Managing scopes

Scopes define the organizational boundaries within which IBM® Guardium® Exposure Manager monitors and secures data interactions, and you can assign policies to each scope to enforce fine-grained security controls.

IBM Guardium Exposure Manager provides two scope types:

  • Projects define workload boundaries for data store assets.
  • Cohorts define workforce boundaries for endpoint devices.

You can create scopes of assets and assign policies to each scope to enforce security controls at the project and cohort levels.

Projects (workload)
A project is a logical container of all the data stores and services that are relevant to a specific software project with a defined goal and a specific owner. IBM Guardium Exposure Manager monitors projects, which can include all the data stores and services that require data monitoring to prevent sensitive data exposure to a specific AI agent or other external facing interface. Project monitoring enables you to track and manage AI applications, RAG pipelines, vector databases, and model inference.
Cohorts (workforce)
IBM Guardium Exposure Manager monitors cohorts, which represent employee endpoints. Monitoring cohorts enables you to track and manage file downloads, file uploads, and copy-paste operations that involve corporate data. Security teams can track how employees interact with AI applications, what data users request from AI systems, and how employees consume and share AI-generated content.