Skip to main content

Understanding File Risk Levels and Prioritization

This article explains how Sonar calculates the risk level associated with your file sharing and how task priorities are assigned to employees and administrators.

1️⃣ How is a partner’s risk level calculated?

Sonar automatically evaluates risk by combining several criteria:

  • Volume of shared files with an external partner.

  • Content sensitivity: financial information, personal data (PII), contracts, passwords, etc.

  • Partner trust level: compliance data such as ISO 27001 or SOC 2 certifications lower the perceived risk, while a partner without certifications may be considered more exposed.

Example: sharing 3 non-sensitive files with an ISO 27001–certified provider is considered low risk. Conversely, sharing a complete organizational chart or salary data with an uncertified freelancer represents high risk.

👍 Good to know:

The risk level is dynamic: it is automatically updated each time a file is added or access is revoked. This ensures you can always focus on the most sensitive areas.

2️⃣ How are priorities defined?

To avoid overloading IT teams, Sonar delegates responsibility directly to employees through Albert. Each employee only receives requests related to the partners or public files they are responsible for, with one simple instruction: validate or revoke access.

👉 Requests are grouped at the start of the month

Tasks aren't sent as they come up: they are gathered and sent to the employee at the start of the month, so as not to interrupt them constantly.

👉 They are handled in bulk

The employee is asked to review everything above the detection threshold, presented as a list. There is still a way out: after two pages (20 items per page), they can postpone the rest to the following month.

👍 Good to know: you control the volume, through each rule's detection conditions. Tightening a threshold directly reduces the number of requests sent to your employees; widening it increases them. See Sonar Rules.

👉 You stay in control

  • You can flag a case as urgent ("Request priority handling") so that it is addressed first.

  • You can also validate or revoke a sharing yourself.

3️⃣ The concept of “Owner”

For each partner, Sonar automatically designates a responsible owner by combining two criteria:

  • the volume of documents shared with that partner by each employee,

  • the employee’s hierarchical position within the organization (as identified in the workspace or via Active Directory).

This “owner” is suggested by default but can be manually reassigned to the most relevant collaborator.

Did this answer your question?