Access mapping
How DSPM shows who and what can reach a data store: public grants, other accounts, access seen in audit events, encryption and keys, and attack paths.
Each store carries five views of access. They answer different questions, and the combination is what turns a label into a priority.
1. Public exposure
A store is treated as public only when an actual grant makes it so. For S3 the engine combines three signals, each suppressed by the matching public-access block setting:
- the provider's own policy verdict that the bucket is public,
- an ACL grant to all users or to all authenticated users,
- a bucket-policy statement with a wildcard principal.
A bucket with no public-access block configured but no public grant is not reported as public. For databases, the provider's publicly-accessible flag is used.
2. Other accounts
Bucket policies are read statement by statement. An Allow to a principal in an account other than the store's own is a finding:
| Grant | Severity |
|---|---|
| Write, delete or modify from another account | Critical |
| Policy-related actions from another account | High |
| Read from another account | High — raised to critical if object reads on the bucket were seen in the last 24 hours |
On AWS, Lake Formation grants are also checked for broad defaults and wildcard administrative grants.
3. Observed access
From cloud audit events over the last 30 days, grouped per store: the number of accesses, the number of distinct principals, the operations used and the time of last access. This is what actually happened, which is often narrower than what policy allows — and occasionally wider than anyone expected.
4. Encryption and keys
The Encryption engine reads DSPM's labels and flags sensitive data that is unencrypted (critical) or protected only by a provider-managed key (high). Key policies are parsed separately for wildcard principals, other accounts and grants. See Exposure, encryption and residency.
5. Attack paths
DSPM writes three facts about every store to the security graph — its top classification, whether it is public, and whether it is unencrypted at rest. The attack-path engine uses them to confirm paths whose last step reaches a sensitive store, so a chain of findings that ends at customer data is scored above one that ends at a scratch bucket. Each account also gets a count of the PII stores in it.
What access mapping does not do
It does not compute, for each store, the complete list of identities whose effective permissions allow a read. That is an identity question, answered per principal in CIEM on the same graph. CIEM findings that concern data access are merged into the DSPM findings view.