Sensitive Information Type
A Sensitive Information Type is a predefined rule that automatically recognizes particular kinds of confidential content, such as social security numbers, credit card numbers, or bank account details, based on the patterns those items typically follow. It is used within data governance platforms to help find and sort sensitive material so it can be handled appropriately. The term is closely associated with Microsoft Purview, though the general concept of pattern-based content detection is not unique to any one product.
A Sensitive Information Type (SIT) is a pattern-based classifier that detects specific categories of sensitive content by matching defined patterns, and it may combine supporting elements such as keywords, formats, and proximity or confidence criteria to identify candidate matches. In Microsoft Purview, SITs are provided as built-in entity definitions covering data types like social security, credit card, and bank account numbers, and can also be created and managed as custom SITs where organizational requirements demand it. SITs support automated detection and classification of content, but their scope is limited to identifying that information matches a pattern; they do not themselves determine records status, retention, disposition, or the authoritative recordkeeping properties (authenticity, reliability, integrity, usability) of the content in which the sensitive data appears. The specific entity definitions and management capabilities described here are documented in the context of Microsoft Purview and should not be assumed to apply identically to other platforms or jurisdictions.
Why it matters
Organizations increasingly hold large volumes of unstructured content across email, documents, and collaboration platforms, much of which may contain confidential material such as social security numbers, credit card numbers, or bank account details. Locating that material manually is often impractical at scale, which is why pattern-based detection has become a common component of data governance programs. Sensitive Information Types provide a mechanism to surface content that matches recognizable patterns, enabling it to be identified and sorted so that appropriate handling can follow.
From an information governance perspective, the value of a SIT lies in supporting downstream decisions rather than making them. Detecting that a document contains what appears to be a credit card number does not by itself establish whether that document is a record, what retention period applies, or how it should ultimately be disposed of or preserved. Those determinations depend on organizational policy and, in many jurisdictions, on statutory and regulatory requirements that vary by sector and location. A SIT is best understood as an input to classification and risk-management workflows, not a substitute for the recordkeeping judgments that govern authenticity, reliability, integrity, and usability of the underlying content.
Because pattern matching identifies candidates rather than confirmed facts, professionals should treat SIT results as indicative and subject to review. Patterns can produce both false positives and missed matches, and the confidence associated with a detection depends on how the SIT is configured. Relying on detection alone, without governance policy to interpret and act on the results, can create a false sense of assurance about where sensitive information resides and how it is being controlled.
Who it's relevant to
Inside SIT
Common questions
Answers to the questions practitioners most commonly ask about SIT.