Unstructured Data Visibility
Seeing and governing who can access sensitive file shares, sites, and folders alongside structured entitlements.
The blind spot classic governance leaves
Most identity governance is good at structured access — an entitlement, a group, a role, a licence — the tidy, enumerable objects a system exposes. But a large share of an organisation's sensitive data does not live behind a neat entitlement. It lives in unstructured places: SharePoint sites, OneDrive personal drives, network file shares, Google Drive and Box folders. A folder called "Payroll 2026" or "M&A Eagle" can be readable by dozens of people through permissions that never pass through the governed model at all.
Unstructured data visibility is the lens that closes that blind spot: it shows who can access sensitive unstructured content, flags the risky exposure, and gives you a path to bring it under governance. This is a deliberate differentiator — visibility that leads to governance, not a static report.
What the lens shows: folders with sensitivity and exposure
The unit is a folder (a share, site, or data location). For each one the lens surfaces:
| Attribute | What it tells you |
|---|---|
| Source and path | Where it lives — SharePoint, OneDrive, network file share, Google Drive, Box |
| Sensitivity | low, medium, high, or critical, with tags such as PII (personally identifiable information) or Confidential |
| Reader / writer / owner counts | How many people can read, write, or own the content |
| External count | How many of those are external guests |
| In-scope flag | Whether this folder is governed inside the platform, or sitting outside it |
| Risk flags | Over-shared, external access, sensitive-but-outside-governance, crown jewel, stale owner |
A summary row of counts sits on top — total folders, high-sensitivity folders, folders outside governance, over-shared folders, folders with external access — and each count is a filter you can click into, so triage starts from the number that worries you.
"Observe before you govern"
The posture is deliberate: you observe first. A folder can be visible in the lens without being under active governance — you can see its sensitivity, its reader list, and its risk flags before you decide to bring it into scope. This matches the platform's broader onboarding philosophy, where read-only visibility is a first-class step that earns trust before any write happens. Classic governance tools are weak at fast, easy visibility; here it is the entry point.
Concretely, an out-of-scope folder is still fully observable. Bringing it in scope is the deliberate act that links it to the governed model — described below.
The reader list is the core question
The single most valuable thing a data owner needs is the actual reader list: who, specifically, can access this folder, and how? The lens answers that with each reader resolved to a real name, email, department, and identity type — grouped by permission level (reader, writer, owner) and with external guests flagged by their email domain. A truncated identifier is not an answer; a named, readable list is.
For a large estate this is presented as a count with drill-in rather than every row at once — a hot folder can have tens of thousands of readers — so the list is searched and paged server-side.
💡 Tip
The reader list is what turns "this folder is high-sensitivity" into an action. Spotting one external guest and one leaver still able to read "Payroll 2026" is the moment a data owner launches a review or requests a revoke.
Governed like any other access
Unstructured data is deliberately not left as a disconnected silo. The intended model wires it into the same governance the platform applies elsewhere:
- A folder is an ownable object. It has an owner, assigned through the standard ownership model, and that owner can be asked to attest its readers.
- Its readers can be reviewed. A data owner can launch an access review over a folder's readers — reusing the platform's review engine, not a bespoke path.
- In-scope folders link to a governing entitlement. When a folder is brought into scope it references the entitlement that governs it, so its readers reconcile like any other assignment — the reconciliation engine, the audit trail, and the assignments view all see them. Out-of-scope folders stay standalone, visibility-only.
- Risk flags reach the advisor inbox. Signals such as sensitive-outside-governance, over-shared, crown jewel (owner-less and highly sensitive), and stale owner are raised as recommendations in the Platform Advisor — the platform's single inbox — so unstructured findings sit next to everything else that needs attention.
Two everyday jobs
Triage sensitive exposure. A security officer scans the estate for high-sensitivity folders that are readable outside the governed model, opens a crown jewel, sees it is owner-less or over-shared or has external guests, and acts: assign an owner, launch a reader review, or request a revoke of external access.
Check a leaver's residual access. When off-boarding someone, the reverse of the lens answers "which sensitive shares can this person still read?" straight from their profile — the unstructured slice of the leaver flow — so the ticket is not closed while a leaver can still open "Payroll 2026".
💡 Tip
Because the ingestion connector that scans real file shares is staged, a tenant without a bound source sees the lens on demonstration data behind a clear banner — the shape is real, the numbers are illustrative until a source is connected.