1️⃣ Connect Google Drive or Microsoft OneDrive
In the “Cloud integrations” section, an administrator connects:
Google (if Google Workspace is set up in your workspace),
Microsoft OneDrive / SharePoint (if Microsoft Active Directory is set up in your workspace).
Once the integration is in place, you can see the status of the scans — for example the latest scan of files and applications — and you can disconnect at any time via “Disconnect”. The first scan can take a few minutes, and up to several hours for the largest organizations.
👍 Good to know:
The permissions granted to Sonar are strictly necessary for it to work and are standard for any DLP tool. You can revoke them at any time from your Google or Microsoft console. For details on how data is processed, visit trust.tryriot.com.
2️⃣ The permissions required
Sonar needs certain permissions (the “scopes”) to work properly. They allow it to:
list your files and read their metadata (name, owner, creation date, location),
identify the risk level of the data shared,
detect internal and external shares,
and, if needed, restrict or revoke access when there is a risk.
With Google, there is no permission limited to updating shares alone: Sonar therefore has to request the full “write” scope, but it uses it exclusively to restrict or revoke access. You can check this at any time in your Google admin console.
Permissions are granted through domain-wide delegation (“Domain-wide delegation”) from the Google Workspace admin console, rather than through an individual administrator account. This avoids any interruption if the administrator leaves the company and makes rate limits (“rate limits”) easier to manage.
Microsoft (OneDrive / SharePoint)
On the Microsoft side, Sonar also uses full permissions, for performance reasons: this lets it apply restrictions directly and without excessive latency. As with Google, write access is used only for remediation (restricting or revoking a share), never to modify the content of your files.
👍 Good to know:
The permissions granted to Sonar are strictly necessary for it to work and are standard for any DLP tool.
You can revoke these rights at any time from your Google or Microsoft console.
For full details on how data is processed, visit trust.tryriot.com.
3️⃣ Choose your level of control
The setup is designed to accommodate even the most cautious administrators: each permission is explained in plain language at the time of connection, and two options can be turned off if you wish:
Write access — if you turn it off, Sonar stays read-only and will not be able to restrict or revoke shares automatically.
File content analysis — if you turn it off, risk assessment relies solely on titles and metadata, without reading the content.
This way you stay in control of the level of access granted, and can adjust it later.
4️⃣ Set the alert delay for public files
Sonar detects files shared publicly outside your organization. You can set a delay before you receive an alert, to avoid being notified about very temporary shares:
1 hour
1 day
1 week
1 month
1 year
👍 Good to know:
This keeps alerts focused on the files that stay exposed over time, and reduces the noise from short-lived shares.
5️⃣ Enable notifications
To empower your employees, you can enable automatic notifications:
Each employee receives alerts only for their own files to review.
Administrators keep a consolidated view of all files and actions in progress.
Notifications are sent by Albert, through each employee’s preferred channel (email, Teams, Slack or Google Chat).
They are sent at most once a week and include up to 5 files, to keep a steady rhythm without overloading teams.
📌 Key takeaways
Setup takes just a few clicks by an administrator, then the scan starts automatically.
On the Google side, permissions go through domain-wide delegation (authorize in Riot, then confirm in the Google console).
On the Microsoft side, it is “all or nothing”: you can fine-tune the permissions afterward from your console.
The write scope is used only to restrict or revoke, never to modify your content — and can be revoked at any time.
You can choose a level of control by turning off write access or content analysis.
