The job to be done
Reduce an unacceptable data exposure without making legitimate work impossible.
What goes in
- Data discovery and classification
- Access and sharing configuration
- Data movement and usage signals
What should come out
- Exposure findings and ownership
- Guardrails or incident alerts
- Retention and access remediation
Questions worth asking
- Where do sensitive copies and exports escape visibility?
- Can a reviewer explain why an action was blocked?
- How are false positives and necessary exceptions handled?
A useful evaluation exercise
Use a synthetic document to test internal sharing, public links, and authorized export. Record the user experience as well as detection.