What golden-benchmark detection controls measure
Detection controls keyed to golden-dataset recall (such as cardholder-data detection) reflect the platform's measured benchmark accuracy, not your tenant's own traffic.
Prerequisites
What these controls measure
- Some detection controls (for example, cardholder-data detection) pass based on the platform's MEASURED recall against curated golden datasets, computed at release build time and embedded in the shipped software.
- A pass means the shipped classifier demonstrably detects that data class at or above the release threshold. It does not mean the control examined your tenant's own traffic.
- The same attested numbers apply to every tenant running that release: the control is a platform capability attestation, not a per-tenant traffic risk signal.
What to check for your own traffic
- Per-tenant detection activity lives in Risk Signals and the session timeline: what was actually inspected, detected, and enforced in your environment.
- If a benchmark-keyed control passes but your Risk Signals show no detections, that usually means the relevant data class has not appeared in governed traffic — not that detection is broken.
Validate
- Benchmark-keyed controls identified in your framework view
- Provenance understood: platform benchmark, not tenant traffic
Next steps
- Review the evidence-truth article for the full evidence-state model