Skip to main content

Data Domain Policies

Setup Guide — Controlling How AI Behaves in Each Data Domain​

Module: AI Module › Configuration  |  Last updated: July 2026


Contents​

  1. Overview
  2. Key Concept: One Policy Per Data Domain
  3. Finding Your Way Around
  4. Turning AI On for a Domain
  5. Choosing the Default Models
  6. Privacy and Logging
  7. How Long Records Are Kept
  8. Quick Reference

1. Overview​

A data domain is one of the top-level areas your OnCoor environment is divided into — the same areas you switch between elsewhere in OnCoor, such as Conversion or Center of Excellence. Each domain holds its own data. (Data domains sit above Enterprise Objects like Material Data or Customer Data, which live inside a domain.) A data domain policy decides whether AI is switched on for a domain and how it behaves there: which models it uses, how it treats sensitive personal information, and how long it keeps a record of what it did.

Because different data has different sensitivity, every domain gets its own policy. AI might be perfectly fine for one set of data and completely off-limits for another — the policy is how you draw that line. Out of the box, AI is switched off for every domain until you create a policy and turn it on.

What you can do here

  • Switch AI on or off for a domain, and control each AI feature individually.
  • Set the default models the domain uses for its AI work.
  • Decide how personal information (like names or emails) is handled.
  • Choose what gets logged, and how long those logs are kept.

WHERE TO FIND IT — Data domain policies live under Admin → AI → Configuration → Domain Policies. Adding one opens the Configure AI for Data Domain screen.


2. Key Concept: One Policy Per Data Domain​

Each data domain can have exactly one AI policy. When you add a policy, you pick from the domains that don't already have one — a domain that's already set up won't appear in the list.

That single policy is what OnCoor checks every time it's asked to do something with AI in that domain. If AI isn't switched on for the domain, nothing happens — no matter what any other setting says.

Rule of thumb: set up a policy for a domain the first time you want to use AI there. After that, you edit the same policy to change how AI behaves.


3. Finding Your Way Around​

Go to Admin → AI → Configuration → Domain Policies. This lists the domains that already have an AI policy. From here you can edit an existing policy or add one for a new domain.

Adding or editing a policy opens the Configure AI for Data Domain screen, which is organised into four groups:

  • Feature toggles — what AI is allowed to do in this domain.
  • Default models — which models the domain uses.
  • Privacy & logging — how personal information and record-keeping are handled.
  • Retention overrides — how long records are kept.

The rest of this guide walks through each group.


4. Turning AI On for a Domain​

The feature toggles decide what AI is allowed to do in the domain.

Steps

  1. Go to Admin → AI → Configuration → Domain Policies.
  2. Click to add a policy (or edit an existing one).
  3. Choose the Data Domain from the list.
  4. Set the toggles you want (see the table below).
  5. Fill in the remaining groups as needed, then Save.
ToggleWhat it controls
AI EnabledThe master switch for the whole domain. If this is off, none of the AI features work here, whatever the other toggles say. Turn this on first.
Embedding EnabledAllows record-matching features, such as Cognitive De-Duplication.
RAG EnabledAllows chat-style question answering against this domain's data. (RAG is the technology behind the chat feature.)
Suggestions EnabledAllows AI suggestions, such as suggested column mappings.

EVERYTHING STARTS OFF — A brand-new domain policy has every feature switched off. Turn on AI Enabled first — it's the master switch the others depend on — then switch on just the features you actually want.


5. Choosing the Default Models​

Each domain can have a default model for each kind of AI work. These are the models OnCoor reaches for automatically when it does something with AI in this domain.

SettingWhat it's for
Embedding ModelThe default model for record-matching in this domain (used, for example, when OnCoor sets up the domain's starting project).
Generation ModelThe default model for chat answers and suggestions in this domain.

You pick from the models you've already switched on in the Models tab. Leave a setting on — None — if you don't want to preset one.

NEED TO SET UP A MODEL FIRST? — Only models you've switched on appear in these lists. See the AI Providers guide for connecting a provider and switching on its models.


6. Privacy and Logging​

AI works by sending your data to a model to be processed. These settings control what happens when that data contains personal information — details that could identify a person, such as names, emails, or phone numbers (often called "PII") — and what OnCoor keeps a record of.

The most important setting here is PII Handling Mode, which decides what OnCoor does when it spots personal information in something about to be sent to AI:

ModeWhat happens when personal information is found
Fail (recommended)The AI request is stopped. Nothing containing personal information is sent anywhere. This is the safest choice and the default.
RedactThe personal information is blanked out — for example, an email address becomes <EMAIL> — and only the cleaned-up text is sent.
Drop silentlyThe piece of content that contains personal information is quietly left out, and the request carries on without it.

The remaining privacy and logging settings:

SettingWhat it controls
Allow PII in EmbeddingsWhether personal information is allowed into the record-matching data. Off by default.
Allow Cross-Domain SearchWhether this domain's AI may look at data belonging to other domains. Off by default — each domain stays separate unless you allow it.
Log PromptsWhether the text sent to the AI is saved so it can be reviewed later. On by default.
Log ResponsesWhether the AI's replies are saved so they can be reviewed later. On by default.

THE SAFE DEFAULTS — Out of the box, OnCoor takes the cautious path: personal information stops a request (Fail), data stays inside its own domain, and no personal information goes into matching data. Change these only when you understand the trade-off. Saved prompts and responses hide sensitive content by default; the full original is available only to a designated compliance reviewer.


7. How Long Records Are Kept​

OnCoor keeps three kinds of record of AI activity, each with its own lifespan. Leave a field blank to use OnCoor's built-in default; enter a number of days only if this domain needs something different.

Record typeWhat it holdsBuilt-in default
Audit LogThe prompts sent and the responses receivedAbout 730 days (2 years)
Usage LogA summary of each request — the model used, the amount of text, the estimated costAbout 365 days (1 year)
Retrieval LogThe data pulled in to help answer a questionAbout 180 days

LEAVE BLANK FOR DEFAULTS — If you don't enter a number, OnCoor keeps records for the built-in periods shown above. Only enter a value when this domain has a specific reason to keep records for a longer or shorter time.


8. Quick Reference​

A fast lookup for the most common actions.

I want to…Do this
Turn AI on for a domainDomain Policies → Configure AI for Data Domain → pick the domain → AI Enabled = Yes → Save
Allow duplicate-matching in a domainSet Embedding Enabled = Yes
Allow chat answers in a domainSet RAG Enabled = Yes
Allow AI suggestionsSet Suggestions Enabled = Yes
Set the domain's default modelsChoose an Embedding Model and a Generation Model
Keep personal information out of AI entirelyLeave PII Handling Mode on Fail (the default)
Send cleaned-up data instead of blocking itSet PII Handling Mode to Redact
Stop a domain seeing other domains' dataLeave Allow Cross-Domain Search = No (the default)
Change how long logs are keptEnter day counts under Retention overrides

Source: OnCoor AI Module product documentation, written for end users. For the latest screens and options, always refer to the in-app interface.