kosa8 docs

Commands / kosa8 label relabel

kosa8 label relabel

Change a sandbox's classification (lowering it needs signed approvals)

Usage

kosa8 relabel SANDBOX LABEL

Raising a label is allowed: it only narrows where the sandbox's data may go. Lowering it, or moving it sideways (CUI//SP-EXPT to CUI//SP-PRVCY), needs a signed approval request for exactly that move, approved by as many distinct people as the label policy asks (two by default):

kosa8 approve request --reason "..." relabel SANDBOX FROM TO kosa8 approve sign REQUEST --reason "..." (each approver) kosa8 label relabel SANDBOX TO --request REQUEST

Write UNLABELLED for no label. The relabel, the approvers' names and the signed records go in the audit log. Snapshots already taken keep their label.

Options

FlagTypeWhat it doesDefault
--requeststringthe approved request (id or file) authorizing a downgrade—