Classification and clearance
How Scrydon classifies information, what enforcement denies, and how to grant a member clearance.
Scrydon classifies information on a Bell–LaPadula ladder and enforces no-read-up: you cannot read something classified above your clearance. The control is on by default for every organization — there is nothing to switch on.
It aligns with ISO 27001:2022 A.5.12 (Classification of information) and NIST SP 800-171 3.1.3.
The default ladder
Every organization starts on the four-tier scrydon.default scheme.
| Rank | Label | Meaning |
|---|---|---|
| 0 | PUBLIC | Approved for external release. |
| 1 | INTERNAL | Internal use only. The baseline for members and for unlabelled uploads. |
| 2 | CONFIDENTIAL | Limited distribution; clearance required. |
| 3 | RESTRICTED | Narrow need-to-know; highest sensitivity. |
A member with no explicit clearance holds INTERNAL. They are internal employees, so they can read their organization's ordinary content without an administrator granting anything. CONFIDENTIAL and above always require an explicit grant — the baseline is a floor, not a blank cheque.
What enforcement actually denies
Only content somebody deliberately classified. An upload that nobody classifies is stored unlabelled and stays readable by anyone with access to its knowledge base.
When a document is classified, a read or write is denied if your clearance is below its rank. Search results are filtered the same way, in every mode — a search never surfaces a document you are not cleared to see.
Granting a member clearance
Settings → Governance → Identity → Members. Pick the member, set their clearance, save. The change is audited.
You cannot grant a clearance higher than your own. Ranks above yours appear in the picker but are disabled, with the reason shown.
Changing the enforcement mode
Settings → Governance → Identity. The Enforcement mode selector sits in the page header and applies to every clearance surface.
| Mode | Behaviour |
|---|---|
| Enforce (default) | Deny on violation. |
| Audit | Log only. The would-be denial is recorded; the action proceeds. |
| Disabled | Checks off. Requires an exception reference and an expiry, capped at 90 days. |
Search stays clearance-strict in all three modes. Lowering the mode relaxes per-document read, write, and delete decisions only.
Adopting the scheme as your policy of record
Until you change something, the Clearance tab shows "Product default · not yet adopted" — you are running Scrydon's packaged scheme, and improvements to it reach you automatically.
The first change you make records you as the approver, with a date. From then on the scheme is your organization's own and Scrydon will not modify it. If an auditor asks who approved your classification policy and when, that is the record.
Editing the defaults
The Clearance tab exposes two organization-wide defaults:
- Default member clearance — what a member holds with no explicit clearance.
- Unlabelled data — what an unclassified upload is treated as.
Member clearance may not sit below unlabelled data. That combination denies every member every unlabelled document in their own organization, so it is rejected on save.