One of the key security measures in an organization is to ensure that the access control policies are deployed effectively. Data Governance Edition provides you with several ways of managing access to data and measuring your progress to meet your security and compliance needs.
This section deals with looking at access management from a resource perspective. Managing account access provides details on managing access from an identity perspective.
Data Governance Edition enables you to:
Determine what is in your environment and who has access to it.
Data Governance Edition provides a real-time view of data access, allowing for a centralized view and control of permission assignments throughout the managed domain.
Minimize IT’s role as gatekeeper.
While IT is responsible for implementing access controls, the governing of data should be carried out by the people within the organization who actually own it. Data Governance Edition, along with the web portal, provides the workflow to accomplish this.
Improve access control consistency.
Inconsistent application of permissions contributes to downtime, lost productivity, security breaches and more. Organizations seek to create a governed environment that provides users with access to exactly the resources they need — no more and no less.
Using Data Governance Edition, you can browse through the resources on the hosts in your managed domains to:
A key challenge in improving data governance is keeping track of permissions within your environment. To ensure that data is secured in a manner that meets your business needs, you must be able to easily identify who has been given access and manage that access appropriately.
Once you have added a managed host, you can view access to its data through the:
: This is a live view of data on the managed host. You can browse through the supported file systems and see all applied permissions and make changes where required.
Through the Resource browser you can also identify, in an easy to browse tree view, where the access on a resource differs from its parent and manage that access.
: This view summarizes the type of data to which an account has access and the specific data of that type. From here, you can also view detailed group membership information.
Note: You can also view governed data access by selecting a user or group’s Account Overview.
Note: You can also select to manage access from Active Directory users and groups. Select Active Directory in the Navigation view, select the required user or group, and select Manage access from the Tasks view.
Once you have located the data, you can edit the security as required or place it under governance to control access to it. For more information, see Bringing data under governance.
To view the access on a specific resource
In the Navigation view, select Data Governance | Managed hosts.
Note: To group this view by host type, right-click on the Host Type column header and select Group By This Column. If the Host Type column is not displayed, right-click on the column headers, select Column Chooser and drag Host Type into the column header.
In the Resource browser, double-click through the resources to locate the required resource.
The Resource browser displays the following information:
For Cloud managed hosts, each site is represented by a folder hierarchy, with the Home top level site displayed as Site contents folder, followed by all other subsites. Each site contains a Site contents folder encompassing other nested folders. The contents of a site and document library are shown as "folder" type, whereas, files are shown as "file" type items. No other resource types are managed for Cloud managed hosts.
NOTE: The Resource browser and resource access reports do not display the limited access users or "previewer" accounts.
You can use the Location field, at the top of the page, to view your current location. If you have navigated too far, you can move back by clicking the Up One Level button.
To view a selected user or group’s access on all managed hosts in your environment
In the Tasks view, select Manage access.
All the access points for the selected user or group are displayed. By default, the results are listed by managed host.
Expand a managed host to display all the resources where the selected user or group has access.
You are able to see if the access has been granted explicitly (Directly held — the account is in the ACL) or through group membership (Indirectly held — the account belongs to a group that is in the ACL).
Browse through the managed hosts and their resources to view and manage the security on the object.
Once you have located the resource, you can select to manage its access and create reports that detail account access and group membership information.
To view all the users and groups that have access on a specific managed host
In the Tasks view, select Accounts view.
All resource types where users and groups have some level of access displays. By default, the results are grouped by resource type.
Expand a resource type to display all the accounts that have access.
You can quickly and easily locate specific resources to manage through the search option.
Note: The search feature is not available for SharePoint and DFS managed hosts.
Once you have located the resource, you can place the resource under governance so that it is available to use in policies and attestations, publish it to the IT Shop so that it is available for identities and business owners to request and grant access to it, assign a business owner, or edit the security as required.
To search for a resource
In the search field, enter the search criteria.
You can use the * character to search for resources. For example, enter Finance* to return all resources that begin with Finance, *.txt returns all resources that end with .txt, and *Fin* returns all resources that contain Fin in their name.
By default all items that match your query are returned. To limit the search results, click the arrow control to the right of the search button and select how many items you would like to return.
You have the option of returning the top 100, 200, or 500 results, or all the items that match your query.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center