| Sensitive-data protection inventory | Systems, fields, classifications, owners, purposes, flows, environments, and exposure points | What must be protected first |
| Technique decision matrix | Use-case criteria, reversibility, utility, risk, performance, and regulatory considerations | Mask, tokenize, synthesise, encrypt, or restrict |
| Target control architecture | Transformation points, token service, vault, key management, access, logging, resilience, and interfaces | How the control will operate safely |
| Rule catalogue | Field-level rules, formats, deterministic domains, exceptions, test cases, owners, and approval status | How protection remains consistent |
| Validation and risk report | Coverage, utility, integrity, leakage checks, performance, residual risks, and limitations | Whether release criteria are met |
| Operating model and runbook | Roles, access reviews, change control, incidents, evidence, metrics, onboarding, and support | Who owns and sustains the service |