Help the elimination of over stimulation of banners:
Executive Summary
Organizations receive many recurring emails from vendors, customers, financial institutions, healthcare providers, and business partners that may legitimately trigger caution banners. Over time, users learn which messages are trustworthy, but that knowledge is not currently leveraged within the INKY banner experience.
This proposal introduces:
Community Trust Indicators ("Marked Safe" System)
Five-Tier Security Banner Classification Model
New Purple Classification for Sensitive Content
Progressive Banner Color Changes Based on Trust Validation
User, Group, Administrator, and Security Provider Trust Levels
The goal is to improve security awareness while reducing alert fatigue and helping users make better decisions.
1. Trusted Message Recognition System
Current Challenge
Many emails generate recurring caution banners despite being regularly validated by users.
Examples:
Banking notifications
Customer invoices
Vendor ACH requests
Payroll communications
Healthcare correspondence
Internal applications
Users eventually ignore banners because they see the same trusted message repeatedly.
This creates:
Banner fatigue
Reduced effectiveness of warning systems
Increased likelihood of users overlooking actual threats
Proposed Solution
Allow users to mark emails as:
✅ "Safe"
INKY would then track:
Sender
Domain
Message characteristics
Similar email fingerprints
Future matching emails would display trust indicators directly in the banner.
2. Trust Recognition Levels
Level 1 - User Verified
Icon
👤✓
Label
Marked Safe by You
Meaning
You have previously reviewed and approved similar messages.
Level 2 - Peer Verified
Icon
👥✓
Label
Marked Safe by Group
Meaning
Multiple users within your organization have previously approved similar messages.
Level 3 - Administrator Approved
Icon
🛡️👥✓
Label
Trusted by Organization
Meaning
Your IT or Security Administrator has validated and approved this communication.
Level 4 - Security Operations Approved
Icon
🏆🛡️
Label
Verified by SCRProtect
Meaning
Your managed security provider or security operations center has globally approved this sender/content.
3. Five-Level Security Classification Framework
Current banner classifications provide excellent visibility into threats but could benefit from greater granularity.
Proposed Security Scale:
4. Yellow Classification Remains Focused on Identity Risks
Yellow banners should remain dedicated to:
Identity & Sender Risks
🟡 Potential Sender Forgery
Examples:
Display name does not match sender
Executive impersonation
CEO fraud
CFO fraud
🟡 Spoofed Internal Sender
Examples:
Appears to come from internal staff
Originates from external infrastructure
Internal name spoofing attempts
🟡 Brand Impersonation
Examples:
Microsoft
Amazon
UPS
FedEx
DocuSign
Adobe
Appears legitimate but originates from unrelated domains.
🟡 Confusable Domain
Examples:
Visual deception intended to trick users.
5. New Purple Category: Sensitive Content
Problem
Many emails are not dangerous but contain information that requires extra care.
Current banners do not clearly distinguish:
Security threat
Confidential information
These are fundamentally different concerns.
Proposed Banner Color
🟣 Purple = Sensitive Content
Meaning:
"The email appears legitimate but contains information that should be handled carefully."
🟣 Financial Data
Examples:
Banking details
ACH instructions
Routing numbers
Account numbers
Wire transfer information
Banner Text:
Financial information detected. Verify before sharing or forwarding.
🟣 Sensitive Personal Information
Examples:
Social Security Numbers
Date of Birth
Driver License Numbers
Passports
Banner Text:
Personal information detected. Handle according to company policy.
🟣 Passwords & Credentials
Examples:
Passwords
Recovery codes
MFA codes
API keys
Encryption keys
Banner Text:
Credentials detected. Do not forward unless explicitly authorized.
🟣 Confidential Company Information
Examples:
Customer lists
Contracts
Internal financials
Employee data
Strategic planning documents
Banner Text:
Confidential company information detected. Distribution should be limited.
🟣 Healthcare & HIPAA Content
Examples:
Patient information
Medical records
Healthcare identifiers
Banner Text:
Protected health information detected. Follow HIPAA handling procedures.
6. Dynamic Banner Color Reduction Based on Trust
When a user validates a previously flagged message, the banner should evolve.
Initial State
🟡 Potential Sender Forgery
User Marks Safe
🟠 Safe – Verified by You
Display:
👤✓ Marked Safe by You
Multiple Users Mark Safe
🟠 Verified by Group
Display:
👥✓ Marked Safe by Group
Administrator Approves
🟠 Trusted by Organization
Display:
🛡️👥✓ Trusted by Organization
Security Provider Approves
🟠 Verified by SCRProtect
Display:
🏆🛡️ Verified by SCRProtect
This preserves historical visibility while reducing unnecessary concern.
7. Administrative Controls
Allow administrators to:
Approve trusted senders
Approve trusted domains
Approve specific brand impersonation exceptions
Set trust expiration periods
Revoke trust status
Export trust history
Audit user trust decisions
Business Benefits
Reduced Banner Fatigue
Users will stop seeing repeated warnings for known-safe communications.
Better Security Awareness
Yellow banners become focused solely on sender identity concerns.
Improved DLP Awareness
Purple banners educate users on handling sensitive information.
Organizational Intelligence
Trust decisions become shared organizational knowledge.
Stronger Security Culture
Users participate in the validation process while security teams maintain oversight.
Proposed Banner Hierarchy
Closing Recommendation
The addition of Trust-Based Validation Indicators, Orange Verified Safe Banners, and a new Purple Sensitive Content Classification would significantly enhance INKY's effectiveness by reducing warning fatigue, improving user confidence, and providing a more mature risk-classification model aligned with real-world security operations and modern MSP/SOC workflows.
