Skip to main content

Data Classification β†’ Nextcloud handling tiers

The browser-first BYOD workplace protects application access well and data-after-download barely β€” the known trade-off (see the Workplace Architecture principle). This page closes the top data-layer gap: a data-classification model enforced as concrete Nextcloud handling tiers, so sensitive corporate information stays server-side. It is direct DORA / GDPR evidence (a control that limits data egress from an unmanaged endpoint).

The three tiers (mapped to the existing P0–P3 data classes)​

TierFrom P-classMeaningHandling
INTERNALP0 (public) + P1 (internal)day-to-day corporate contentdownload OK Β· internal share OK Β· no public/anonymous share
CONFIDENTIALP2business-sensitive (risk reports, contracts)browser-preferred Β· download restricted where feasible Β· no public/anonymous/federated share Β· internal share only
RESTRICTEDP3 (PII / regulated / privileged)claims, financial, legal, sanctions, execWEB-ONLY Β· download DENIED Β· no sync Β· no share beyond an explicit grant Β· short session + strong MFA (Authentik) Β· watermark Β· audited

Insurance data β†’ tier (the worked mapping)​

Public documentation β†’ INTERNAL Β· Risk-Engineering reports β†’ CONFIDENTIAL Β· Claims documents β†’ RESTRICTED Β· Financial / legal / sanctions β†’ RESTRICTED.

How Nextcloud enforces each tier (real mechanisms, NC 33)​

Classification is a restricted system tag (INTERNAL / CONFIDENTIAL / RESTRICTED) β€” only admins / the DLP flow may assign it, so a user can't down-classify their own file. Enforcement:

ControlApp / settingApplies to
Web-only document experience β€” no download/print/copy + watermarkOnlyOffice Secure View (the real "web-only" for office docs, which is the bulk of content)RESTRICTED
No public / anonymous / federated share on sensitive dataglobal sharing guardrails (applied: password + 30-day expiry enforced, federated off) + the "never publicly share RESTRICTED/CONFIDENTIAL" policyCONF + RESTRICTED
Access gate β€” RESTRICTED files only reachable by the authorised groupfiles_accesscontrol rule: tag = RESTRICTED AND user βˆ‰ restricted-group β†’ deny access. NB: this denies access entirely (it is binary β€” it cannot "allow view but block download"); pair it with the tight Group-Folder ACL.RESTRICTED
Space isolation + ACL (deny reshare on Restricted)Group Folders (Corporate / Department / Project / Restricted) β€” scriptable via occ groupfolders:*all
Session / MFA / step-upAuthentik (not Nextcloud) β€” short session + re-auth for RESTRICTED appsRESTRICTED
Auditadmin_audit β†’ log β†’ the unified SOC plane (Authentik + app + Falco)all
Auto-classify / Retention (optional)files_automatedtagging (tag by folder) Β· files_retention (by tag)all

Honest limit (matches the reference's own Β§24). Nextcloud cannot natively "allow browser view but block download" for an arbitrary file β€” that granularity doesn't exist. The strong, layered controls are: OnlyOffice Secure View (web-only for documents β€” the main content type), no public link for sensitive tags, a tight Restricted Group-Folder ACL, audit, and β€” for the truly sensitive minority β€” the VDI / browser-isolation sensitive-workforce tier. Full download-proofing of any binary is not a config toggle; it's the VDI tier.

Space architecture (Group Folders)​

Nextcloud
β”œβ”€β”€ Corporate Files (all staff Β· INTERNAL)
β”œβ”€β”€ Department Spaces (per Direction group Β· CONFIDENTIAL default)
β”œβ”€β”€ Project Spaces (project groups)
└── Restricted Spaces (RESTRICTED Β· web-only Β· tight ACL Β· audited)

Permission = group + role + folder + classification (never "authenticated β‡’ everything").

Global sharing hardening (applied 2026-09-30 β€” "restrict with guardrails")​

Independent of tags. Chosen posture: keep public links possible but controlled (an insurer has legitimate broker/vendor sharing). Applied: public links require a password + an enforced 30-day expiry; auto-accept of external shares off; federated (server-to-server) sharing disabled. A pre-change audit showed 0 existing shares, so nothing broke. Employee login access from the internet is unaffected β€” this only governs anonymous share-links, never authenticated access.

Implementation β€” what's APPLIED vs remaining​

Applied live 2026-09-30 (via occ):

NC(){ kubectl exec -n nextcloud deploy/nextcloud -c nextcloud -- php occ "$@"; }
NC app:install files_accesscontrol ; NC app:install groupfolders # engines
NC tag:add INTERNAL restricted ; NC tag:add CONFIDENTIAL restricted ; NC tag:add RESTRICTED restricted
# global sharing guardrails (audit first showed 0 existing shares β†’ nothing broke):
NC config:app:set core shareapi_enforce_links_password --value=yes # public links MUST have a password
NC config:app:set core shareapi_enforce_expire_date --value=yes # expiry mandatory
NC config:app:set core shareapi_expire_after_n_days --value=30
NC config:app:set core shareapi_auto_accept_share --value=no
NC config:app:set files_sharing outgoing_server2server_share_enabled --value=no # federated off
NC config:app:set files_sharing incoming_server2server_share_enabled --value=no

Group-Folder spaces — scriptable (run when the department→group mapping is confirmed):

ID=$(NC groupfolders:create "Restricted Spaces") # returns the folder id
NC groupfolders:group "$ID" "Direction Sinistres" read write # grant the owning group
NC groupfolders:permissions "$ID" -e # enable advanced ACL, then deny reshare
NC groupfolders:quota "$ID" 50GB

Remaining β€” admin UI (see the walkthrough below):

  • files_accesscontrol rule (Settings β†’ Administration β†’ Flow β†’ Files access control β†’ Add new flow): condition File system tag is RESTRICTED [+ Group membership is not the authorised group] β†’ the rule denies access. (Access-control is binary β€” the web-only-view comes from OnlyOffice Secure View, below, not from here.)
  • OnlyOffice Secure View (Settings β†’ Administration β†’ ONLYOFFICE β†’ Secure view): enable restrict download / copy / print + a watermark (e.g. {userId} β€” RESTRICTED β€” {date}), scoped to the RESTRICTED tag/group. This is the real web-only document experience.

Verify / audit​

admin_audit logs every share/download/access with the Authentik identity β†’ who Β· when Β· where Β· app Β· action Β· resource. Feed it into the unified audit plane for the regulated-insurer trail. Test: tag a throwaway file RESTRICTED β†’ confirm (1) it opens in OnlyOffice with a watermark and no download button, (2) a non-authorised user gets access-denied, (3) a public link can't be made without a password + expiry.

Status (2026-09-30)​

βœ… Design + runbook Β· βœ… enforcement engines (files_accesscontrol, groupfolders) Β· βœ… classification tags (restricted) Β· βœ… global sharing guardrails (audit showed 0 shares β†’ safe). ⏳ Remaining (admin-UI, additive): the access-control rule + OnlyOffice Secure View; Group-Folder spaces (scriptable, pending the group mapping). Tracked on the Digital Workplace board (#10).