Feature Request: Trusted Message Recognition & Enhanced Security Classification Framework for INKY

Help the elimination of over stimulation of banners:

Executive Summary

Organizations receive many recurring emails from vendors, customers, financial institutions, healthcare providers, and business partners that may legitimately trigger caution banners. Over time, users learn which messages are trustworthy, but that knowledge is not currently leveraged within the INKY banner experience.

This proposal introduces:

  1. Community Trust Indicators ("Marked Safe" System)

  2. Five-Tier Security Banner Classification Model

  3. New Purple Classification for Sensitive Content

  4. Progressive Banner Color Changes Based on Trust Validation

  5. User, Group, Administrator, and Security Provider Trust Levels

The goal is to improve security awareness while reducing alert fatigue and helping users make better decisions.

1. Trusted Message Recognition System

Current Challenge

Many emails generate recurring caution banners despite being regularly validated by users.

Examples:

  • Banking notifications

  • Customer invoices

  • Vendor ACH requests

  • Payroll communications

  • Healthcare correspondence

  • Internal applications

Users eventually ignore banners because they see the same trusted message repeatedly.

This creates:

  • Banner fatigue

  • Reduced effectiveness of warning systems

  • Increased likelihood of users overlooking actual threats


Proposed Solution

Allow users to mark emails as:

βœ… "Safe"

INKY would then track:

  • Sender

  • Domain

  • Message characteristics

  • Similar email fingerprints

Future matching emails would display trust indicators directly in the banner.


2. Trust Recognition Levels

Level 1 - User Verified

Icon

πŸ‘€βœ“

Label

Marked Safe by You

Meaning

You have previously reviewed and approved similar messages.


Level 2 - Peer Verified

Icon

πŸ‘₯βœ“

Label

Marked Safe by Group

Meaning

Multiple users within your organization have previously approved similar messages.


Level 3 - Administrator Approved

Icon

πŸ›‘οΈπŸ‘₯βœ“

Label

Trusted by Organization

Meaning

Your IT or Security Administrator has validated and approved this communication.


Level 4 - Security Operations Approved

Icon

πŸ†πŸ›‘οΈ

Label

Verified by SCRProtect

Meaning

Your managed security provider or security operations center has globally approved this sender/content.


3. Five-Level Security Classification Framework

Current banner classifications provide excellent visibility into threats but could benefit from greater granularity.

Proposed Security Scale:

ColorClassificationPurpose

πŸ”΄ Red

Danger

Active threat or high-risk content

🟠 Orange

Trusted / Verified Safe

User, Group, Admin or Security Team approved

🟑 Yellow

Identity & Sender Risk

Potential impersonation concerns

🟣 Purple

Sensitive Content

Safe but requires proper handling

βšͺ Gray

Neutral

Informational only


4. Yellow Classification Remains Focused on Identity Risks

Yellow banners should remain dedicated to:

Identity & Sender Risks

🟑 Potential Sender Forgery

Examples:

  • Display name does not match sender

  • Executive impersonation

  • CEO fraud

  • CFO fraud


🟑 Spoofed Internal Sender

Examples:

  • Appears to come from internal staff

  • Originates from external infrastructure

  • Internal name spoofing attempts


🟑 Brand Impersonation

Examples:

  • Microsoft

  • Amazon

  • UPS

  • FedEx

  • DocuSign

  • Adobe

Appears legitimate but originates from unrelated domains.


🟑 Confusable Domain

Examples:

Visual deception intended to trick users.


5. New Purple Category: Sensitive Content

Problem

Many emails are not dangerous but contain information that requires extra care.

Current banners do not clearly distinguish:

  • Security threat

  • Confidential information

These are fundamentally different concerns.


Proposed Banner Color

🟣 Purple = Sensitive Content

Meaning:

"The email appears legitimate but contains information that should be handled carefully."


🟣 Financial Data

Examples:

  • Banking details

  • ACH instructions

  • Routing numbers

  • Account numbers

  • Wire transfer information

Banner Text:

Financial information detected. Verify before sharing or forwarding.


🟣 Sensitive Personal Information

Examples:

  • Social Security Numbers

  • Date of Birth

  • Driver License Numbers

  • Passports

Banner Text:

Personal information detected. Handle according to company policy.


🟣 Passwords & Credentials

Examples:

  • Passwords

  • Recovery codes

  • MFA codes

  • API keys

  • Encryption keys

Banner Text:

Credentials detected. Do not forward unless explicitly authorized.


🟣 Confidential Company Information

Examples:

  • Customer lists

  • Contracts

  • Internal financials

  • Employee data

  • Strategic planning documents

Banner Text:

Confidential company information detected. Distribution should be limited.


🟣 Healthcare & HIPAA Content

Examples:

  • Patient information

  • Medical records

  • Healthcare identifiers

Banner Text:

Protected health information detected. Follow HIPAA handling procedures.


6. Dynamic Banner Color Reduction Based on Trust

When a user validates a previously flagged message, the banner should evolve.

Initial State

🟑 Potential Sender Forgery


User Marks Safe

🟠 Safe – Verified by You

Display:

πŸ‘€βœ“ Marked Safe by You


Multiple Users Mark Safe

🟠 Verified by Group

Display:

πŸ‘₯βœ“ Marked Safe by Group


Administrator Approves

🟠 Trusted by Organization

Display:

πŸ›‘οΈπŸ‘₯βœ“ Trusted by Organization


Security Provider Approves

🟠 Verified by SCRProtect

Display:

πŸ†πŸ›‘οΈ Verified by SCRProtect


This preserves historical visibility while reducing unnecessary concern.


7. Administrative Controls

Allow administrators to:

  • Approve trusted senders

  • Approve trusted domains

  • Approve specific brand impersonation exceptions

  • Set trust expiration periods

  • Revoke trust status

  • Export trust history

  • Audit user trust decisions


Business Benefits

Reduced Banner Fatigue

Users will stop seeing repeated warnings for known-safe communications.

Better Security Awareness

Yellow banners become focused solely on sender identity concerns.

Improved DLP Awareness

Purple banners educate users on handling sensitive information.

Organizational Intelligence

Trust decisions become shared organizational knowledge.

Stronger Security Culture

Users participate in the validation process while security teams maintain oversight.


Proposed Banner Hierarchy

ColorMeaningAction

πŸ”΄ Red

Dangerous

Avoid interaction

🟠 Orange

Verified Safe

Trusted communication

🟑 Yellow

Identity/Sender Risk

Validate sender

🟣 Purple

Sensitive Content

Handle carefully

βšͺ Gray

Informational

Awareness only

Closing Recommendation

The addition of Trust-Based Validation Indicators, Orange Verified Safe Banners, and a new Purple Sensitive Content Classification would significantly enhance INKY's effectiveness by reducing warning fatigue, improving user confidence, and providing a more mature risk-classification model aligned with real-world security operations and modern MSP/SOC workflows.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
πŸ“§

Email Security

Date

22 days ago

Author

Jason Johnson

Subscribe to post

Get notified by email when there are changes.