> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mspilot.io/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> MSPilot enrolls technician Windows machines and Apple Silicon Macs so Claude Desktop and ChatGPT run through one governed gateway. Seat words are standard seat and power seat. ConnectWise PSA import is not available. HIPAA is not a self-serve switch.

# Sensitive data detection

> The organization default and the per-client action when a prompt contains a credit card, US Social Security number, email address, IBAN, or secret.

The gateway checks user text on each prompt from a client's devices. It looks for a credit card number, a US Social Security number, an email address, an IBAN, or a secret. Owners, admins, and staff choose the action. Members can view it.

The check reads every user message in that request, including earlier turns the app sends again. It skips images, tool results, assistant replies, and system text.

A secret is an OpenAI-style key that starts with `sk-`, an AWS access key ID that starts with `AKIA`, a GitHub token that starts with `ghp_`, or a Slack token that starts with `xoxb-` or `xoxp-`.

The gateway applies the saved action on the next prompt. This setting is separate from the config pull that carries skills, branding, and power models.

## Organization default

Open **Organization** and choose **Policy**. **Sensitive data detection** is the default for every client that follows the organization.

The starting action is **Off**. Pick an action and **Save**.

* **Off**. Prompts are sent as written.
* **Block**. The gateway stops the request and the desktop app shows an error. The model never sees the prompt.
* **Log**. The prompt goes through as written. A client uses this only when [conversation capture](/conversations) is on. Otherwise that client is treated as **Off**.
* **Replace**. The model receives a placeholder. The person using the app still sees what they typed.

Placeholders are `<CREDIT_CARD>`, `<US_SSN>`, `<EMAIL_ADDRESS>`, `<IBAN_CODE>`, and `<SECRET>`.

## One client

Open the client and choose **Policy**. **Sensitive data detection** sits above the Claude Desktop and ChatGPT tabs. It applies to prompts those apps send, and to the other apps on the machine that send through the gateway.

**Use organization defaults** follows the organization action. The label names that action, such as **Use organization defaults (Block)**. **Edit organization defaults** opens **Organization → Policy**.

**Custom for this client** saves an action on this client. **Save** appears for that choice. **Log** stays unavailable until conversation capture is on for this client. The label then reads **Log (conversation capture is off)**.

Choosing **Use organization defaults** after a custom action asks you to confirm. The client follows the organization action. Its custom action is kept and is not applied.

If conversation capture is turned off later, a client whose action is **Log** is treated as **Off** until capture is on again.

## What reaches the model

**Block** shows an error in the desktop app that names what it found, such as a credit card number. Conversation capture skips that prompt. **Activity** records the types and **Blocked**.

**Log** sends the text as written. The text is stored only by conversation capture. **Activity** records **Logged**.

**Replace** sends the placeholders to the model. When conversation capture is on, it stores those placeholders. **Activity** records **Replaced**.

**Off** sends the prompt as written. Conversation capture stores that text when capture is on. **Off** adds no activity row.

If the gateway cannot read the action, or cannot finish the check, it blocks the request. The desktop app shows "This request was blocked because sensitive-data detection failed." **Activity** lists **Detection failed** under **Types** and **Blocked** under **Action**.

## Activity

**Activity** is on the client. It lists the latest 50 hits. Each row has **Time**, **Device**, **App**, **Types**, and **Action**. Types are **Credit card**, **US SSN**, **Email**, **IBAN**, and **Secret**. The row records the types and the action. The prompt text stays out of this list. An empty list says "No sensitive data has been detected yet."

The organization page has the action only.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.