Enterprise Shield adds an enhanced layer of fortified security and control to an account on Lucid’s already highly secure platform. This add-on enables admins on your account to streamline processes for safeguarding sensitive data and elevate compliance controls with robust content lifecycle management capabilities.
The features covered in this article are available for setup and usage primarily via the Lucid admin panel for the account owner, account admins, document admins, and Shield admins. Contact sales to purchase the Enterprise Shield add-on.
Access Enterprise Shield Center
In the Enterprise Shield Center, you can explore all the available Enterprise Shield features. Check out the use cases for inspiration on the value and purpose of the features.
To access the Enterprise Shield Center, follow these instructions:
- In Lucid, click Admin from the More menu in the bottom-left corner.
- Select Add-ons from the left-hand panel.
- From the dropdown, select Enterprise Shield Center.
Protect sensitive data
Automate sensitive data identification in bulk by continuously scanning documents for information—such as personally identifiable information (PII) or personal data—in order to handle data in accordance with regulatory and internal guidelines.
Prevent unauthorized data access and the mishandling of sensitive information with robust classification controls that restrict documents from being shared outside the organization via email or sharing links. Employ precise controls for revoking external shares on specific documents in bulk.
Create a content inspection policy
This feature, which is available to the account owner, document admins, and Shield admins, queues all documents on your account to scan for certain categories of sensitive data. Upon queue activation, Lucid will continuously scan all account documents. After the initial scan, we'll focus on scanning only the modified documents. Scan results appear on the results tab where you can review any detected sensitive data matches by document. Content inspection is intended to aid your evaluation of document content, but cannot identify all content subject to data privacy laws or regulations and should not be used as a substitute for a robust legal compliance program. For instructions to use this feature, refer to our Lucid admin panel: Compliance settings article.
Content inspection functions on documents and not other Lucid objects. For instance, data within the insights dashboard will not be scanned by content inspection. However, because the insights are derived from roll-up fields in a Lucid document, that initial occurrence is scanned by content inspection and would flag sensitive data in its original location. It's also important to note that if sensitive content is removed or redacted from the document, it will still be visible to accelerator managers in the past dashboard insights.
Note: Content inspection assesses your data based on a non-exhaustive list of sensitive data detailed in this sensitive categories and infotypes community post. Not all categories of sensitive data are capable of being detected and sensitive data that is detected may not be able to be categorized accurately (e.g. name is categorized as general PII; the system cannot identify whether a specific name is from the EU). Performing a full content inspection will not provide 100% accuracy across all scenarios or identify all content subject to data privacy laws or regulations. You are responsible for independently evaluating your own content as appropriate to meet your legal and compliance obligations under applicable law.
Set up classification controls
Lucid has enhanced the classification feature to offer more intelligent capabilities specifically designed for Enterprise accounts seeking a way to maintain the confidentiality of sensitive information with the Enterprise Shield add-on. By customizing document classifications, such as “confidential” or other appropriate designations with corresponding actions, your organization can control who has access to certain types of information.
During the creation of classification labels, the account owner, account admins, document admins, and Shield admins can set controls tied to each classification to restrict external sharing, replicating, publishing, exporting, and printing from within Lucid. These controls typically align with your organization's data governance policies. For instructions to set up classification controls, check out our Lucid admin panel: Compliance settings article.
Classification controls do not apply to rolled-up fields within our accelerators. They also do not apply to insights displayed on dashboards for accelerator managers.
Search with document management API
Lucid's document management API enables the account owner, document admins, and Shield admins to efficiently search and retrieve documents and folders within their organization. Admins can access all document and folder details through specific endpoints. For technical details, check out the Search documents and Search folders resources from the Lucid API documentation.
Control content access
In this section, you’ll learn how you can distribute security based on the needs of your users by:
- Setting sharing permissions at the organizational group level
- Limiting unauthorized access with an IP allowlist, as well as max session and idle session time-outs
- Utilizing the Lucid key management system (KMS)
By using these features, you can customize content access to prevent unauthorized access to sensitive data. The features outlined in this section are available to the account owner, account admins, and Shield admins.
Set sharing permissions at the organizational group level
Using Lucid’s organizational groups, the account owner, account admins, and Shield admins can customize shareable link settings and publishing and embedding settings for different users within your organization. To do so, select a group from the “Organizational groups” established on your account and adjust the shareable link settings before adjusting the sharing settings using the steps found in our Lucid admin panel: Security settings article.
Customize max session time-out
This feature lets you define a maximum session duration for users on your account. Once a user exceeds the configured session limit—regardless of activity—they will be required to re-authenticate. This can be set for durations between 2 hours and 365 days. The default for Enterprise Shield accounts is set to 30 days.
To enable and customize the max session time-out to best suit your account’s needs, check out the instructions in our Lucid admin panel: Security settings article.
Configure idle session time-out
Use this feature to force logout following inactive periods. Set a time limit between 15 minutes and 14 days of inactivity, after which users on your account will be required to log in to resume activity. For instructions to set up an idle session time-out limit as the account owner, account admin, or Shield admin, refer to our Lucid admin panel: Security settings article.
Note: If you are a FedRAMP account, this idle session time-out feature is a standard offering available to your Enterprise account. The other features covered in this article are a part of the Enterprise Shield for Lucid GovSuite add-on.
Set up an IP allowlist
Leverage this offering as an account owner, account admin, or Shield admin to choose which IP addresses can access your account. This feature requires CIDR notation to denote IP ranges, e.g. 192.168.2.0/24. Check out the Lucid admin panel: Security settings article for more information.
Utilize the Lucid key management service
The Lucid key management service (KMS) allows you to control your encryption keys. If there is evidence that the key has been compromised, you can rotate your Master Key from the KMS page in the Lucid admin panel. For additional information, refer to our Lucid admin panel: Security settings article.
Restrict user login to organization accounts only
This feature ensures that only users from your approved Lucid account(s) can access Lucid products from within your corporate network, blocking all personal or unmanaged accounts. Implementing this feature requires coordination between your IT team and Lucid.
To get started, provide Lucid with the account ID(s) you want to allow, including any test and production accounts. You can do this by contacting your account manager or reaching out to Lucid Support.
Once initiated, you must configure both your proxy server and all corporate client devices to support this restriction. Failure to complete the configuration as outlined below will prevent the feature from functioning correctly.
Client Configuration
- Route all outbound traffic to lucid.app through your organization's web proxy servers.
-
Configure each client device to trust your SSL proxy:
- Deploy the internal Root Certificate Authority (CA) used by the proxy.
- Mark the internal CA as trusted on all devices.
Proxy Configuration
- Enable SSL interception on your proxy server.
- Intercept all requests to lucid.app.
-
Add the HTTP header: X-Lucid-Allowed-AccountIds
- The account ID(s) listed must match the ones you previously provided to Lucid.
-
If allowing multiple accounts, use a comma-separated list of account IDs.
Example: X-Lucid-Allowed-AccountIds: 123456,789012
Note: All configurations, including HTTP header names and values, are case-sensitive and must be entered exactly as shown.
Content lifecycle management
Effectively manage and preserve all relevant documents and data when facing legal actions or audits. Quickly identify and apply holds to Lucid users to prevent accidental or intentional deletion. Enhance compliance and data governance with content lifecycle management.
Support compliance and governance requirements by setting rules for how your organization retains and disposes of data.
Set up a document retention policy
This feature offers a seamless solution to manage your organization's data lifecycle. With it, you can set up an automated policy to delete documents based on specified criteria, ensuring compliance with regulatory standards and internal data management protocols. To learn more, check out our Lucid admin panel: Compliance settings article.
Access audit logs
Lucid’s audit logs provide you access to a log of key events across your account. These events provide valuable insight into user activity, content management, and system administration, ensuring robust security and compliance. You can filter by one or more of the following:
- Date
- Event type
- Actor
Once filtered, the table displays all events matching your search. Depending on your search criteria, you may see a selection of up to five columns from the following list: Date (UTC), IP address, Actor, Event, and Target(s).
Click any event to open its audit log details in the right panel. You can also export the results in JSON or CSV format using the Export button at the top right of the table.
You also have the option to leverage an Audit log API to access logs that can be forwarded to your SIEM (Security information and event management) or other log aggregation system as explained in the API documentation from the Lucid Developer Docs.
Lucid's audit log API tracks a wide range of key events, including:
- User access events such as when a user successfully logged in, joined an account, and experienced a failed password login
- User actions within Lucid, including when a document was created, downloaded, opened, and deleted
- Actions within the admin panel, such as creating a new user, removing a user from the account, and updating a user role
- When a user is deleted and anonymized, their account is removed from the system; however, the user’s name, email address, and user ID may remain visible in audit logs for the duration of the 180 day audit log retention period.
For a full list of all currently logged events, please refer to our Developer Docs.
Use Lucid’s legal hold API
The legal hold API equips the account owner, document admins, and Shield admins with the tools to preserve a user’s documents during legal proceedings or audits. With this API, you can effectively create and manage legal holds to ensure that crucial documents are protected from permanent deletion throughout the process.
Note: Legal hold applies to documents and not other Lucid objects. For instance, the insights dashboard will not be included in a legal hold. If the insights are exported into a Lucid document, that document will be included in the legal hold, provided the custodian has access.
Admins can create a legal hold through the API, which includes the following options:
- Name the legal hold.
- Add an optional description for the hold.
- Set start and end dates for the hold. You can manually release a hold prior to the end date, if needed.
- Add users to be impacted by the legal hold, which are referred to as “custodians.” This can be done before the hold has begun. By default, all documents owned or shared with the custodian are included.
- To narrow down the scope of the hold, you can leverage a keyword search of the current document contents (though keep in mind that past versions on documents aren’t included). This helps ensure that only documents accessible to a custodian that also currently contain a specific keyword will be included in the legal hold.
Users on legal hold can’t delete documents from the trash. Any account documents that a user on legal hold (also called a “custodian”) has access to at the start of the hold or gains access to during the hold will be added to the legal hold. Custodians of a scheduled or active legal hold cannot be deleted from Lucid. Users with documents on a legal hold can switch accounts, but their documents on the legal hold will be transferred to the account’s default document owner (in order to remain on the legal hold); but no documents on legal hold can be transferred to an user that isn’t on the Enterprise account. Legal hold will only preserve documents the account owns. It does not preserve an externally owned document that is shared with a user on legal hold.
Lucid doesn’t notify users that are put on legal hold; this is up to the discretion of your legal team and admins. Additionally, if a user tries to delete a document on a hold, they are discreetly notified that an admin has prevented deletion. Upon the expiration of the legal hold, documents are released and can be permanently deleted. Refer to the legal hold API documentation for instructions.
Note: This API functions the same regardless of retention settings that have been set for the account. Documents put on legal hold can’t be permanently deleted, even if they would otherwise meet the deletion criteria established via your retention settings.
Manage documents with Discovery
Leverage the Discovery feature to search and access all documents owned by your account. While the bulk of the functionality offered with this feature is available to all Enterprise accounts, with the Enterprise Shield add-on you gain the ability to export metadata CSV and PDFs, to revoke external sharing in bulk, and to see the revision history of all documents on your account. To learn more, refer to our Lucid admin panel: Compliance settings article.
FAQ
Which objects are included in content inspection?
The following objects are included in content inspection scans:
- Shapes
- Text boxes
- Sticky notes
- Comments
Which documents in my Lucid account are included in content inspection?
All active documents will be inspected—which means all documents in your Documents page. Documents in the trash are excluded.
What are the minimum and maximum periods of time for document retention?
We have minimum and maximum limits on our retention period options, which are:
- 30-999 days
- 1-180 months
- 1-15 years
Give feedback on this article
Have feedback about this article? Tell us about your experience here.