
Quick summary: Unstructured document repositories like Microsoft SharePoint and Google Drive remain hotbeds for accidental data exposure due to layered sharing links and orphaned guest accounts. Integrating document sensitivity parameters with Oleria Trustfusion, an AI-native identity security platform, empowers compliance and engineering teams to institute rigorous identity security posture management over unstructured content lakes. This unified engine maps layered group hierarchies and exposes anonymous link sharing to continuously protect high-value corporate intellectual property.
Security and compliance teams gain a continuously maintained, identity-centric view of who can access classified or sensitive content in Microsoft SharePoint and Google Drive — mapped against each file or site's data classification label. Overly broad access to confidential, restricted, or regulated content is surfaced as an actionable posture finding, remediated through structured campaigns, and evidenced for auditors — without manual effort or point-in-time snapshots.
Why MS SharePoint and Google Drive are high-risk: Collaboration platforms are where the most sensitive documents in an organization actually live — contracts, financial models, HR records, source code, board materials, and customer data. They are also where access control is most frequently misconfigured: broad sharing permissions accumulate over time, classification labels are applied inconsistently, and access is almost never reviewed with the same rigor applied to structured databases or SaaS CRM systems.
SharePoint and Google Drive each have native classification and access control capabilities — Microsoft Purview sensitivity labels and Google Drive data classifications, respectively — but knowing which identities can actually reach classified content, and whether that access is appropriate, requires connecting classification signals to the identity layer. Without that connection, organizations face:
· Classification labels exist but access governance does not. Microsoft Purview and Google Workspace can label a document or drive as Confidential or Restricted, but neither platform answers the identity question: who, specifically, has been granted access to everything carrying that label, and should they have it? Classification without access governance is metadata without control.
· Access paths are layered and hard to trace. In SharePoint, a user may reach a classified document through a site permission, a SharePoint group, an Entra ID security group, a sharing link, or a combination of all four. In Google Drive, access can come through individual sharing, a Google Group, a domain-wide permission, or an inherited Drive structure. Flat permission reports from admin consoles miss this layering entirely.
· Sharing links create invisible exposure. Anonymous sharing links and broad organizational links in SharePoint and Google Drive grant access to classified documents without creating a named identity in the access model. This exposure is effectively invisible to any tool that only reads explicit permission assignments.
· External and guest identities accumulate unchecked. Contractors, partners, and vendors are routinely granted access to SharePoint sites and shared Google Drive folders containing classified content, then remain active long after the engagement ends. There is no native mechanism in either platform for continuous monitoring and automatic cleanup of stale external access.
· No cross-platform view. Organizations that use both Microsoft 365 and Google Workspace have classified content in both environments — with no native tool that provides a unified view of who can reach sensitive content across both platforms simultaneously.
· Access reviews for content platforms are rare or nonexistent. Formal access certification programs typically cover SaaS applications and identity providers. SharePoint sites and Google Drive folders are almost never included in structured access reviews, leaving classified content exposure unreviewed for months or years at a time.
Oleria Trustfusion ingests both the access model and the classification signals from SharePoint and Google Drive, joining them in the composite Access Graph. The result is a unified, identity-centric view of who can reach classified content across both platforms — with full path resolution, NHI coverage, continuous posture evaluation, and structured remediation.
.webp)
· Microsoft sensitivity label ingestion. Oleria reads sensitivity labels applied to SharePoint sites, document libraries, and files via Microsoft Graph API — including Confidential, Highly Confidential, Restricted, and custom label tiers configured in Purview. Labeled assets are tagged in the Access Graph as regulated data objects.
· Full SharePoint access path resolution. Oleria resolves every path by which an identity can reach a labeled SharePoint asset: direct site member, SharePoint group, Entra ID security group, Microsoft 365 group, sharing link, and inherited site collection permissions. No access path is hidden by SharePoint's layered permission model.
· Sharing link visibility. Anonymous sharing links and organizational sharing links that grant access to classified SharePoint content are surfaced in the Access Graph as exposure findings — not as a named identity, but as a documented open-access vector tied to a specific labeled asset.
· External and guest identity tracking. Guest accounts in Entra ID with access to SharePoint sites or document libraries containing classified content are identified, their access scope is mapped, and dormant or over-permissioned guest access is surfaced as a posture finding.
Google Workspace data classification ingestion. Oleria reads data classification labels applied to Google Drive files and shared drives via the Google Drive API and Google Workspace Admin SDK — including labels configured through Google's built-in classification feature or applied via DLP policies. Labeled assets are tagged in the Access Graph accordingly.
· Full Google Drive access path resolution. Oleria resolves access paths through individual file sharing, folder inheritance, shared drive membership, Google Groups, and domain-wide sharing policies. A user who can reach a classified file because they are a member of a Google Group that has edit access to a shared drive is as visible as one with a direct share.
· Domain-wide and link sharing exposure. Files or folders shared with "anyone in the organization" or "anyone with the link" that carry a classification label are surfaced as over-exposure findings — with the labeled asset, the sharing scope, and the label tier all captured in the Access Graph.
· External sharing governance. Google Drive files and folders shared externally with identities outside the organizational domain are identified and evaluated against classification policy. Classified content shared externally without a documented justification is flagged as a high-severity posture finding.
· Unified classified content access inventory: A single Access Inventory view across both SharePoint and Google Drive shows every identity with access to classified content — filterable by label tier, platform, identity type, and access path — without switching between admin consoles.
· Identity 360 View enriched with content access. Each identity's profile in Oleria’s Trustfusion shows not only their SaaS application entitlements but also which classified SharePoint sites and Google Drive resources they can reach, through which path, and at what permission level.
· NHI coverage for content platforms. Service accounts, OAuth-connected applications, and automated pipelines with access to classified SharePoint or Drive content are identified and included in posture evaluation — with human steward assignment and scope documentation.
· Posture Campaigns for classified content remediation. Over-permissioned access to classified content is packaged into Posture Campaigns with assigned owners, due dates, and integration with Microsoft 365 or Google Workspace admin workflows. Remediation is tracked to confirmed closure.
Stage 1 — API Ingestion of Microsoft Purview and Google Drive Sensitivity Labels: Oleria connects to Microsoft 365 via Microsoft Graph API (SharePoint, Entra ID, Microsoft Purview) and to Google Workspace via Google Drive API and Admin SDK. Connectors ingest site structures, file hierarchies, permission assignments, group memberships, sharing configurations, and sensitivity/classification labels. Connections are read-only and operate via standard OAuth 2.0 service principals with scoped, least-privilege API permissions.
Stage 2 — Structural Modeling of Collaborative Permissions in the Access Graph Architecture: Ingested data is normalized and loaded into the Access Graph. Each classified asset (SharePoint site, document library, file; Google Drive file, folder, shared drive) becomes a tagged node with its label tier and platform. Every identity's access path to that asset — direct or indirect — becomes a typed edge with path provenance: which group, role, or sharing mechanism grants the access.
Stage 3 — Automated Posture Assessment and Collaborative Sharing Optimization: Oleria Trustfusion evaluates access to classified content against configurable policy rules: which identity types may access which label tiers, whether external sharing of classified content is permitted, whether anonymous or org-wide sharing links on labeled assets are acceptable, dormancy thresholds for classified content access, and separation-of-duties constraints. Violations produce posture findings with severity scoring, asset context, and recommended remediation action.
Stage 4 — Automated Workspace Remediation and Auditor Evidence Generation: Findings appear in the Posture Dashboard filtered by label tier and platform. Posture Campaigns assign remediation to site owners, IT, or data owners with due dates and workflow integration. When access is removed or a sharing link is revoked, Trustfusion confirms the change in the Access Graph and closes the finding. The full chain — classification signal, access finding, remediation action, confirmation — is retained as audit-ready evidence.
A mature classified content access governance program across SharePoint and Google Drive produces measurable, auditor-defensible outcomes:
· Every classified asset has a known access population: For any SharePoint site or Google Drive resource carrying a sensitivity or classification label, the full set of identities that can reach it — and through which path — is known at all times, without manual enumeration.
· No anonymous or over-broad links on classified content: Sharing links that grant unauthenticated or organization-wide access to classified content are measured, trended toward zero, and addressed through Posture Campaigns. New over-broad links on classified assets generate findings within hours.
· External access to classified content is controlled and time-bounded: Every external or guest identity with access to classified SharePoint or Drive content has a documented business justification, a named internal owner, and a review date. Stale external access is detected continuously and remediated before it compounds into a data exposure risk.
· NHIs with classified content access are owned and scoped: No service account or application integration has undocumented, unowned access to classified SharePoint sites or Google Drive resources. Every NHI with classified content access has a human steward and a defined minimum scope.
· Classified content included in access review: SharePoint and Google Drive are part of the organization's formal access governance program — not excluded from it. Periodic reviews of classified content access are faster and more confident because Trustfusion pre-populates them with current, complete data and has addressed obvious anomalies continuously.
· Audit evidence produced on demand: When a regulator, external auditor, or internal compliance team asks who had access to a classified SharePoint site or Google Drive folder on a given date, Trustfusion answers the question directly — with point-in-time access data, remediation history, and policy evaluation results, without manual log reconstruction.

No. Oleria operates exclusively at the identity and access layer. It reads permission structures, group memberships, sharing configurations, and classification labels — it does not read, index, or store file content. This keeps Oleria's footprint minimal and avoids any privacy or data residency concerns associated with content inspection.
Oleria ingests sensitivity labels configured in Microsoft Purview Information Protection, which is the standard classification framework for Microsoft 365. This includes default label tiers (Public, General, Confidential, Highly Confidential) and any custom label taxonomy an organization has defined in Purview. Labels applied at the site, library, and file level are all supported.
Oleria ingests classification labels applied through Google Workspace's built-in Drive label feature, which allows administrators to define custom label fields and values that users apply to files and shared drives. Labels applied via Google Workspace DLP policies are also ingested where available through the API. Organizations that use a third-party classification tool integrated with Google Drive can have those signals ingested via Oleria's classification configuration options.
Sharing links — including anonymous links, organization-wide links, and specific-person links — are ingested as access vectors and surfaced in the Access Graph. For classified assets, any sharing link that grants access beyond the policy-permitted scope (for example, an anonymous link on a Confidential-labeled SharePoint document) is flagged as a high-severity posture finding. The finding includes the asset, the label, the link type, and the recommended remediation action (revoke or restrict the link).
Oleria's Microsoft 365 connector covers SharePoint Online sites and document libraries. Coverage of personal OneDrive for Business content is a configuration option. For most enterprise use cases, SharePoint (where team and project content lives) is the primary scope for classified content governance; OneDrive personal libraries can be included where policy requires it.
Yes. This is one of the primary value propositions for organizations running both platforms. Oleria ingests and normalizes access data from both environments into the same Access Graph, so a single query — "show me all identities with access to Confidential or above content" — returns results across both SharePoint and Google Drive simultaneously. Identities that exist in both environments are correlated into a single record, so a user's full classified content access footprint is visible in one view regardless of platform.
Purview and Google Workspace DLP classify data and enforce content-based controls — they answer "what data exists and where is it?" Oleria answers the complementary identity question: "who can reach it, through which path, and is that appropriate?" The two layers are designed to work together. Oleria ingests classification signals from Purview and Google DLP as inputs, then applies identity governance on top — providing the access control layer that content classification tools do not deliver on their own.
Oleria Trustfusion platform supports guided and automated remediation. In guided mode, Posture Campaigns notify site owners or data owners with the specific finding and the recommended action (revoke a sharing link, remove a guest from a site, narrow a group's permission scope), and track their response to closure. More advanced configurations can trigger automated remediation actions — such as revoking an anonymous sharing link on a Highly Confidential asset — through Microsoft Graph or Google Workspace API integrations.