Grotabyte
Contact SalesBook a Demo

Supervise · Supervision & DLP

An open alert is an unreviewed communication

Eight lexicons that cite their regulation, eighteen data-loss detectors across twelve countries, and a queue where every alert ends in a written, attributed disposition — because a supervisory programme is evidenced by dispositions, not by alert volume.

Grotabyte — Supervision & DLP
MNPI · lexicon (SEC 10b-5)CRITICAL
“…not public yet, but the filing lands Thursday…”escalated · r.patel
DLP · CARD (Luhn-verified)HIGH
“…please wire to ⟦45••••••••31⟧ before Friday…” — evidence masked by constructioncleared · reason typed
Review coverage3.0% of population
sampled deterministically by hash — same document, same answer
8 lexicons citing their regulation · 18 detectors, 12 countries · dispositions, not dashboards

Where it starts

A new tenant does not start from a blank page. Seven working policies ship enabled-ready — insider trading and MNPI, off-channel communications, customer complaints, conduct, gifts and entertainment, sensitive data leaving, credentials and key material — each naming the regulation it evidences. Your first act is tuning them to your firm, not inventing supervision from scratch.

How it runs

  1. 01

    Tune the policy before the first run

    Edit a shipped policy or write your own: severity, the regulation it evidences, the fraction reviewed, your own terms and expressions — or describe it in plain words and the engine proposes matching vocabulary from your archive's own language, which you read before it becomes policy. Editing a shipped policy asks why, and the reason goes on the record.

  2. 02

    Run against the whole population

    A run streams the entire ordered population, not a convenience sample. Where a policy samples, the rate is deterministic by document — the same document is always in or out — and the rate is recorded on every run, because a procedure claiming full coverage while sampling misrepresents to the regulator.

  3. 03

    Work the queue

    Each alert shows severity, the policy and rule that raised it, the custodian, and masked evidence: the words around the match with the matched value itself replaced — so the supervision queue never becomes a second copy of the card number it caught.

  4. 04

    Dispose every alert, in writing

    Clear or escalate — each demands a typed reason, attributed to the reviewer, timestamped, and written to the hash-chained ledger. An empty reason is refused: a disposition without a stated reason cannot evidence the review.

  5. 05

    Read the coverage, not the count

    The screen reports review coverage against the population — documents supplied, documents in population, per-policy examined counts and sample rates — the numbers a supervisory procedure actually has to defend.

Why it holds up

Every lexicon carries its regulation: MNPI (SEC 10b-5; Reg FD), collusion (FINRA 2010; Sherman Act §1), guarantees (FINRA 2210), complaints (FINRA 4513), gifts (FINRA 3220), off-channel (SEC 17a-4), sales pressure (FINRA 2111).
Nine national identifiers are checksum-verified — a 16-digit number that fails Luhn is not a card alert. In testing, the bare-shape version of one detector alone raised thousands of false alerts that the checksummed version silenced.
Credential and passport rules match 密码, contraseña, Passwort, пароль and 비밀번호 — not just 'password'. An English-only CRITICAL rule reports the archive clean.
A policy that cannot raise anything is refused at creation, not discovered at the quarterly review.
Concept-expanded criteria are frozen once approved; re-expansion is an explicit, recorded act — a criterion that quietly matched different words each quarter could not be defended.

What you hand the regulator

A workflow that ends on a screen isn’t finished. This one ends in a document.

Run record + disposition set

What a firm hands FINRA is not a dashboard screenshot. It is the run record, the disposition set, and the audit-log export that ties them to the tamper-evident ledger.

  • documents_in_population · documents_supplied · coverage_pct
  • per-policy: examined count, sample rate, alerts raised
  • every disposition: reviewer, timestamp, state, typed reason
  • audit-log CSV filtered to SUPERVISION_SCAN + SUPERVISION_DISPOSITION
  • ledger root hash from Chain of Custody, anchoring the lot

Adjacent workflows

Chain of Custody & AuditSearch & Term Hit ReportsRetention & Certified Destruction

See it run on your data scenario

The demo form asks which workflows you want to see — name this one and we’ll stage it.

Book a DemoAll workflows

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.