Employees discovery
See which employees and departments use each system, how often, and whose access should be reviewed, using data from email and SSO discovery.
Knowing a system exists is only half the picture. Employees discovery shows who uses each system, which departments they belong to, and how often they use it. This helps you understand what a system is really used for, decide what belongs in your inventory, and spot access that should be reviewed, such as former employees who still have active accounts.
Where the data comes from
Employee information comes from your email and SSO discovery:
| Source | What it adds |
|---|---|
| SSO | Your employee directory, including departments and account status, and which employees have access to each managed system |
| Which employees interact with each system, and how often, including systems not managed through SSO |
Connecting both gives the most complete picture. See Discover your data sources with Radar.
What you can see for each system
Open a finding in Radar, or a data source in your inventory to see:
| Detail | What it tells you |
|---|---|
| Employees with access | How many employees use or have access to the system |
| Usage | How often the system is used, from low to high |
| Departments | Which departments the users belong to |
| Employee list | Each employee who uses the system, with their account status |
Use employee data to map your systems
Employee data helps you fill in your inventory with confidence:
- Confirm a system is in use. High usage across many employees means it belongs in your inventory. A single employee with low usage may be a one-off sign-up.
- Understand what it's used for. The departments using a system point to its business purpose. For example, a tool used mainly by HR is likely tied to recruitment or payroll. Use this to review its processing activities. See Map business purposes with processing activities.
- Find the right owner. The department, or the heaviest user, is usually the best person to confirm a system's details. See Send data sources to coworkers for review.
Review access
Employee data also surfaces access that may need attention:
| What you see | What it may mean | Consider |
|---|---|---|
| An inactive employee with an active account on a system | A former employee still has access | Asking IT to remove the account |
| Many employees with access but low usage | More people can access the data than need to | Limiting access to those who need it |
| A system used by employees outside the expected department | Data may be shared more widely than intended | Checking with the system's owner |
For a broader view across all your systems, compare usage and employee counts in Analyze business impact across your data sources.
Things to know
- Usage is based on the email and SSO activity discovery can see. A system employees use without email notifications or SSO sign-in may show low usage even if it's used often.
- Systems found only through Microsoft Entra ID SSO don't show last sign-in dates, because Entra ID shares which apps are assigned to users but not when each user last signed in.
- If departments are missing, check that your SSO directory assigns employees to departments or organizational units.
Related articles
- Reviewing findings: add discovered systems to your inventory
- Analyze business impact across your data sources: compare systems by usage and access
Updated about 1 hour ago
