Skip to main content
Organization Admins can add regular expressions for internal credential formats under Organization Settings → Security → Data redaction. These rules extend Serval’s built-in secret detection for help desk messages across your organization’s teams.
Custom redaction is available to enrolled organizations. If the section is missing, contact Serval support to request access.

Add and test a rule

  1. Open Security settings and select Add pattern.
  2. Enter a descriptive name and a regular expression for your credential format. For example, ACME_SECRET_[A-Za-z0-9]{24} matches a distinctive prefix followed by 24 letters or digits.
  3. Enter synthetic sample text containing matching and non-matching examples, then run the preview. The preview applies Serval’s built-in rules and your candidate rule using the same engine as message scrubbing. Sample text is not saved with the rule.
  4. Select Save disabled to keep the rule for later, or Save and enable to start applying it after a successful preview.
Editing a rule does not change its saved behavior until you save. If the rule is enabled, its previous expression remains active while you edit. Test realistic examples before saving: redacted values cannot be recovered from the stored message.

Supported expressions

Expressions use Go’s RE2 syntax. Lookarounds and backreferences are not supported. Each expression can contain at most 200 characters, and an organization can have up to 50 rules. Use a distinctive credential prefix and a constrained body. Expressions that match empty text or common examples of ordinary text, emails, phone numbers, or UUIDs are rejected. This feature is intended for credential formats; it is not a general personal-data classification system.

Scope and timing

Enabled rules replace matching text with [REDACTED] in newly written or updated help desk messages and supported stored external-message payloads. Rules apply across teams in the organization. Changes normally propagate within two minutes. These rules cover saved message text and the listed mirrors. They do not provide a guarantee for every ticket field, such as ticket names, summaries, other metadata, or separate tool arguments and results. The rules do not scan historical data, attachment contents, or Catalyst workspaces. They do not remove a message already stored by an external service, such as Slack or Microsoft Teams. Do not treat the preview as a scan of existing data or a guarantee that every live stream, external delivery, or model input is filtered by your custom rule. If the policy cannot be refreshed temporarily, Serval continues using the last successfully loaded policy. A message operation that cannot load any trusted policy fails so it can be retried.

Manage rules

Organization Admins can edit, disable, or delete rules. Disabling or deleting a rule affects future message writes; it cannot restore text already redacted. Changes are recorded in the organization’s audit log. Serval’s built-in detectors remain active independently of custom rules. They recognize known credential formats, including Serval API-key secrets. You do not need to add a custom expression for those formats.