Protect and automate

Data protection

Find overshared assets and sensitive content, assess exposure risk, and coordinate remediation with employees.

Reviewed Oct 9, 2026 · Product

Overview

Data Protection identifies supported assets that are shared outside their intended audience or contain sensitive content. Administrators can investigate exposures, distribute issues to employees, and use source-specific actions or playbooks to remediate them.

Open the module for your Elba region:

Supported sources

Data Protection currently uses seven source families:

  • Google Workspace
  • Microsoft Teams
  • Slack
  • SharePoint
  • OneDrive
  • Dropbox
  • Confluence

All seven sources support external-sharing signals. Slack and Microsoft Teams also support sensitive-content signals in messaging. Detection and remediation capabilities still vary by source, connection, and object type; use the capability shown in Elba for the specific source as the source of truth.

Data handling

For content analysis, Elba retains the source reference and finding metadata needed to display, deduplicate, and audit an issue rather than a durable copy of the raw content in its primary finding records. Content can be staged temporarily while processing completes. See the security and privacy FAQ for more detail.

Slack Data Protection and the Slack employee-communications integration are separate capabilities and require different permissions. Slack Data Protection analyzes supported messages in public channels available to the customer-authorized connection for enabled detections; its current permission set does not grant access to private-channel history. See OAuth scopes and permissions for both Slack grants.

The module has four tabs:

  • Radar summarizes high-risk and common exposure patterns.
  • Issues lists detected exposures and their current status.
  • Playbooks contains available automation templates and configured workflows.
  • Sources shows connections, synchronization status, and source-specific settings.

Check connection errors from Home

For organization owners and administrators with Data Protection configured, Home → Data Protection connections highlights configured sources with a recorded connection error that prevents at least one active playbook from running. Each source appears once, with the number of affected active playbooks. Healthy or unconfigured sources and sources with only draft or paused playbooks are excluded.

  1. Review the source and affected-playbook count. Home shows up to three sources, with the oldest known errors first. An unknown error start time is explicitly indicated.
  2. Select View source to open that source’s existing settings, or View all sources to open the full Sources list. Opening these pages does not reconnect the source or resolve the error.
  3. Select Refresh to reload connection information. Elba also reads it again whenever you open Home and automatically every minute while Home is open.

Information read at … UTC records when Elba last successfully loaded stored connection information. The separate Error recorded at … UTC is the recorded error time. Neither timestamp confirms a live check with the provider, and stored information can lag the provider’s actual state.

If a refresh fails or the last successful read is at least a minute old, Elba warns that the information may be out of date and keeps the previous read time. If no read has succeeded, the affected playbooks are unknown. Use Refresh to try again. A successful read of a recovered connection removes its row. The absence of a notice does not guarantee that all protection is operating.

Use the Radar

The Data Protection Radar contains:

  • High Risk Exposures for issues with the highest AI-assessed risk
  • Overly shared data for sensitive-data categories and their exposure levels
  • Playbooks for configured workflows and available templates
  • Most common exposures for sensitive categories by internal, external, or public sharing
  • Frequent data recipients for external users, domains, Slack channels, or Teams channels receiving the most shared data

Select a widget result to open the related filtered issue view.

Investigate observed Google Drive sharing by domain

Open Radar → Frequent data recipients → Sharing by domain. Observed sharing by domain lists Google Drive sharing records already collected by Elba. It helps you move from a recipient domain to addresses and files without assembling an export. Browsing these records does not establish that access is still active or that every drive has been scanned.

  1. Choose Professional, Personal, Public or No domain. Public links are kept separate from named recipients. Professional and personal are address-domain categories, not verified customer or employer identities.
  2. Search for a domain and open it. Review the distinct addresses, files and observed shares. You can search its addresses, open one recipient, or choose All files shared with the domain. Search and breadcrumb navigation keep the investigation context.
  3. Review each file's owner, observation date and source. Open the Google Drive file link or the existing alert when present. Browsing or selecting files does not remove access, change an alert or send a message. To remove selected recipient access, use the preview and confirmation below.

The view uses stored observations, not a live provider check. Latest sharing observation describes recorded sharing observations; mixed or older dates remain visible. Source status opens the existing connection settings. A connected source and a recent stored record do not prove complete scanning. Coverage unknown, source errors and empty results must not be interpreted as a complete inventory or as proof that no files are shared.

Files load in pages of 25. Grant-record and listed-address limits are independent: the list examines up to 1,000 grant records per group; an opened group examines up to 50,000. When a grant limit is exceeded, Elba marks file/share counts as lower bounds and withholds a misleading observation date. Exactly reaching a limit is distinguished from exceeding it. Listed addresses have their own limits of 1,000 in a list row and 50,000 in an opened domain. Distinct-address counts use a separate calculation; do not infer their precision from the file/share cap.

Domain search covers the whole domain index. Address search covers the full group while its address list is complete. If that list is capped, the persistent notice and empty-search explanation say that the search covers only listed addresses. This view does not search file names or provide a complete ranking of all sharing.

Remove selected recipient access in Google Drive

Owners and administrators can remove supported direct access for a selected address or domain from this same view, while keeping other recipients' grants.

  1. Open the recipient's files and explicitly select up to 100 files. For a domain, check whether the selection covers its addresses and whole-domain grants or only whole-domain grants.
  2. Select Preview selected files. Elba reads the current Google Drive permissions and shows eligible grants, other grants retained, and files it could not verify. Inherited, group, public-link, internal and owner access is excluded; folders are not supported.
  3. Review the counts and per-file details. Select Confirm removal of N grants only when they match your intended scope. The preview expires after ten minutes; if it expires or a grant changes, prepare a new preview.
  4. Open Saved previews and results to review progress and the recorded outcome. Results distinguish removed grants, grants already absent, inherited access, failures and unknown results. A retry applies only to unresolved grants from the original confirmed selection, without adding new access.

Google Drive recipient preview showing selected files, eligible grants and unavailable files

This preview was captured in Elba's internal EU organisation. File names and recipient details are omitted.

Before confirmation, Return to files cancels the preview and keeps the file selection. The canceled preview remains in the history. Cancellation does not undo an already confirmed removal.

This action does not activate a Playbook or notify employees. It removes only the verified supported grants on selected files; it does not certify complete offboarding, resolve every alert, or recover gaps in the source inventory. If a file is unavailable, inspect its current permissions in Google Drive before deciding how to proceed.

Continue in Issues or an unsaved Playbook

From an opened Google Drive domain or address in Radar, choose View alerts to carry that recipient and source into Issues. Draft a playbook opens the existing editor with the same selection. The return link takes you back to that domain or address.

The selection has three distinct meanings:

  • Address matches that exact recipient address.
  • Domain (addresses and whole domain) includes addresses in that exact domain and grants to the whole domain. It does not include subdomains or similarly named domains.
  • Whole domain only matches grants to the whole domain, without its individual addresses. Previously saved domain filters keep this narrower meaning.

You can deliberately enter an address or domain in the recipient selector even when it is absent from the suggestions. Issues still applies its other filters and normal access rules. It lists alerts, while Radar lists observed sharing: files without an alert, historical alert permissions and deleted owners can make the lists differ. An alert does not prove that access still exists.

The Playbook opens as an unsaved draft, with the Google Drive trigger and recipient condition already selected. Opening or leaving it saves nothing, activates nothing and sends nothing. Review the conditions before saving the draft, and deliberately add an action before activating the Playbook. The recipient condition selects files; actions apply to the whole file. In particular, Remove sharing removes all sharing on that file, not only this recipient's access. This is not targeted offboarding.

A file shared only with a whole domain is available for review in Radar and Issues, but has no recipient Playbook drafting action: the current trigger does not cover that sharing type. An unsupported whole-domain-only draft link is refused.

The condition reads sharing recorded on the alert. It is checked when an alert is created, the Playbook is activated, edited or resumed, the file's sharing type changes, or a waiting run restarts. A recipient added later to a file that already has an open alert may wait until one of those events. Review the observation dates and current access in Google Drive before deciding on a removal.

Understand detections

Sharing types

Elba classifies detected sharing as:

  • Professional for an external professional domain
  • Personal for an external personal domain
  • Public for access available through a public link
  • Internal for exposure within the organization, including supported messaging signals

Sensitive-content categories

The current sensitive-content categories are:

  • Credentials
  • Financials
  • Legal
  • PHI for protected health information
  • PII for personally identifiable information

An issue can also include more specific detected elements and a confidence level. Treat automated findings as investigation signals and validate important decisions against the source asset and your organization's data-classification policy.

Risk levels

When AI risk analysis is available, Elba assigns Low, Medium, or High and provides an explanation. The issue details also show the score on a 0-to-10 scale.

File formats

The current file-format selector contains 312 extensions. It covers documents, spreadsheets, source code, presentations, images, audio and video, fonts, 3D files, databases, email, archives, executables, design files, and chat exports.

Format availability is source-dependent. A file extension alone does not confirm that content was analyzed; check the issue details for the format, sensitive findings, tags, and AI analysis actually available for that asset.

Work with issues

The Issues tab shows each asset, member, source, risk level, status, and last activity.

To see every issue for one Google Drive file, paste its link or file ID in the search bar. A link finds that exact file, even when other files share its name; a bare ID also finds names containing it. The results include open and completed issues: the Issue status filter pauses while you search a file and applies again when you remove the search. Choose statuses during the search to narrow the file's issues.

You can also search by object name or filter by:

  • Member, enrolled-member status, or group
  • Source
  • Issue status, creation date, or distribution date
  • Object last-updated period or file format
  • Risk, tag, sensitive-content category, or sharing type
  • Recipient

Issue statuses displayed in the workspace are:

  • Detected for a new issue that has not been sent to an employee
  • Distributed for an issue sent to an employee and awaiting completion
  • Changes made for a completed issue where permissions or the asset changed
  • Ignored for a completed issue accepted without a source change

In the Issue status filter, issues a playbook fixed are listed as Auto-fixed by elba. Issues completed before elba recorded who completed them are listed under Completed by admin, as Changes made or Ignored.

For an ignored file, a later source scan does not raise another issue merely because an allow-listed recipient also has access. A newly detected sharing permission that is not allow-listed can raise a new issue. This does not start a scan or change sharing permissions by itself.

Admin actions

Select one or more open issues to see the actions supported for that selection. Depending on the source and object, actions can include:

  • Distribute issues to enrolled employees
  • Ignore issues
  • Remove sharing permissions
  • Delete assets

Elba only displays a direct source-changing action when the source settings report that capability. If the source does not support it, investigate and remediate the asset in the source system.

Verify Google Drive sharing removal

For a supported direct Google Drive permission, Elba checks the result of a removal request. If the permission remains or its removal cannot be confirmed, the issue stays open or reopens for review. A request can take time to complete; check the issue again before treating it as resolved.

Sharing inherited from a parent folder cannot be removed on the file. Elba keeps that issue open. Review the sharing on the source folder in Google Drive and change it there if appropriate.

This behavior applies to new removal requests. It does not replay earlier requests or automatically recheck issues previously marked Changes made. For an earlier high-risk issue, verify the current access in Google Drive before relying on that status.

Some older Google Drive issues contain sharing from a removal whose outcome was not verified. These issues remain visible in Issues, but playbooks do not automatically distribute or remediate them, even when an issue also contains newer sharing. Review the current access in Google Drive before deciding what to do. Issues already distributed to employees remain assigned, and their existing reminders may continue. Newly detected sharing that does not belong to one of these held issues continues through the normal playbook flow.

Configure playbooks

Playbooks can distribute detected issues and, where supported, apply remediation actions. Available triggers, conditions, exclusions, and actions are specific to the selected source.

To activate a workflow safely:

  1. Connect the source and let its initial detection complete.
  2. Review the issue volume and representative assets in Issues.
  3. Select or create a playbook for the source.
  4. Configure sharing, content, risk, age, format, tag, or recipient conditions that the editor makes available.
  5. Configure exclusions or an allow-list when supported.
  6. Review the action, audience, and any delay before activation.
  7. Activate the playbook and monitor its run history.

Issue detection does not itself notify an employee. Notification timing is controlled by issue distribution, the playbook action, and communication settings; there is no universal Friday or weekly digest schedule.

Employee remediation

Distributed issues appear in the employee's Checklist. The available actions depend on the source:

  • Ignore to complete the issue without changing the source asset.
  • Edit permissions to select and remove supported sharing permissions.
  • Delete asset when the source supports direct deletion.
  • Open the asset in the source and make the change there when direct remediation is unavailable.

Elba can also offer Refresh for sources that support checking the asset again. If a connection has an error, actions that change the source can be temporarily unavailable.

  1. Connect one source and let detection finish.
  2. Review high-risk exposures and a sample of lower-risk issues.
  3. Validate sensitive findings and sharing classifications against the source.
  4. Configure exclusions for legitimate recurring sharing where supported.
  5. Distribute a small, representative set of issues and review the employee experience.
  6. Add source-supported remediation only after confirming ownership and rollback procedures.
  7. Monitor issue outcomes and refine conditions before expanding the workflow.

On this page