Blog

What's New in OpenText CDDRI 26.2

Written by Wyldlynx | Fri, Sep 4, 2026

If you're responsible for keeping OpenText Core Data Discovery & Risk Insights (CDDRI) running smoothly, release notes can feel like a chore. They're long, technical, and buried in a PDF nobody wants to read properly. But skip them, and you risk missing a change that quietly affects your compliance posture, or worse, an action you can't undo.

Version 26.2 has a few of those. There's a new data source to connect, a masking feature that permanently overwrites original documents, and a grammar change that affects how Australian company data gets classified. Here's what matters in this release and what to do about it.

A new source: Confluence

CDDRI 26.2 adds support for processing content from Confluence 7.19.x or later Data Centres. You connect using a configured user or an API token, then define which Confluence space you want scanned using its space key. You can register up to 500 unique spaces per dataset, though each individual space can only belong to one dataset per Confluence source.




Once connected, Confluence items show up in the folder tree view when you're reviewing content lists in Analyse or Manage. Deletions and updates to Confluence items are tracked automatically. At scan time, the system compares what's currently in the Confluence space against what it's already processed and flags the difference.

If your organisation has been storing policy documents, meeting notes, or project records in Confluence without a way to scan them for sensitive information, this closes that gap.

Masking at the source

This is the change we'd flag to every CDDRI administrator before anyone touches it.

Previously, masking created protected copies of documents. Now you can mask file system and SharePoint documents directly at their original location, called internal masking. The masked version replaces the original file, in its original format, at the source.

Here's the part that matters: this action is irreversible. Once you mask a document at its source, the original is gone. The release notes recommend performing a "send to target" action on the workbook first, so you have a backup copy somewhere else before you mask anything at the source.

A single Internal Masking file protection system is created automatically when your organisation installs the application. You can't edit or delete it, but you do need to build your own file protection rules to specify which grammars (the patterns CDDRI uses to detect things like tax file numbers or medical terms) trigger masking.

When you set up a workspace or workspace template with the Protect feature turned on, you'll now choose which file protection rules are available for that workspace's workbooks. When someone applies the Protect action to a workbook, they pick a specific rule, either internal masking or Microsoft Purview labelling (the renamed version of what used to be called Microsoft data protection), and CDDRI shows a summary of how many documents will be affected before anything happens.

If your team plans to use internal masking, two permission changes matter: the existing "Protect documents" permission at both the Manage application level and the Manage workspace security level now covers this new masking action. Worth reviewing who currently holds that permission before you switch it on.

A grammar change that affects Australian privacy compliance

Under the Australian Privacy Principles grammar set, the Government ID rule will no longer match an Australian Company Number (ACN) as a Social Security Taxation ID. The reasoning is straightforward: an ACN is public information, not a protected identifier. But if your workspace has been treating ACNs as sensitive, this changes what gets flagged going forward.

To apply the update, you'll need to re-analyse any datasets using this grammar rule. In Connect, go to Sources > Manage Datasets, open the relevant dataset's detail pane, and click the re-analyse icon or the Re-Analyse link next to the Grammar Sets information. It won't happen automatically.

Beyond that, 26.2 adds new grammars for:

  • Addresses: India, Oman and UAE
  • Date of Birth: Arabic and Hindi languages
  • Driving Licenses: Oman and UAE
  • Health ID: Norway, Oman and UAE
  • Medical Terms: Arabic and Hindi languages
  • Names: Oman and UAE
  • National ID: Oman
  • Nationalities: India, Oman and UAE
  • Passport Numbers: Oman and UAE
  • Telephone Numbers: India, Oman and UAE

If your organisation processes data connected to any of those regions, it's worth checking whether these new grammars should be part of your existing rules.

Smaller changes worth knowing about

A handful of other updates affect day-to-day use, even if they're not headline features:

  • In Connect, when you switch a dataset's default action from "metadata only" to "analysed," you can now also enable "Store content as text" and "Extract grammar values" at the same time, rather than doing this in a separate step.
  • The retry function for agent activity scans that completed with errors has moved. For scans with multiple job runs, retry now sits at the top-level scan activity rather than requiring you to expand and retry each job run individually. Single job run scans work as before.
  • Content Manager datasets can now capture external metadata dynamically using the external metadata file processor.
  • In Manage, the Workspace Overview dashboard no longer shows zero-count cards for workspaces you don't have access to. They're hidden rather than cluttering the view.
  • In Administration, users with the "User Management" permission can now remove themselves from application-level roles, as long as doing so doesn't strip their own User Management access.
  • If you're using the API, protect actions against the approve, request-review, or approve-without-review policy methods now require the `secureRuleId` property in the payload to be linked to the workspace. If your integration calls these endpoints directly, this is a breaking change worth testing before you upgrade production.

Bugs fixed in this release

Several fixes address issues that have likely caused real frustration for CDDRI administrators: scans that silently failed to trigger on schedule, SharePoint datasets that got stuck in initialisation when a related dataset without a Sub-URL was deleted, incorrect user attribution on manual workbook refreshes, and grammar values not extracting properly from tables in Word documents. There's also a fix for Exchange Online scans failing with "Credentials are invalid or unauthorised" even when the credentials were fine, a particularly annoying one if you've hit it.

One known issue remains: if you're idle on an auto-refreshing page (Workbooks, Agent Activity, Manage Datasets) and your session times out, you may see an "Authentication Error" instead of the expected "Session Timed Out" message. Not a functional problem, but worth telling your team so they're not alarmed.

Let's talk about your upgrade

None of this is complicated once you know it's there, but that's exactly why it's worth reviewing properly before you move. If you'd like a second set of eyes on your 26.2 upgrade plan or would like to maximise your value with these new features, we're happy to talk about it with you.


Bonus: Watch the OpenText Technical Webinar

Check out the video below from Jason Boswell of OpenText for further insight and details on the release.