Skip to content

Multi-Department Setup Guide

Learn how to configure Zotniq for multi-department deployments within your organization.

SDK v1 note

Some examples on this page reference the legacy client.with_policy_group() method that shipped in an earlier SDK. The v2 team architecture makes policy groups obsolete — mint one team API key per department instead and pass the correct key to each Zotniq(api_key=...) call. The narrative on this page is being rewritten for the team-key model.


Overview

Zotniq supports a hierarchical structure for managing different departments with different policies:

Your Organization
├── License (zot_lic_xxx)
├── Policy Groups (Departments)
│   ├── Engineering
│   ├── Marketing
│   ├── Sales
│   └── Default
└── Policies
    ├── Engineering Policy (strict secrets blocking)
    ├── Marketing Policy (allow masked PII for analytics)
    └── Sales Policy (mask financials, allow names)

Multi-org management

Managing multiple separate companies under one account isn't a self-service feature today. Contact sales if you need it and we'll scope what's possible.


Policy Groups (Departments)

Policy groups allow different departments to have different rules under the same organization license.

Use Cases

Department Policy Focus
Engineering Strict API secret blocking
Marketing Allow masked PII for analytics
Legal Block all sensitive data
Sales Allow customer names, mask financials

Creating Policy Groups

Via Dashboard:

  1. Go to Organization → Settings → Policy Groups
  2. Click Create Policy Group
  3. Configure rules for this group

Via SDK:

from zotniq import Zotniq

# Initialize with org license
zotniq = Zotniq(api_key="zot_lic_xxx")

# Create instances for different departments
engineering = client.with_policy_group("engineering")
marketing = client.with_policy_group("marketing")
sales = client.with_policy_group("sales")

# Each uses department-specific rules
eng_result = engineering.check(content, "AI_TOOL")
mkt_result = marketing.check(content, "AI_TOOL")

Organization Settings

Data Region

Configure where data is processed for compliance:

Region Data Center Compliance
US Virginia SOC2, HIPAA
EU Frankfurt GDPR, SOC2
APAC Singapore SOC2

Data region + retention

retention_mode is configurable on every org today (FULL vs METADATA). Data-region selection (EU vs US vs APAC) is not a self-service toggle yet — contact sales if you have a residency requirement.


Policies Per Department

Create department-specific policies:

Engineering Policy

{
  "name": "Engineering Policy",
  "tags": ["engineering", "strict"],
  "rules": [
    {
      "name": "Block All Secrets",
      "dataTypes": ["API_SECRETS"],
      "destinations": ["AI_TOOL", "VENDOR", "CUSTOMER"],
      "action": "BLOCK"
    },
    {
      "name": "Mask PII for AI",
      "dataTypes": ["PII"],
      "destinations": ["AI_TOOL"],
      "action": "MASK"
    }
  ]
}

Marketing Policy

{
  "name": "Marketing Policy",
  "tags": ["marketing", "analytics"],
  "rules": [
    {
      "name": "Allow Masked Email",
      "dataTypes": ["PII"],
      "destinations": ["VENDOR"],
      "action": "MASK"
    },
    {
      "name": "Block Financial Data",
      "dataTypes": ["FINANCIAL"],
      "destinations": ["AI_TOOL", "VENDOR"],
      "action": "BLOCK"
    }
  ]
}

SDK Configuration

Single Organization

import os
from zotniq import Zotniq

# Use license key from org settings
zotniq = Zotniq(api_key=os.environ["ZOTNIQ_API_KEY"])

Multi-Department

# Initialize with license
zotniq = Zotniq(api_key="zot_lic_xxx")

# Get department-specific instances
def get_client_for_user(user):
    """Get Zotniq instance based on user's department."""
    department = user.department  # e.g., "engineering"
    return client.with_policy_group(department)

# Usage
user_client = get_client_for_user(current_user)
result = user_client.preflight.check(content, destination="AI_TOOL")

Environment-Based Configuration

import os
from zotniq import Zotniq

# Different configs for different environments
config = {
    "development": {
        "api_key": os.environ.get("ZOTNIQ_DEV_API_KEY"),
        "policy_group": "dev",
    },
    "staging": {
        "api_key": os.environ.get("ZOTNIQ_STAGING_API_KEY"),
        "policy_group": "staging",
    },
    "production": {
        "api_key": os.environ.get("ZOTNIQ_PROD_API_KEY"),
        "policy_group": "production",
    },
}

env = os.environ.get("ENVIRONMENT", "development")
zotniq = Zotniq(**config[env])

API Keys Per Policy

Each policy has its own API key for direct API access:

# Engineering team uses their policy's API key
curl -X POST .../api/preflight/text \
  -H "X-Zotniq-API-Key: zot_sk_engineering_key" \
  -d '{"text": "...", "destination": "AI_TOOL"}'

# Marketing team uses their policy's API key
curl -X POST .../api/preflight/text \
  -H "X-Zotniq-API-Key: zot_sk_marketing_key" \
  -d '{"text": "...", "destination": "VENDOR"}'

License Management

License Hierarchy

Organization
└── License (zot_lic_xxx)
    ├── Policy Group: engineering
    │   └── Policies: [Engineering Policy]
    ├── Policy Group: marketing
    │   └── Policies: [Marketing Policy]
    └── Policy Group: default
        └── Policies: [Default Policy]

License Types

Current tiers and limits live at zotniq.ai/pricing; they change more often than this page does. Enterprise scoping is case-by-case — contact sales.

License Revocation

Revoking a license deactivates all associated policies:

# Revoke license (cascades to policies)
curl -X DELETE .../api/orgs/{org_id}/licenses/{license_id}

Analytics Per Organization

View analytics for specific organizations:

# Organization analytics
GET /api/orgs/{org_id}/analytics?period=30d

# Platform-wide analytics (admin only)
GET /api/analytics?period=30d

Dashboard Views

  • Organization Dashboard: Metrics for single org
  • Platform Dashboard: Aggregated metrics across all orgs

Best Practices

1. Use Consistent Naming

Organization: "Acme Corp"
Slug: "acme"
Policy Groups: "engineering", "marketing", "sales"
Policies: "acme-engineering-v1", "acme-marketing-v1"

2. Separate Dev and Prod

Create separate organizations or policy groups for environments:

# Development
dev_client = Zotniq(license_key="zot_lic_dev_xxx")

# Production
prod_client = Zotniq(license_key="zot_lic_prod_xxx")

3. Audit Trail

All checks are logged with organization context:

{
  "preflight_id": "pf_xxx",
  "org_id": "acme",
  "org_name": "Acme Corp",
  "policy_name": "Engineering Policy",
  "decision": "BLOCKED"
}

4. Regular Policy Review

  • Review policy effectiveness monthly
  • Check detection analytics for gaps
  • Update rules based on new data types

See Also