How to deidentify data in Maskbits?
De-identification masks sensitive data and replaces it with secure PII alternatives. This article is the starting point: it walks the shared configuration sequence every de-identification follows and helps you choose one of the three methods: Auto, Excel-based, or Manual for the step where rules are created.
Before you begin
You need the Maskbits Designer role and a connected data source. Security tags are configured by an Account Admin in Maskbits and applied by Designers. Every de-identification follows the same fixed sequence of name, method and data source, rule definition, filter, output, summary and only the rule-definition step differs by method.
Choose a method
The three methods produce the same kind of rules and differ only in how those rules are created. Pick based on how you want to define them, then follow that method’s how-to for the rule-definition step:
- Auto — detects PII with AI and de-identifies it. Fastest; no field-by-field entry.
- Excel-based — applies rules from a downloaded, filled-in template. Good for many rules at once.
- Manual — defines each field rule directly in the UI.
Start and name the de-identification
- Open De-identification.
- Select the project and enter a title, then select Next.
Choose method and data source
- Select Auto, Excel-based, or Manual configuration.
- Select the data source, then select Next.
Define rules (method-specific)
- Create the de-identification rules using the method you chose. Each rule binds a Generator, a Mode, and a Field Path. Follow the matching how-to: Auto, Excel, or Manual De-identification.
- When rules are defined, select Next.
Filter, output, and submit
- On the Filter screen, optionally restrict processing to a subset, then select Next.
- On the Output Configuration screen, choose the output store and add a prefix or suffix to the output table name; the output preview shows the resulting name. Select Next.
- On the Summary page, review and select Submit.
Result
Maskbits applies the configured rules and writes the de-identified data to the chosen output as a separate table, named from the source table plus your prefix or suffix, leaving the original in place.