# Data Masking

> Data masking  gives your organization the ability to better protect customer privacy by minimizing access to sensitive data.

Source: https://help.kustomer.com/en_us/data-masking-S1ezaXhgc

Last updated: 2026-05-20T22:24:54.657Z

Data masking helps your organization protect customer privacy by limiting access to sensitive data. Kustomer lets admins choose which standard and custom attributes should be masked, then control which users, roles, or teams can view the unmasked values.

This helps minimize accidental exposure of private data while still giving agents the information they need to support customers.

## Who can access this feature?

Admins can access data masking settings and configure masked attributes.

## In this article

*   [What is data masking?](#what-is-data-masking)
*   [Why use data masking?](#why-use-data-masking)
*   [How data masking works](#how-data-masking-works)
*   [Where data is and is not masked](#where-data-is-masked)
*   [Full vs. partial masking](#full-vs-partial-masking)
*   [Data masking settings](#data-masking-settings)
*   [Set up masked attributes](#set-up-masked-attributes)
*   [Configure permission sets](#configure-permission-sets)
*   [Temporary access to unmask data](#temporary-access-to-unmask-data)
*   [Customize the unmasking widget](#customize-the-unmasking-widget)
*   [Sensitive data edge cases](#sensitive-data-edge-cases)
*   [Interactions with other features](#interactions-with-other-features)
*   [Appendix: data masking and the Kustomer Apps Platform](#appendix-data-masking-and-the-kustomer-apps-platform)

## What is data masking?

Data masking, also known as data obfuscation, is the process of hiding sensitive information from users who are not authorized to view it.

Sensitive data can include personally identifiable information (PII), such as:

*   Names
*   Email addresses
*   Phone numbers
*   Physical addresses
*   Dates of birth
*   Social Security numbers
*   Account identifiers
*   Any data that can identify a person on its own or when combined with other information

Data masking should not be confused with [message redaction](https://help.kustomer.com/message-options-H1tSk3QOI#Redaction).

*   **Data masking** hides sensitive data from specific users, roles, or teams. The data remains in Kustomer.
*   **Message redaction** permanently removes information from the platform.

## Why use data masking?

Data masking helps your organization reduce privacy and security risk by limiting access to sensitive data on a need-to-know basis.

For example, your organization may want agents to verify a customer's phone number without showing the full number, or may need to limit access to PII for compliance reasons.

Because each organization's data security needs are different, Kustomer lets admins decide which attributes should be masked and which users should be allowed to view them.

## How data masking works

Admins configure data masking on individual attributes in **Settings > Platform > Klasses**.

When editing an attribute, admins can select **Mask the data in this attribute**. The attribute editor shows a preview of how the masked value will appear to users without permission to view unmasked data.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/e2301029ae0e6545d127b0ee39ed7035.png)

Admins can then use permission sets to control which users or teams have access to view masked data using the **Read Unmasked** checkbox, much in the same way you'd control a team's _Read_ or _Edit_ access. Learn more about using attribute permissions in [Attribute level permissions](https://help.kustomer.com/en_us/attribute-level-permissions-S1v2afL1v).

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/d0d845c37297617b00e8af14809bda22.png)

Authorized users will have normal access to viewing and searching Klass attributes. However, users without the correct field-level permissions access will see that the customer's sensitive information is obscured with asterisks, along with a **Masked** badge to indicate that data is being masked.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/7e0b7079b5ac4c1ab5ff551c5bb245a6.png)

## Where data is masked

Data is masked for unauthorized users in areas such as:

*   Standard and custom object views, including customers, conversations, companies, and KObjects
*   The customer timeline
*   Customer details and currently viewed panels
*   Browser tab or window titles
*   Insights details, cards, and panels
*   Attribute edit modals
*   Search results for customers, conversations, companies, and KObjects
*   API responses for standard and custom objects
*   Audit log object names, where applicable

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/713ac7bd85f63ca22590b06f52c27c42.png)

## Where data is not masked

Data masking may not apply to every surface or workflow. Be especially careful with features that process, export, or transmit data outside the normal object UI.

Data masking does not necessarily prevent exposure through:

*   Automations, including business rules, queues and routing, and workflows
*   Conversational assistants
*   Reporting
*   Data exports
*   Dynamic text
*   Some apps or custom integrations

Users who can create automations or exports may be able to indirectly access sensitive data by sending it to external systems or exporting it.

Review permission sets carefully before granting access to automations, reporting, exports, or app configuration.

## Full vs. partial masking

Attributes can be fully masked or partially masked.

**Full masking** hides the entire value. Fully masked values display as:

`********************`

**Partial masking** shows only a limited portion of the value. Current examples include:

Attribute type

Example masked value

Email

`****************.com`

Phone

`****************9210`

Partial masking is available only for supported standard attributes. Current configuration examples include customer emails, shared emails, phones, shared phones, and company emails and phones.

Email partial masking preserves the domain suffix, such as `.com` or `.org`, and phone partial masking preserves the last 4 digits.

### Data masking settings

Go to **Settings > Security > Sensitive Data Protections** to view the in-app data masking setup page.

The setup page includes steps to:

1.  Set up masked attributes
2.  Configure permission sets
3.  Customize temporary access
4.  Customize the unmasking widget

The temporary access setting controls how long masked data remains visible after a user requests access. The default is **24 hours**, and admins can set a value from **1 to 72 hours**.

### Set up masked attributes

To mask data in an attribute:

1.  Go to **Settings > Platform > Klasses**.
2.  Select the pencil icon next to the Klass you want to edit.
3.  Locate the attribute you want to mask.
4.  Select the pencil icon to open the attribute editor.
5.  Select **Mask the data in this attribute**.
6.  Choose **Partially Mask** or **Fully Mask**, if both options are available.
7.  Review the preview.
8.  Select **Save Changes**.

Repeat these steps for each attribute you want to mask.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/093e3fb2569e2335ca01a65423fefe10.png)

You can review an attribute's masking status in the attributes list.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/f6134c39443f261b5e87d7c8aeb16349.png)

### Temporary access to unmask data

Admins can allow users to request temporary access to masked customer data.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/146809129682fa83d5b054a3edd54cb8.png)

When this permission is enabled, users without regular access to unmasked data can request temporary access while supporting a customer. Temporary access events are recorded in the audit log.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/6bc18db8e263ddce5495f87a3f49c2bc.png)

If the agent proceeds, the customer's data will be unmasked temporarily. The **Masked** badge will change color and be labeled **Unmasked**, and users can hover on the badge to see how much time remains in the temporary access period.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/c7469487e60340ab16730bab8c9ec62b.png)

To review all unmasking events, go to **Settings![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/4a20a66b5a965fc5f9000b784a396921.png)** and select **Security > Audit Log**.

![](https://cdn.kustomerhostedcontent.com/media/570fad9d9001bc1000163b28/3a9707f6e6cc127fe231959ffeb016da.png)

## Customize the unmasking widget

Admins can customize the authentication widget that appears when a user requests temporary access to masked data.

This option appears in the Data Masking setup page as:

**Customize Unmasking Widget**

The setting lets admins choose a custom auth widget instead of the default modal.

## Sensitive data edge cases

Kustomer includes powerful automation and customization features. Some of these features can reference, transform, export, or transmit data. Admins should understand these edge cases before granting access to users who should not otherwise view sensitive data.

### Dynamic text

Dynamic text can expose sensitive data if it references masked attributes.

For example, an admin with access to unmasked customer data might insert dynamic text into a reply or note. When the message is sent, the dynamic text resolves to plain text. That plain text may then be visible to users who would not otherwise have permission to view the underlying masked attribute.

Users with access to unmasked data should avoid inserting sensitive values through dynamic text unless they intend for that data to be visible.

### Automations

Users with access to automation tools may be able to indirectly access masked data.

This includes features such as:

*   Business rules
*   Queues and routing
*   Workflows
*   REST API actions
*   Email forwarding and templates

Review automation permissions carefully for users who should not have access to sensitive data.

### Conversational assistants

Conversational assistants can use customer, conversation, and KObject attributes in messages shown to end users.

If a conversational assistant is configured to include sensitive masked attributes, those values may later appear in the customer timeline when an agent takes over the conversation.

Avoid using masked attributes in assistant messages unless that exposure is intentional.

### Exports

Exports can expose data outside Kustomer.

Review export permissions carefully, especially for users who should not have access to sensitive data. This includes exports from Search, Reporting, and Scheduled Reports.

## Interactions with other features

### Conditional attributes

Conditional attributes can require agents to complete fields before marking a conversation as done.

Before requiring a masked attribute, confirm that the affected agents have the access they need. Otherwise, agents may be unable to complete the required field or mark the conversation as done.

### Undefined or empty values

If an attribute uses partial masking but the value is empty, null, or undefined, Kustomer cannot meaningfully show a partial value.

In those cases, unauthorized users see a fully masked value instead. Backend tests confirm that null and undefined values are fully masked for read-only users, including partial-mask scenarios.

## Appendix: data masking and the Kustomer Apps Platform

Data masking can affect apps and custom integrations.

Apps and integrations that display Klass attributes should be reviewed to make sure they handle masked values correctly. Fully or partially masked values may be returned instead of the original data when the requesting user does not have permission to view unmasked values.

If your organization has custom apps, Klass Views, or Cards SDK customizations, review them for compatibility with masked attributes. Custom integrations should avoid assuming that a sensitive attribute will always be returned as a raw string.
