control alarms unless the SDP Basic filter is enforced on the live Floor Setting, and the Set Floor Setting action sets it to ENABLED on Enforce: Enabled per ... (preserving any existing advancedConfig block — Advanced mode is not in scope here). When Disabled, the filter is not checked.
Targets
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
Setting this policy configures this control:
Policy Specification
Schema Type | |
|---|---|
Default | |
Valid Values [YAML] |
|
Examples [YAML] | Enabled |
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/security
- tmod:@turbot/gcp-modelarmor#/policy/types/floorSettingSettingsDetectionSensitiveDataProtection
- turbot graphql policy-type --id "tmod:@turbot/gcp-modelarmor#/policy/types/floorSettingSettingsDetectionSensitiveDataProtection"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/gcp-modelarmor#/policy/types/floorSettingSettingsDetectionSensitiveDataProtection"
Get Policy TypeGet Policy Settings