Managing projects or workload

IBM® Guardium® Exposure Manager enables you to create and manage projects, which are logical groupings of workloads, through the Projects tab on the Scopes page.

The Projects tab on the Scopes page is also called the Workload tab. Projects are logical groupings of data stores, services, and AI workloads that align with business structures (projects, teams, departments) to do the following tasks:
  • Apply scalable policies with granularity
  • Track violations by business unit
  • Prevent sensitive data exposure to a specific AI Agent or other external facing interface
  • Gain insights into the violations
A table in the Projects tab of the Scopes page lists the default project that is automatically created during the onboarding process of IBM Guardium Exposure Manager and the custom projects that you create. The table provides the following details and insights about the projects.
Name
Name of the project.
Data stores
Number of data stores that are included in the project.
Data classification
The different types of data that are found in the data stores included in the project.
Policy
Name of the policy assigned to the project.
Violations
The number of violations associated with the project.
Owner
Name of the owner of the project.

From the Scopes page, when you click any project listed in the table of the Projects tab, you can find additional information on the side panel that opens in the following sections.

  • Details
  • Data stores
  • Data classification
  • Policy
  • Issues
  • Owner
Note:
  • If a policy is assigned to a project, you can click the policy listed in the Policy section to view details about the policy.
  • The Issues section contains a link to the Issues page that is pre-filtered to display the open issues related to the project.
  • IBM Guardium Exposure Manager creates issues for a project only if that project is assigned to a policy.

Managing project properties

The default project cannot be changed. It can gain data stores only when IBM Guardium Exposure Manager onboards new assets. It can lose data stores only when you remove it from the default project.

You can perform the following actions from a custom project's side panel to manage the project:

Update project description
Do the following steps to update a project name and project description.
  1. Click Actions > Edit details on the side panel or click the Edit icon in the Details section of the side panel.
  2. Update the Project name and Description fields.
  3. Click Save.
Assign policy
If a policy is not assigned to a project, do the following steps to assign a policy to a project.
  1. Click Assign policy in the Policy section of the side panel.
  2. Select the policy you want to assign to the project.
  3. Click Apply.
Note: You can assign only one policy to a project but you can assign one policy to multiple projects.
Edit policy
If a policy is assigned to a project, do the following steps to edit the policy assignment for a project.
  1. Click the Edit icon in the Policy section of the side panel.
  2. Select the policy you want to assign to the project.
  3. Click Apply.
Note: You can assign only one policy to a project but you can assign one policy to multiple projects.
Add data stores
Do the following steps to add data stores to a project.
  1. Click Manage data stores in the Data store side panel.
  2. Click Add data stores.
  3. Select one or more data stores, and then click Add.
Data store side panel

In the Data store side panel, you can click on a listed data store to view more details about the data store resource list and classification chart. You can also click on the listed resource to display the Resource sensitivities panel.

You can export the data in a CSV file format from any of the panels. You can use the imported data to gain insights into sensitivities and resolve violations related to the data sensitivity.

Remove data stores
Do the following steps to remove data stores from a project.
  1. Click Manage data stores in the Data stores section of the side panel.
  2. Click Manage.
  3. Select one or more data stores, and then click Remove.
  4. Select I accept this may affect policy coverage, and then click Remove.
Note: If a data store is not associated with any custom project, it is automatically associated with the default project. There can be no data store that is not associated with a project.
Move data stores
Do the following steps to move data stores from a project to existing projects or to a new project.
  1. Click Manage data stores in the Data stores section of the side panel.
  2. Click Manage.
  3. Select one or more data stores, and then click Move.
  4. Select the projects to which you want to move the data stores or click Create project, enter the Project name, click Create and then select the projects to which you want to move the data stores.
  5. Click Move.
Add data stores of a project to other projects
Do the following steps to add data stores of a project to to other existing projects or to a new project.

A user can create a new project when they add data stores to another project. The process is the same as when a user moves data stores.

  1. Click Manage data stores in the Data stores section of the side panel.
  2. Click Manage.
  3. Select one or more data stores, and then click Move.
  4. Select the project to which you want to move the data stores or click Create project, enter the Project name, click Create and then select the projects to which you want to move the data stores.
  5. Click Move.
Note: The data stores that you add to other projects:
  • Remain part of the project from which you are adding them.
  • Become part of the projects to which you are adding them.
Delete a project
Do the following steps to delete a project.
  1. Click Actions > Delete on the side panel.
  2. Select I accept this may affect policy coverage.
  3. Click Delete.
Note:
  • Deleting a project does not delete the data stores associated with the project.
  • If there are data stores that were associated only with a deleted project, the data stores move to the Default project on the next discovery schedule.
  • The policy associated with the deleted project no longer applies to the data stores that were part of the deleted project.
Add owner
If there is no project owner assigned, do the following steps to add a project owner.
  1. Click the Add icon in the Owner section of the side panel.
  2. Enter the Owner name and Owner email (optional).
  3. Click Save.
Change owner
Do the following steps to change the owner of a project.
  1. Click the Edit icon in the Owner section of the side panel.
  2. Enter the modified Owner name and Owner email (optional).
  3. Click Save.
Delete owner
Do the following steps to delete the owner of a project.
  1. Click the Delete icon in the Owner section of the side panel.
  2. In the Confirm owner removal dialog, click Delete again.