Employees discovery

See which employees and departments use each system, how often, and whose access should be reviewed, using data from email and SSO discovery.

Knowing a system exists is only half the picture. Employees discovery shows who uses each system, which departments they belong to, and how often they use it. This helps you understand what a system is really used for, decide what belongs in your inventory, and spot access that should be reviewed, such as former employees who still have active accounts.

Where the data comes from

Employee information comes from your email and SSO discovery:

SourceWhat it adds
SSOYour employee directory, including departments and account status, and which employees have access to each managed system
EmailWhich employees interact with each system, and how often, including systems not managed through SSO

Connecting both gives the most complete picture. See Discover your data sources with Radar.

What you can see for each system

Open a finding in Radar, or a data source in your inventory to see:

DetailWhat it tells you
Employees with accessHow many employees use or have access to the system
UsageHow often the system is used, from low to high
DepartmentsWhich departments the users belong to
Employee listEach employee who uses the system, with their account status

Use employee data to map your systems

Employee data helps you fill in your inventory with confidence:

  • Confirm a system is in use. High usage across many employees means it belongs in your inventory. A single employee with low usage may be a one-off sign-up.
  • Understand what it's used for. The departments using a system point to its business purpose. For example, a tool used mainly by HR is likely tied to recruitment or payroll. Use this to review its processing activities. See Map business purposes with processing activities.
  • Find the right owner. The department, or the heaviest user, is usually the best person to confirm a system's details. See Send data sources to coworkers for review.

Review access

Employee data also surfaces access that may need attention:

What you seeWhat it may meanConsider
An inactive employee with an active account on a systemA former employee still has accessAsking IT to remove the account
Many employees with access but low usageMore people can access the data than need toLimiting access to those who need it
A system used by employees outside the expected departmentData may be shared more widely than intendedChecking with the system's owner

For a broader view across all your systems, compare usage and employee counts in Analyze business impact across your data sources.

Things to know

  • Usage is based on the email and SSO activity discovery can see. A system employees use without email notifications or SSO sign-in may show low usage even if it's used often.
  • Systems found only through Microsoft Entra ID SSO don't show last sign-in dates, because Entra ID shares which apps are assigned to users but not when each user last signed in.
  • If departments are missing, check that your SSO directory assigns employees to departments or organizational units.

Related articles


Did this page help you?