pii_scan
Sweep string columns across tables for common PII patterns (email, SSN, credit card, phone, JWT, bearer tokens). Heuristic-only — not a compliance guarantee. [BUILD tier]
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| connection | No | Target connection name from this tenant's inventory. Call `list_connections` to see every name + dialect, then match semantically to the user's intent (e.g. 'analytics' → a connection named `*-analytics-*`; 'prod' → a connection with `prod-` prefix). If the user didn't specify, use the tenant's default (first added). Do not invent names — resolve from `list_connections` output. | |
| max_tables | No | Max tables to sample (default 25, cap 50) | |
| sample_rows | No | Rows sampled per table (default 20, cap 100; values < 5 are floored to 5) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| data | No | ||
| meta | No | ||
| display | No | ||
| summary | No | ||
| insights | No |