Concepts rapidvalue.eu →

Unstructured Data Visibility

Seeing and governing who can access sensitive file shares, sites, and folders alongside structured entitlements.

The blind spot classic governance leaves

Most identity governance is good at structured access — an entitlement, a group, a role, a licence — the tidy, enumerable objects a system exposes. But a large share of an organisation's sensitive data does not live behind a neat entitlement. It lives in unstructured places: SharePoint sites, OneDrive personal drives, network file shares, Google Drive and Box folders. A folder called "Payroll 2026" or "M&A Eagle" can be readable by dozens of people through permissions that never pass through the governed model at all.

Unstructured data visibility is the lens that closes that blind spot: it shows who can access sensitive unstructured content, flags the risky exposure, and gives you a path to bring it under governance. This is a deliberate differentiator — visibility that leads to governance, not a static report.

What the lens shows: folders with sensitivity and exposure

The unit is a folder (a share, site, or data location). For each one the lens surfaces:

Attribute What it tells you
Source and path Where it lives — SharePoint, OneDrive, network file share, Google Drive, Box
Sensitivity low, medium, high, or critical, with tags such as PII (personally identifiable information) or Confidential
Reader / writer / owner counts How many people can read, write, or own the content
External count How many of those are external guests
In-scope flag Whether this folder is governed inside the platform, or sitting outside it
Risk flags Over-shared, external access, sensitive-but-outside-governance, crown jewel, stale owner

A summary row of counts sits on top — total folders, high-sensitivity folders, folders outside governance, over-shared folders, folders with external access — and each count is a filter you can click into, so triage starts from the number that worries you.

"Observe before you govern"

The posture is deliberate: you observe first. A folder can be visible in the lens without being under active governance — you can see its sensitivity, its reader list, and its risk flags before you decide to bring it into scope. This matches the platform's broader onboarding philosophy, where read-only visibility is a first-class step that earns trust before any write happens. Classic governance tools are weak at fast, easy visibility; here it is the entry point.

Concretely, an out-of-scope folder is still fully observable. Bringing it in scope is the deliberate act that links it to the governed model — described below.

The reader list is the core question

The single most valuable thing a data owner needs is the actual reader list: who, specifically, can access this folder, and how? The lens answers that with each reader resolved to a real name, email, department, and identity type — grouped by permission level (reader, writer, owner) and with external guests flagged by their email domain. A truncated identifier is not an answer; a named, readable list is.

For a large estate this is presented as a count with drill-in rather than every row at once — a hot folder can have tens of thousands of readers — so the list is searched and paged server-side.

💡 Tip

The reader list is what turns "this folder is high-sensitivity" into an action. Spotting one external guest and one leaver still able to read "Payroll 2026" is the moment a data owner launches a review or requests a revoke.

Governed like any other access

Unstructured data is deliberately not left as a disconnected silo. The intended model wires it into the same governance the platform applies elsewhere:

Two everyday jobs

Triage sensitive exposure. A security officer scans the estate for high-sensitivity folders that are readable outside the governed model, opens a crown jewel, sees it is owner-less or over-shared or has external guests, and acts: assign an owner, launch a reader review, or request a revoke of external access.

Check a leaver's residual access. When off-boarding someone, the reverse of the lens answers "which sensitive shares can this person still read?" straight from their profile — the unstructured slice of the leaver flow — so the ticket is not closed while a leaver can still open "Payroll 2026".

💡 Tip

Because the ingestion connector that scans real file shares is staged, a tenant without a bound source sees the lens on demonstration data behind a clear banner — the shape is real, the numbers are illustrative until a source is connected.

Further reading