DLP - Drive Document Access

Justin_W
Contributor II

I'm having a hard time finding a "correct" way to tackle this:

 

We use DLP for various things here in Google Workspace, and I'll get notifications from time to time related to this. 

 

The thing is, if I get notification it's saying who the file owner/share is and what the document name/ID is.

 

My questions is: How am I expected to verify this and follow-up?

Since I don't actually have access/permission to the file, I can't just click and see if it's something legitimately problematic.  

 

We have a 3rd-party tool that we can use to grant access, but it doesn't work in real time so it's not a great fit at times.

 

A quick search just suggest maybe Vault can do this - but that seems like the wrong tool for the job.

 

I get the privacy/ethical concerns/considerations to this.  

 

So how is anyone else doing this? 

 

Put another way: How do I grant myself permission (if only temporary) to view a document/file in Drive without notifying the owner of that file?

Are ya'll using DLP? Are you just ignoring the reports? Are you reaching out directly to each flag and having them show/explain/share the document/file? Even students?

2 REPLIES 2

kaned
Contributor II

1.  You could use Gam to grant yourself access.

2.  I simply go into Google Vault and search for the file under that user account.

3.  Use the investigation tool to view/download the file or add a user to that file.

I could definitely see that it could be more convenient to be Able to simply take over a file, but I could certainly see that as a security risk as well.

 

I agree on the security risk. This is why Google Drive is defaulting to least access.

The superadmin should not by default have access to everything.

GAM and Investigation Tool can be used to gain access, and then that action is logged.

--
https://wheretofind.me/@NoSubstitute