For example, your organization may be okay with sharing PII in a private HR project, but not in projects that are shared across the company. Without policy flexibility, you are forced to take more of an “all or nothing” approach - even if there is only one place where PII is not okay, you’ll get alerts when it appears anywhere. This leads to noise / alerts for data occurrences you don’t really care about. With policy flexibility, alerts are targeted to the violations that truly matter.