NERVE is live across local, private and approved-cloud deployments. Book an evaluation

Handling, privacy and purpose remain separate.

Handling markings, privacy profiles and purpose of use are modelled as distinct concerns, so authority to administer the platform is not the same as authority to read protected content.

Governance

5 min

Three separate concerns

Handling, privacy and purpose are modelled separately because they answer different questions. Handling describes how sensitive the material is and who may see it. A privacy profile describes what obligations attach to personal data within it. Purpose of use describes why a particular person or service is reading it right now.

Markings travel with the object

Handling markings are attributes of the canonical object, not of the screen that displays it. A derived artefact inherits the handling of the material it was produced from. When an object is exported or read through the Search API, the marking travels with it.

Workload identity

Service-to-service access uses a workload identity rather than a borrowed human account. CORTEX reads NERVE under its own workload identity, and that identity is constrained by the same handling policy as a human user. Machine access stays auditable and separately revocable.

Administration is not access

Platform administration and content access are deliberately different authorities. Broad administrative permission does not automatically grant protected content access. An operator can run the pipeline, manage connectors and inspect job health without being granted sight of restricted material.

Shared responsibility

NERVE enforces the policy it is given and records the decisions it makes. Accreditation of the environment, hardening of the infrastructure and the lawful basis for processing remain a shared responsibility between the platform and the operating organisation.

Key points

Handling markings travel with the object, not with the interface that displays it.

Privacy profiles and purpose of use are recorded separately from handling markings.

Workload identity governs service-to-service access, including the CORTEX Search API.

Broad administrative permission does not automatically grant protected content access.

Where this stops

NERVE enforces the policy it is given. Accreditation, environment hardening and lawful basis for processing remain a shared responsibility between the platform and the operating organisation.

Next

See the behaviour on your own material.

An evaluation runs NERVE against an approved sample in your environment, with the originals retained and every transformation recorded.