---
title: "Curator: records and retention management on DataXray"
description: "Curator turns DataXray discovery into defensible records management: change detection, alerts, retention, disposition, and capture, all under an audit trail."
url: "https://www.dataxray.io/modules/curator/"
language: "en-US"
---

1. [Home](https://www.dataxray.io/)
2. [Modules](https://www.dataxray.io/platform/)
3. Curator

Modules / Curator

# Records management you can defend

Curator turns what DataXray has already found into a working records program. It flags what changed, suggests what to keep, and sends declared records to accredited systems. Every step is logged in a tamper-evident audit trail.

[Book a demo](https://www.dataxray.io/demo/)

[All modules](https://www.dataxray.io/modules/)

What it makes possible

## Know what to keep, and where it sits

Records managers must run an active, continuing program while modern mandates require records to be kept electronically. Curator turns what DataXray finds into the decisions and actions that program requires.

- Other records tools depend on people declaring records by hand. Curator starts from the files DataXray has already discovered and classified across the estate.
- Rules flag stale or duplicate files, sensitive data in open folders, and controlled material outside its allowed location, on estates of hundreds of millions of files.
- Curator suggests a retention schedule for each file, then governs cutoff and disposition once a records manager declares the record.

## The records pipeline

Configured to how you work. Your alert rules, retention schedules, and routing targets are set up around your records program. If you need something Curator doesn't do yet, we can build it with you.

1. ### Capture

   Harvest snapshots of DataXray's file index and raise alerts on what changed.
2. ### Alerts

   Triage detections into a staging queue for a records historian.
3. ### Reports

   Suggest a retention schedule for each file.
4. ### Declare

   A records manager declares each record, and its retention and cutoff are governed from then on.
5. ### Transfer

   Move declared records into an accredited system of record.

Change detection

## Alerts follow the rules you set

With the Curator module, you can compare each new DataXray scan with the last one and turn the differences into events. Nothing is missed or counted twice, and DataXray’s own scans run as normal.

You decide which changes become alerts, and each rule has its own threshold, severity, and escalation contact. Rules can cover:

- files added, deleted, or moved
- sensitive data in open folders
- access or sharing changes on sensitive content
- restricted file types outside their allowed location
- stale or duplicate files

Capabilities

## Curator handles retention, markings, and routing per file

Curator works on everything DataXray has indexed, not only files that already carry a classification. DataXray's classifications and location rules decide which retention schedule each file is proposed for, and anything that matches no rule lands in an unfiled view.

- **Retention and policy engine**

  Suggest and apply retention schedules per file, then govern cutoff and disposition on the records you declare.
- **Classification and CUI marking**

  Controlled Unclassified Information (CUI) and other controlled-data markings travel through the pipeline, so records are handled according to their sensitivity rather than guesswork.
- **Accredited routing**

  Each record routes to the system of record accredited for all of its controlled labels. Routing fails closed, so a marking with no accredited target is blocked and never silently defaulted.
- **Copy or manage in place**

  Choose whether the authoritative record is a copy captured into the system of record or a governed pointer to the file where it already lives.
- **Immutable audit trail**

  A hash-chained audit log, role-based access with clearance, and encryption at rest, so every action is attributable and tamper-evident.
- **Air-gap ready**

  Curator runs as a single container with no telemetry, one instance per network. It deploys on-premises first and is sized for estates of hundreds of millions of files.

Regulated recordkeeping

## Records managers see how up to date their view is

Curator is positioned to support modern electronic records mandates and defense records-management standards. It picks up each change at DataXray's next scheduled scan, and the interface shows when each change was detected.

## Frequently asked questions

### What is Curator?

Curator is a DataXray module for records and retention management. It handles change detection, alerts, retention scheduling, disposition, and records capture into accredited systems of record.

### Do I need DataXray to use Curator?

Yes. Curator is a module, and it runs on the files DataXray has already read and classified, so no file is read twice.

### Can it be configured to our needs?

Yes. Your alert rules, retention schedules, and routing are set up around your records program. If you need something it doesn't do yet, talk to us.

### Does it run in air-gapped or classified environments?

It runs wherever DataXray runs, including air-gapped networks.

### How does Curator detect change without webhooks?

Curator uses a gentle, partitioned, resumable, and rate-limited harvester. It snapshots each data source and diffs successive snapshots into events, without disrupting DataXray's scheduled scans.

### What kinds of changes can it alert on?

Configurable rules cover files that are added, deleted, or moved, sensitive data in an open folder, and restricted file types outside their allowed location. They also cover access-control drift on sensitive content, sharing or protection changes, and stale or duplicate files.

### Where do declared records go?

Each record routes to the system of record accredited for all of its controlled labels. Routing fails closed, so a marking with no accredited target is blocked rather than silently defaulted.

### How is it deployed?

Curator runs as a single container with no telemetry, one instance per network. It deploys on-premises first and is sized for estates of hundreds of millions of files.

The other modules

## Built on every file DataXray has already read

Modules extend the DataXray platform into the workflows customers ask for most. Each one runs on files DataXray has already read and classified, so no file is read twice. Every module is configured to fit how your team works.

- **[AI Platform](https://www.dataxray.io/modules/ai-platform/)**

  Let AI assistants use your files safely, within each user's permissions.
- **[Compass](https://www.dataxray.io/modules/compass/)**

  Explore what is in your data and build the taxonomy to govern it.
- **[Curator](https://www.dataxray.io/modules/curator/)**

  Manage retention, disposition, and records capture, with every decision logged in a tamper-evident audit trail.
- **[AutoFOIA](https://www.dataxray.io/modules/autofoia/)**

  Take FOIA and Privacy Act requests from intake to a redacted, Bates-numbered release.
- **[eDiscovery](https://www.dataxray.io/modules/ediscovery/)**

  Review, redact, and produce documents for litigation, regulatory, and privacy requests without exporting them.

**[Curator](https://www.dataxray.io/modules/curator/)**

Manage retention, disposition, and records capture, with every decision logged in a tamper-evident audit trail.

[Learn more about modules](https://www.dataxray.io/modules/)

## In 30 minutes, see how DataXray reads what other tools only label

[Book a demo](https://www.dataxray.io/demo/)
