Inventory your sensitive data, put it on a consistent classification scheme with sensitivity labels, and map every asset to the controls and policies that are supposed to protect it. Data protection stops being a guess about where the crown jewels live.
You can’t protect what you haven’t named. TATER holds one register of your data assets, each tagged with a classification tier and label, tied to the controls that guard it and the policy that governs it — so “how is our confidential data protected?” has an answer you can show.
Put every data asset on a consistent tier — Public, Internal, Confidential, Restricted, or your own scheme — so classification is a shared vocabulary instead of a judgment call that differs by team.
Attach a sensitivity label to each classified asset, capturing how it should be handled — the human-readable marker that tells anyone touching the data what care it demands.
Keep a living inventory of data assets — what it is, where it lives, who owns it, and which system holds it — so the sensitive-data map is a maintained record, not a workshop artifact from two years ago.
Link each classification to the controls that protect it and the Data Classification policy that governs it, so a Restricted asset is visibly connected to the safeguards and the rules that apply — not just a label with nothing behind it.
Record the handling and retention expectations that ride with each tier — how long it’s kept and how it’s treated — so retention is defined per classification instead of decided ad hoc when someone asks.
The classification register is the evidence an auditor asks for on data-protection controls — a maintained inventory with owners, tiers, and control mappings — ready to show instead of assembled the night before.
The module runs the classification lifecycle in one register, tied to the controls and policies TATER already holds.
Record each data asset — what it is, where it lives, and who owns it — in one register.
Assign a tier and sensitivity label, and attach the handling and retention rules for that level.
Map each classification to its protecting controls and policy, and keep the register current as data changes.
“Where does our most sensitive data actually live, and who owns it?”
The inventory names each asset with its tier, location, and owner — so the sensitive-data map is a maintained record anyone can pull, not tribal knowledge.
A framework asks you to prove how confidential data is classified and protected.
Each classification links to the controls that protect it and the policy that governs it, so the answer is a mapping you can show rather than an assertion.
“Show me your data classification scheme and evidence it’s applied.”
The register is the evidence — tiers, labels, owners, retention, and control mappings in one place — sampled directly instead of reconstructed for the review.
The guide covers defining your classification scheme, building the data inventory, labeling assets, and mapping classifications to controls and policy.
See the classification register, labeling, and control mapping on your own tenant in a live walkthrough.