1. Administration and security
  2. Bring your own key (BYOK)
  3. Decrypt a Workspace


When you unassign an encryption key from a workspace, that workspace immediately returns to encryption using the system master key. There are a few scenarios where you might want to unassign a key:

  • Your key rotation policy states that you must rotate your keys between BYOK-encrypted workspaces at fixed intervals.
  • The workspace is no longer required to be encrypted with a BYOK key.

All model data within a workspace remains encrypted during the process of unassigning keys.

To unassign a key from a workspace:

  1. In the Administration sidebar, under BYOK, select Workspaces.
  2. Select a workspace with a BYOK status of Encrypted.
  3. Click Unassign Key.
  4. In the Unassign Your Encryption Key dialog, if you're certain you want to go ahead and decrypt the workspace using your key, click Unassign Key.

You can view the progress of the decryption at BYOK > Workspaces, in the BYOK column. When the decryption completes, the status changes to Not Encrypted. The workspace is now encrypted with the system master key.


We may update our documentation occasionally, but will only do so in a way that does not negatively affect the features and functionality of the Anaplan service.