dekkosecure

Tenancy Management

De-identified Hubs for External Sharing

Prevent parties outside your organisation from seeing internal users’ details

De-identified sharing replaces the names and email addresses of your internal users with aliases wherever an external user would otherwise see them. Externals still see who is who, because each user keeps the same alias, but they do not see real profile names or real email addresses.

Notion image
Notion image

The policy applies at the tenancy level. When it is enabled, it takes effect in every Hub in the tenancy.

💡

Only what external users are shown changes. Real identities are retained by the platform, and internal users continue to see real names and email addresses as normal.

Where aliases appear

External users see the alias instead of the real identity in:

  • the contact list
  • the Owner column in the file list
  • the status column, including the expanded sharing details for a file or folder

Items the external user owns themselves continue to show as me.

Configuring the policy

De-identified sharing is set by a tenancy administrator, using two values:

  • Alias full name, the display name that replaces real names, for example Support Staff #
  • Base alias email, the address the alias emails are generated from, for example support@demo-agency.gov
Notion image

The system uses these two values as a convention and applies them to every internal user an external can see.

How aliases are numbered

Where a Hub contains more than one user, the alias name and email are iterated with an appended number. The number is added to the name you set, and it indexes the local part of the base email address.

Using the values above, users would be presented to externals as:

Alias name
Alias email
Support Staff #1
support1@demo-agency.gov
Support Staff #2
support2@demo-agency.gov
Support Staff #3
support3@demo-agency.gov

Each user keeps the same alias, so an external can still tell your users apart across files, folders, and messages.

💡

Use a non-deliverable subdomain for the base alias email so that generated aliases cannot collide with real mailboxes in your organisation.

What externals can and cannot see

De-identified sharing works alongside the team to external and external to external relationship controls for Hubs:

  • External users see your team users, with the name and email de-identified.
  • Other external users are hidden from the contact list completely.

Updating the conventions

The alias name and email conventions can be updated at any time. Externals will see the new convention in place of the previous one.

If the policy is disabled

External users see the real profile names and email addresses of the other users in the Hub.

 
Did this answer your question?
😞
😐
🤩