LightBeam Documentation
Installer GuidesData SourcesPlaybooksInsightsPrivacyOpsGovernance
  • 💡What is LightBeam?
  • 🚀Getting Started
    • ⚙️Installer Guides
      • Pre-Requisites / Security Configurations
        • Firewall Requirements
        • Securing LightBeam on EKS with AWS Certificate Manager on Elastic Load Balancer
        • Configure HTTPS for LightBeam Endpoint FQDN Standalone deployment
        • Using Custom Certificates with LightBeam
        • Securing LightBeam on GKE with Google Certificate Manager and GCE Ingress
      • Core
        • LightBeam Deployment Instructions
        • LightBeam Installer
        • Web App Deployment
        • LightBeam Diagnostics
        • LightBeam Cluster Backup & Restore using Velero
      • Platform Specific
        • AWS
        • Microsoft Azure
        • Google Cloud (GKE)
        • Standalone Virtual Machine
        • Deployment on an Existing Managed Kubernetes Cluster
        • Azure Marketplace Deployment
      • Integration and Setup
        • Setting Up AWS PrivateLink for RDS-EKS Interaction
        • Twingate and LightBeam Integration Guide
        • Data Subject Request Web Application Server
        • Generate CSR for LightBeam
  • 🧠Core Features
    • 🔦Spectra AI
      • 🔗Data Sources
        • Cloud Platforms
          • AWS Auto Discovery
          • GCP Auto Discovery
        • Databases and Datalakes
          • PostgreSQL
          • Aurora (PostgreSQL)
          • Snowflake
          • MS SQL
          • MySQL
          • Aurora (MySQL)
          • BigQuery
          • AWS Redshift
          • Oracle
          • DynamoDB
          • MongoDB
          • CosmosDB (PostgreSQL)
          • CosmosDB (MongoDB)
          • CosmosDB (NoSQL)
          • Looker
          • AWS Glue
          • Databricks
          • SAP HANA
          • CSV Files as a Datasource
        • Messaging
          • Gmail
          • Slack
          • MS Teams
          • MS Outlook
        • Developer Tools
          • Zendesk
          • ServiceNow
          • Jira
          • GitHub
          • Confluence
        • File Repositories
          • NetDocuments
          • AWS S3
          • Azure Blob
          • Google Drive
          • OneDrive
          • SharePoint
          • Viva Engage
          • Dropbox
          • Box
          • SMB
        • CRM
          • Hubspot
          • Salesforce
          • Automated Data Processing (ADP)
          • Marketo
          • Iterable
          • MS Dynamics 365 Sales
          • Salesforce Marketing Cloud
      • 🔔PlayBooks
        • What is LightBeam Playbooks?
        • Policy and Alerts
          • Types of Policies
          • How to create a rule set
            • File Extension Filter
          • Configuring Retention Policies
          • Viewing Alerts
          • Sub Alerts
            • Reassigning Sub-Alerts
            • Sub-alert States
          • Levels of Actions on Alerts
          • User Roles and Permissions
            • Admin View
            • Alert Owner View
            • Onboarding New Users
              • User Management
              • Okta Integration
              • Alert Assignment Settings
              • Email Notifications
            • Planned Enhancements
          • Audit Logs
          • No Scan List
          • Permit List
          • Policy in read-only mode
      • 📊Insights
        • Entity Workflow
        • Document Classification
        • Attribute Management Overview
          • Attributes Page View
          • Attribute Sets
          • Creating Custom Attribute
          • Attributes List
        • Template Builder
        • Label Management
          • MIP Integration
          • Google Labels Integration
      • 🗃️Reporting
        • Delta Reporting
        • Executive Report
        • LightBeam Lens
      • Scanning and Redaction of Files
        • On-demand scanning
      • How-to Guides
        • Leveraging LightBeam insights for structured data sources
      • LightBeam Dashboard Outlay
      • Risk Score
    • 🏛️PrivacyOps
      • Data Subject Request (DSR)
        • What is DSR?
        • Accessing the DSR Module
        • DSR Form Builder (DPO View)
          • Creating a New DSR Form
            • Using a Predefined Template
            • Creating a Custom Form
          • Form Configuration
          • Form Preview and Publishing
          • Multi-Form Management
          • Messaging Templates
        • Form Submission & Email Verification (Data Subject View)
        • DSR Management Dashboard (DPO View)
        • Processing DSR Requests
          • Data Protection Officer (DPO) Workflow
          • Self Service Workflow (Direct Validation)
          • Data Source Owner (DSO) Workflow
        • DSR Report
      • 🚧Consent Management
        • Overview
        • Consent Logs
        • Preference Centre
        • Settings
      • 🍪Cookie Consent
        • Dashboard
        • Banners
        • Domains
        • Settings
        • CMP Deployment Guide for Google Tag Manager
        • FAQs
      • 🔏Privacy Impact Assessment (PIA)
        • PIA Templates
        • PIA Assessment Workflow
        • Collaborator View
        • Process Owner Login View (With Collaborator)
        • Filling questionnaire without collaborator
        • Submitting the assessment for DPO review
        • DPO review process
        • Marking the assessment as reviewed
        • Editing and resubmitting assessments after DPO review
        • Revoke review request
        • Edit Reviewer
        • PIA Reports
      • ⏺️Records of Processing Activity (RoPA)
        • Creating a RoPA Template
          • How to clone a template
          • How to use a template
        • How to create a process
          • Adding Process Details
          • Adding Data Elements
          • Adding Data Subjects
          • Adding Data Retention
          • Adding Safeguards
          • Adding Transfers
          • Adding a Custom Section
          • Setting a Review Schedule
          • Data Flow Diagram
        • How to add a collaborator
        • Overview Section
        • Generating a RoPA Report Using LightBeam
        • Collaborator working on a ticket
    • 🛡️Governance
      • Access
        • Dashboard
        • Users
        • Groups
        • Objects
        • Active Directory Settings
        • Access Governance at a Data Source Level
        • Policies and Alerting
        • Access Governance Statistics
        • Governance Module Dashboard
      • Privacy At Partners
  • 📊Tools & Resources
    • 🔀API Documentation
      • API to Create Reports for Structured Datasource
    • ❓Onboarding Assessments
      • Structured Datasource Onboarding Questionnaire
        • MongoDB/CosmosDB Questionnaire
        • Oracle Datasource Questionnaire
      • SMB Questionnaire
    • 🛠️Administration
      • Audit Logs
      • SMTP
        • Basic and oAuth Configuration
      • User Management
        • SAML Identity Providers
          • Okta
            • LightBeam Okta SAML Configuration Guide
          • Azure
            • Azure AD SAML Configuration for LightBeam
          • Google
            • Google IDP
        • Local User Management
          • Adding a User to the LightBeam Dashboard
          • Reset Default Admin Password
  • 📚Support & Reference
    • 📅Release Notes
      • LightBeam v2.2.0
      • Reporting Release Notes
      • Q1 2024 Key Enhancements
      • Q2 2024 Key Enhancements
      • Q3 2024 Key Enhancements
      • Q4 2024 Key Enhancements
    • 📖Glossary
Powered by GitBook
On this page
  1. Core Features
  2. Governance
  3. Access

Access Governance at a Data Source Level

PreviousActive Directory SettingsNextPolicies and Alerting

Last updated 9 days ago

Navigating to Access Governance at the Data Source Level

To view access governance details for a specific data source:

  1. Click on the Data Sources tab from the top navigation bar.

  2. In the list view, select any data source by clicking on its name under the Data Source Name column.

  1. The dedicated page for that data source will open.

  2. From the left-hand side panel, click on Governance.

  1. A dropdown menu will appear—select Dashboard to access the access governance overview for the selected data source.

Dashboard

The Access Governance dashboard at the data source level provides a centralized overview of user, group, and object-level access to sensitive data across connected systems.

  • Users Overview: Displays the total number of users and highlights:

    • Users with access to sensitive data (e.g., 20 users)

    • User breakdown by type (Employees vs. Contractors)

  • Groups Overview: Shows the total number of groups and:

    • Number of groups with access to sensitive data

    • Distribution between those with and without sensitive access

  • Entities Data Access by Users: A donut chart showing how many users have access to entities (e.g., 6 users across 86 entities). Helps visualize data reachability and usage patterns.

  • Objects with Open Access:

    • Total open objects (e.g., 16)

    • A bar graph of top departments with open access

    • Highlights departments like Sales responsible for most exposure

  • Objects with Excessive Access:

    • Total objects with excessive permissions (e.g., ~4 objects)

    • Departmental breakdown of over-privileged access

    • Helps flag risk from improper access controls

  • Unresolved Alerts: Lists critical issues requiring attention, such as:

    • Data shared publicly (e.g., “My Company Data Open to the World”)

    • Sensitive customer data exposure

    • Each alert links to detailed insights and remediation steps

Objects

The Objects section at the data source level provides visibility into all data objects owned by individuals or departments, along with insights into their sensitivity and access risk.

1. All Objects Tab

This tab displays the total number of data objects owned by each individual, with a breakdown of how many are classified as sensitive.

  • Example:

    • Owner: Kasim Sharif

    • Total Objects: 330

    • Sensitive Objects: 223

2. Open Access Tab

This view highlights objects that are accessible to a wide group of users, either internally or externally—posing a risk of unauthorized access.

  • Example:

    • Owner: Kasim Sharif

    • Open Access Objects: 16

    • Sensitive Open Access Objects: 16

3. Excessive Access Tab

This tab identifies objects where access levels exceed the required permissions, such as users with unnecessary edit or share rights.

  • Example:

    • Owner: Kasim Sharif

    • Excessive Access Objects: 4

    • Sensitive Objects with Excessive Access: 4

Users

The Users section provides a department-wise breakdown of all users who have access to data within a specific data source.

User Distribution by Department: Users are grouped into tiles based on their department (e.g., Finance, Sales, HR, Legal, etc.). Each tile shows:

  • Department name

  • Number of users in that department

Example:

  • Unknown: 111 users

  • Finance: 9 users

  • Sales: 9 users

  • HR1: 8 users

  • Others: Product, Legal, HR, Marketing

Note- Users can switch between grid and list view for ease of navigation.

Groups

The Groups section provides a comprehensive view of all user groups associated with a data source.

Group Overview Cards: Each card represents a group and displays:

  • Group Name

  • Number of Members in the group

Example:

  • PMUX: 5 members

  • test_inbox: 3 members

  • kaiftest, Scale test 5, hussnain_site: 2 members each

Note- Switch between grid and list views for easier navigation based on preference.

🧠
🛡️
Click on datasources tab and click on a specific data source
Click on the governance option in the left menu panel
Access Governance Dashboard at a datasource level
All objects in a datasource related to a user
Object with open access in a datasource related to a user
Objects with excessive access in a datasource related to a user
department wise users in a specific datasource
Displays all the groups associated with a specific datasource