Reviewing Results After a Discovery
After the discovery process is complete, GEODI offers several ways to analyze the results: Reports, Dashboards, and Predefined Queries.
If any risky findings are detected, actions such as Secure Delete, Quarantine, or Masking should be considered to mitigate the risk.
How to Query Risky Findings
GEODI Discovery offers you numerous insights into the data. Compliance with PCI/DSS, KVKK, GDPR, or another national regulation and AI-based deep analysis for fraud, threat, and more...
predefined:PII → Selects all content that has PII info, that is, ID or Name, along with phone, address, blood type, etc.
predefined:PCI → Selects all content that has IBANs, CVVs, credit card numbers, and similar financial data.
(predefined:PCI OR predefined:PII) source:<Risky> → Now you select PII and PCI on a risk source, i.e., common file sharing.
(predefined:PCI OR predefined:PII) predefined:10Y → Content that has PII or PCI data and older that 10 years.
You write a GEODI Query like the ones above, take a report, look at a panel, or start remediation, such as deleting, masking, or quarantining. GEODI’s semantic queries give you razor-sharp targeting.
Risky information di
Querying Old Files
GEODI also provides queries for content older than a certain number of years:
predefined:O5Y
predefined:O10Y
predefined:O15Y
Combine with other filters for deeper insights:
predefined:O5Y predefined:PII
predefined:O5Y (predefined:PII veya predefined:PCI)
predefined:O5Y (predefined:PII veya predefined:PCI) source:<risky>
👥 User-Based Analysis
GEODI allows you to intersect queries by user or group, making it possible to analyze what a specific user can access:
user:<user|group>
user:<user|group> and source:<risky>
With the GEODI Access Management license, you can also report on and update user permissions via workflows.
🗃️ Duplicates and Deletion
Duplicates are a common issue and can disrupt workflows. GEODI helps identify original files, duplicates, and similar content:
Malicious Email Discovery:EMail Threat AI
This is a capability provided by GEODI Q and can be included in email discovery for PII or PCI purposes. After filtering out problematic emails, you can perform from/to and frequency analyses. The standard GEODI Discovery reports are sufficient.
https://support.decesoftware.com/space/geodien/5229150209/%F0%9F%92%A3%F0%9F%93%A7+Email+Threat+AI
🧠 GEODI Q – AI & LLM Integration
GEODI Q brings advanced AI capabilities to GEODI discovery:
Email Threat AI is just one sample.
Detects document types, fraud patterns, competition violations
Performs summarization, CV analysis, sentiment analysis, and flags offensive emails
🔍 Searching for Anything
Beyond predefined queries like PCI or PII, GEODI supports flexible keyword and rule-based searches:
🔗 Full Search Guide
This is especially valuable for Data Subject Access Requests (DSAR) under GDPR or KVKK. You can easily search for a person’s name, isolate internal content, and generate a content list report.
📊 Discovery Dashboard
GEODI includes a ready-to-use Discovery Panel, offering summarized insights driven by queries.
Accessible to system admins and ACC.Discovery group members. Only visible in projects where:
json
"GenericSettings": { "ACC.Discovery": true } The panel includes:
Finding Breakdown: e.g., number of PII IDs, how many VISA cards
Trend Analysis: See how findings evolve week by week (default: last 8 weeks)
Source Filtering: e.g.,
source:<Risky>shows counts by source
Reports
Queries affect not only dashboards but also reports and actions.
Examples:
Use
predefined:PIIto generate reports listing all relevant findingsUse duplicate queries to list all redundant files
Actions and Workflows
Queries can trigger actions—manually or as part of automated workflows.
Examples:
Use a duplicate query to securely delete files
Use
predefined:PIIto perform bulk masking
Actions can include:
Secure Delete
Quarantine
Masking
Send Email
Generate Report
Destructive actions and other operations that alter data often require user consent. For this purpose, GEODI offers a simple solution that involves data owners in the process.
📌 Other Predefined Queries
Predefined queries make complex or hard-to-remember rules easy to use.
Query | Purpose |
|---|---|
| Recognizes multiple currencies ($, €, £, SAR, etc.) |
| Covers over 10 CC types and test cards |
| Brings DB files like SQL Server, Oracle, SQLite, MDB |
| Finds video files |
| Finds image files |
| Web content, including email |
| Maskable content |
| Local-only content |
| GDE-fed content |
| PII-related content, adaptable to local rules |
| Religion |
| Ethnicity |
| Marital status |
| Health-related terms |
| Unions |
| Political views |
| Foundations |
| CV-related documents |
| Classifiable by tag |
| Classifiable by ADS rules |
| Source code files |
**