Skip to main content

Understanding Sonar

Sonar is Riot's module designed to protect against data leaks. It maps and analyzes everything your organization shares externally to help you regain control over your sensitive data.

1️⃣ What is Sonar for?

External shares are one of the leading sources of data leaks in organizations. Without a tool to keep track, you quickly end up with:

  • “temporary” access left open for months,

  • forgotten shares (partners, contractors, personal email addresses…),

  • access that is still active after an employee has left,

  • a volume of documents too large to track manually.

Without visibility, there is no way to make sure that only the right people have access to the right information. Sonar gives you that visibility back and lets you revoke unnecessary or risky access in a single click.


2️⃣ The goal behind Sonar: empowering your employees

Most DLP tools put all the work on the IT team, which has to decide the fate of thousands of files on its own — without knowing the context behind each share. Sonar takes the opposite approach, an “employee-first” philosophy built on three ideas:

  • Group by “partners” rather than by files. There are far fewer partners (the companies or people you share with) than documents, which makes prioritizing much easier.

  • Assign a risk level to each partner, based on the sensitivity of the data shared and the trustworthiness of the company involved.

  • Involve employees, who actually know the relationship, to provide the context: approve or revoke a share. The administrator stays in control and can make the final call at any time.

The result: the burden no longer falls solely on the CISO, and decisions are made by the people best placed to make them.

👍 Good to know:

Sonar is not designed to block your teams’ work, but to reduce your data’s exposure surface without creating unnecessary friction.


3️⃣ What Sonar analyzes

Sonar covers three complementary angles:

  • Shared files — across Google Drive, Microsoft OneDrive and SharePoint: who has access to which document outside your organization.

  • Applications (Shadow IT) — the third-party apps your employees sign into via “Sign in with Google / Microsoft”, the permissions they have been granted and their risk level.

  • Email auto-forwarding — automatic forwarding rules to personal addresses, a common exfiltration vector.

👍 Good to know:

Sonar focuses on cloud environments (Google and Microsoft). On-premise file servers and endpoint-level monitoring are not covered at this time.


4️⃣ How it works, in brief

  • Connection — a Google or Microsoft administrator authorizes Sonar in a few clicks.

  • Analysis — Sonar automatically scans your files, your shares and your applications, then updates regularly.

  • Risk assessment — an AI analysis identifies critical information (personal data, financial data, passwords…) and assigns a risk level to each partner and each application.

  • Alerts first — when they open Sonar, the administrator first sees a list of alerts: what actually requires action on their part (a high-risk partner not yet reviewed, a share to a personal email address, a risky application…).

  • The “Explorer” to browse everything — for free exploration, the Explorer brings together three tabs: “Partners” (external partners), “Apps” (applications) and “Files” (all shared files). The “Files” view can be filtered by owner, type of sensitive information, access level or location — personal drive or shared drive.

  • Prioritized tasks — Albert distributes the shares to approve or revoke to employees in small batches, ordered by risk priority, without ever overwhelming them.

  • Optional automatic revocation — the administrator can set rules to automatically revoke access left inactive for too long, so that no file stays overexposed simply because it was forgotten.

In this way, Sonar clearly separates what is up to the employee (providing context on a share) from what is up to the administrator (acting on alerts).


5️⃣ Your data stays protected

  • Sonar reads the titles, metadata and permissions of your files — not their content on a systematic basis.

  • Only potentially sensitive files have their content analyzed temporarily, solely to detect critical information.

  • No document content is stored: only labels (for example “contains a password”) and titles are kept.

  • Data is processed and hosted on European infrastructure.

To learn more about our compliance and how your data is secured, visit trust.tryriot.com.


📌 Key takeaways

  • Sonar gives you visibility and control over everything you share externally: files, applications and emails.

  • An “employee-first” approach: IT does not decide alone — employees provide the context.

  • Risk-based prioritization so you can focus on what matters.

  • Your content is never stored, and processing stays in Europe.

Did this answer your question?