NERVE is live across local, private and approved-cloud deployments. Book an evaluation
Handling, privacy and purpose remain separate.
Handling markings, privacy profiles and purpose of use are modelled as distinct concerns, so authority to administer the platform is not the same as authority to read protected content.
Governance
5 min
Three separate concerns
Handling, privacy and purpose are modelled separately because they answer different questions. Handling describes how sensitive the material is and who may see it. A privacy profile describes what obligations attach to personal data within it. Purpose of use describes why a particular person or service is reading it right now.
Markings travel with the object
Handling markings are attributes of the canonical object, not of the screen that displays it. A derived artefact inherits the handling of the material it was produced from. When an object is exported or read through the Search API, the marking travels with it.
Workload identity
Service-to-service access uses a workload identity rather than a borrowed human account. CORTEX reads NERVE under its own workload identity, and that identity is constrained by the same handling policy as a human user. Machine access stays auditable and separately revocable.
Administration is not access
Platform administration and content access are deliberately different authorities. Broad administrative permission does not automatically grant protected content access. An operator can run the pipeline, manage connectors and inspect job health without being granted sight of restricted material.
Shared responsibility
NERVE enforces the policy it is given and records the decisions it makes. Accreditation of the environment, hardening of the infrastructure and the lawful basis for processing remain a shared responsibility between the platform and the operating organisation.
Key points
Handling markings travel with the object, not with the interface that displays it.
Privacy profiles and purpose of use are recorded separately from handling markings.
Workload identity governs service-to-service access, including the CORTEX Search API.
Broad administrative permission does not automatically grant protected content access.
Where this stops
NERVE enforces the policy it is given. Accreditation, environment hardening and lawful basis for processing remain a shared responsibility between the platform and the operating organisation.
Related
Next
See the behaviour on your own material.
An evaluation runs NERVE against an approved sample in your environment, with the originals retained and every transformation recorded.