← Back to Guidelines
Common Approaches
These are just some examples to help you think through options based on your process — not a required list. Send us a message if you’re unclear — we’re glad to help!
Program standards apply to deal-processing roles only.
- View-only document access in system of record.
- Email attachments route automatically to system of record, limiting human access.
- Document watermarking — Aquamark or equivalent.
- Secure document delivery — forms, links, API.
- Company-managed devices — restricting access to unauthorized cloud storage, USB drives, and other removable or external transfer methods.
- Email account / tenant restrictions — allow access to approved company email accounts while blocking personal or unauthorized email accounts on company-managed devices.
- Outbound email quarantine on specific messages (e.g. outbound + attachments + sent to external or personal domain).
- CASB (Cloud Access Security Broker) (e.g. Netskope) — applies access and data controls across cloud applications, such as restricting personal accounts, downloads, uploads, syncing, or use from unmanaged devices. Netskope describes CASB as a policy-enforcement layer for managed and unmanaged cloud applications.
- Enterprise browser or browser isolation tools (e.g. Island) — can restrict downloads, copy/paste, screenshots, uploads, or other data movement within specific apps.
- Web/DNS filtering — rules enforced through a firewall, secure web gateway, DNS filtering service, or managed device that block access to selected domains such as personal email or cloud-storage sites.
- Browser management policies — settings configured through browser management platforms such as Chrome Enterprise/Google Admin or Microsoft Intune, Group Policy, and Edge for Business to restrict browser sign-in to approved company accounts, block specific websites, or enforce other browser-level controls. Microsoft Edge specifically supports policies restricting which accounts may sign in.
- MDM / endpoint management (e.g. Intune, Jamf) — centrally applies and enforces device-level security policies, such as app restrictions, browser controls, USB restrictions, and access requirements, regardless of the network being used.
- DLP (Data Loss Prevention) software (e.g. Microsoft Purview DLP) — detects sensitive information and applies rules to prevent or restrict unauthorized sharing through email, uploads, cloud apps, or other transfer methods. Microsoft Purview DLP supports policies that can block external email sharing based on configured conditions.