Data Classification β Nextcloud handling tiers
The browser-first BYOD workplace protects application access well and data-after-download barely β the known trade-off (see the Workplace Architecture principle). This page closes the top data-layer gap: a data-classification model enforced as concrete Nextcloud handling tiers, so sensitive corporate information stays server-side. It is direct DORA / GDPR evidence (a control that limits data egress from an unmanaged endpoint).
The three tiers (mapped to the existing P0βP3 data classes)β
| Tier | From P-class | Meaning | Handling |
|---|---|---|---|
| INTERNAL | P0 (public) + P1 (internal) | day-to-day corporate content | download OK Β· internal share OK Β· no public/anonymous share |
| CONFIDENTIAL | P2 | business-sensitive (risk reports, contracts) | browser-preferred Β· download restricted where feasible Β· no public/anonymous/federated share Β· internal share only |
| RESTRICTED | P3 (PII / regulated / privileged) | claims, financial, legal, sanctions, exec | WEB-ONLY Β· download DENIED Β· no sync Β· no share beyond an explicit grant Β· short session + strong MFA (Authentik) Β· watermark Β· audited |
Insurance data β tier (the worked mapping)β
Public documentation β INTERNAL Β· Risk-Engineering reports β CONFIDENTIAL Β· Claims documents β RESTRICTED Β· Financial / legal / sanctions β RESTRICTED.
How Nextcloud enforces each tier (real mechanisms, NC 33)β
Classification is a restricted system tag (INTERNAL / CONFIDENTIAL / RESTRICTED) β only
admins / the DLP flow may assign it, so a user can't down-classify their own file. Enforcement:
| Control | App / setting | Applies to |
|---|---|---|
| Web-only document experience β no download/print/copy + watermark | OnlyOffice Secure View (the real "web-only" for office docs, which is the bulk of content) | RESTRICTED |
| No public / anonymous / federated share on sensitive data | global sharing guardrails (applied: password + 30-day expiry enforced, federated off) + the "never publicly share RESTRICTED/CONFIDENTIAL" policy | CONF + RESTRICTED |
| Access gate β RESTRICTED files only reachable by the authorised group | files_accesscontrol rule: tag = RESTRICTED AND user β restricted-group β deny access. NB: this denies access entirely (it is binary β it cannot "allow view but block download"); pair it with the tight Group-Folder ACL. | RESTRICTED |
| Space isolation + ACL (deny reshare on Restricted) | Group Folders (Corporate / Department / Project / Restricted) β scriptable via occ groupfolders:* | all |
| Session / MFA / step-up | Authentik (not Nextcloud) β short session + re-auth for RESTRICTED apps | RESTRICTED |
| Audit | admin_audit β log β the unified SOC plane (Authentik + app + Falco) | all |
| Auto-classify / Retention (optional) | files_automatedtagging (tag by folder) Β· files_retention (by tag) | all |
Honest limit (matches the reference's own Β§24). Nextcloud cannot natively "allow browser view but block download" for an arbitrary file β that granularity doesn't exist. The strong, layered controls are: OnlyOffice Secure View (web-only for documents β the main content type), no public link for sensitive tags, a tight Restricted Group-Folder ACL, audit, and β for the truly sensitive minority β the VDI / browser-isolation sensitive-workforce tier. Full download-proofing of any binary is not a config toggle; it's the VDI tier.
Space architecture (Group Folders)β
Nextcloud
βββ Corporate Files (all staff Β· INTERNAL)
βββ Department Spaces (per Direction group Β· CONFIDENTIAL default)
βββ Project Spaces (project groups)
βββ Restricted Spaces (RESTRICTED Β· web-only Β· tight ACL Β· audited)
Permission = group + role + folder + classification (never "authenticated β everything").
Global sharing hardening (applied 2026-09-30 β "restrict with guardrails")β
Independent of tags. Chosen posture: keep public links possible but controlled (an insurer has legitimate broker/vendor sharing). Applied: public links require a password + an enforced 30-day expiry; auto-accept of external shares off; federated (server-to-server) sharing disabled. A pre-change audit showed 0 existing shares, so nothing broke. Employee login access from the internet is unaffected β this only governs anonymous share-links, never authenticated access.
Implementation β what's APPLIED vs remainingβ
Applied live 2026-09-30 (via occ):
NC(){ kubectl exec -n nextcloud deploy/nextcloud -c nextcloud -- php occ "$@"; }
NC app:install files_accesscontrol ; NC app:install groupfolders # engines
NC tag:add INTERNAL restricted ; NC tag:add CONFIDENTIAL restricted ; NC tag:add RESTRICTED restricted
# global sharing guardrails (audit first showed 0 existing shares β nothing broke):
NC config:app:set core shareapi_enforce_links_password --value=yes # public links MUST have a password
NC config:app:set core shareapi_enforce_expire_date --value=yes # expiry mandatory
NC config:app:set core shareapi_expire_after_n_days --value=30
NC config:app:set core shareapi_auto_accept_share --value=no
NC config:app:set files_sharing outgoing_server2server_share_enabled --value=no # federated off
NC config:app:set files_sharing incoming_server2server_share_enabled --value=no
Group-Folder spaces β scriptable (run when the departmentβgroup mapping is confirmed):
ID=$(NC groupfolders:create "Restricted Spaces") # returns the folder id
NC groupfolders:group "$ID" "Direction Sinistres" read write # grant the owning group
NC groupfolders:permissions "$ID" -e # enable advanced ACL, then deny reshare
NC groupfolders:quota "$ID" 50GB
Remaining β admin UI (see the walkthrough below):
files_accesscontrolrule (Settings β Administration β Flow β Files access control β Add new flow): condition File system tag is RESTRICTED [+ Group membership is not the authorised group] β the rule denies access. (Access-control is binary β the web-only-view comes from OnlyOffice Secure View, below, not from here.)- OnlyOffice Secure View (Settings β Administration β ONLYOFFICE β Secure view): enable
restrict download / copy / print + a watermark (e.g.
{userId} β RESTRICTED β {date}), scoped to the RESTRICTED tag/group. This is the real web-only document experience.
Verify / auditβ
admin_audit logs every share/download/access with the Authentik identity β who Β· when Β· where Β·
app Β· action Β· resource. Feed it into the unified audit plane for the regulated-insurer trail.
Test: tag a throwaway file RESTRICTED β confirm (1) it opens in OnlyOffice with a watermark and no
download button, (2) a non-authorised user gets access-denied, (3) a public link can't be made without a
password + expiry.
Status (2026-09-30)β
β
Design + runbook Β· β
enforcement engines (files_accesscontrol, groupfolders) Β· β
classification
tags (restricted) Β· β
global sharing guardrails (audit showed 0 shares β safe). β³ Remaining (admin-UI,
additive): the access-control rule + OnlyOffice Secure View; Group-Folder spaces (scriptable, pending the
group mapping). Tracked on the Digital Workplace board (#10).