Organizations today are managing rapidly growing volumes of data. Over years of collaborating with our customers’ data center teams, I have watched the vocabulary of scale shift dramatically by moving from gigabytes to terabytes, and now, routinely to petabytes. Yet the real challenge isn’t just the sheer volume; it’s the format. A staggering 80 percent or more of this stored information is unstructured data, which is file-based content isolated outside the clean rows and columns of traditional databases.
These unstructured data environments comprise word processing documents, spreadsheets, presentations, media, source code, and more. Within this mix, files range from outdated, redundant junk to the organization’s absolute “crown jewels.” Managing this complexity is where Data Access Governance (DAG) becomes critical. It is the discipline of identifying what these files are, evaluating their sensitivity and relevance, and ensuring they are strictly secured against unauthorized access.
What is the driver of data access governance?
Today’s biggest driver for data access governance may be the deployment of AI inside the organization. As tools like Microsoft Copilot are rolled out and begin drawing on internal data, the questions of what AI is going to find, and who it is going to tell, exist not only in the IT department, but up through the business to organizational leadership. Fortunately, these tools respect existing permissions: they show each user only what that user can already access. That is also the problem. Copilot grants no new access, but it removes the obscurity that has quietly protected overshared data for years, so anything a user can reach becomes findable with a single prompt. The safeguard is only as good as the access permissions underneath it.
While every organization’s data landscape is unique, their journeys toward mastering Data Access Governance follow a predictable path. To help businesses chart their progress, we recently published a new DAG Maturity Model, which categorizes companies into one of five distinct organizational states. In this article, I will define and explore the first two foundational levels of this model: Unmanaged Risk and Visibility.
“Organizations are mandating AI deployments like Microsoft 365 Copilot, and that’s accelerating data access governance projects. Copilot can surface anything a user already has access to, so overshared data that was out of sight becomes a real exposure. The DAG Maturity Model gives organizations the phased roadmap that’s been missing to fix that, one stage at a time,” according to David Condrey, the OpenText Data Access Governance engineering lead.
A data access governance maturity model helps organizations assess how effectively they discover sensitive data, understand access, remediate exposure, and sustain governance.
Level 1: Unmanaged data access risk
This classification often begins with a simple, sobering question: “Can you confidently say where your most sensitive unstructured data lives, and who currently has access to it?”
Organizations in the Unmanaged Risk state cannot confidently identify where sensitive unstructured data resides or who can access it. Data continues to grow, but the organization lacks the visibility, tools, and processes needed to govern it effectively.
This blind spot is the result of years of compounding and unmanaged growth. Network shares, cloud repositories, and collaboration spaces have accumulated continuously, leaving behind complex permissions structures and unclear ownership. In this state, organizations are effectively making decisions with limited visibility. Access problems and vulnerabilities rarely get caught proactively; instead, they surface only after an audit failure, a disruptive security incident, or an urgent regulatory request.
This operational vulnerability exists primarily because the necessary expertise is treated as a minimal, incidental afterthought. Rather than employing dedicated data custodians, organizations at this stage rely on IT generalists to manage permissions reactively. Handled as a secondary duty, system management depends entirely on undocumented, tribal knowledge. Because no single role explicitly owns data access governance, the organization is trapped in a classic circular challenge: it struggles with a problem it cannot quantify, meaning it often cannot yet articulate the exact expertise it is missing.
The day-to-day characteristics of this state are as predictable as they are dangerous. Unstructured data grows continuously without any centralized oversight, while data ownership remains entirely informal or undefined. Permissions are assigned on an ad hoc basis and rarely, if ever, reviewed. Crucially, access control is entirely disconnected from the broader identity lifecycle. When employees change roles or leave the company, their permissions remain intact, causing a massive accumulation of orphaned accounts and access. While internal teams might suspect they are exposed to significant risk, they lack the tools and data required to prove it.
Ultimately, this structural neglect drives a severe business impact. Operating in a purely reactive posture, these organizations face elevated exposure to insider threats and data leakage. When compliance mandates call, audit requests drag on, consuming large amounts of manual effort and specialized labor to assemble data by hand. This slow, painful response to regulatory inquiries ultimately results in an environment with incredibly low confidence in its own security and governance.
Key characteristics of unmanaged risk
- Sensitive data locations are largely unknown
- Ownership is informal or undefined
- Permissions are granted and rarely reviewed
- Access governance is disconnected from identity lifecycle processes
- Former employees often retain unnecessary access
- Audits require significant manual effort
- Risk exposure is difficult to quantify
Level 2: Visibility into data and permissions
A step up from Unmanaged Risk, organizations in the Visibility state have begun taking control of their data landscape. At this level, companies are actively deploying specialized tools such as OpenText™ Voltage™ Data Security Platform to locate where sensitive unstructured data is being stored and OpenText File Reporter (part of OpenText Data Access Governance) to specify who has access to it. However, a critical hurdle remains: while they now possess the insights to see their exposure, actual remediation and ongoing governance are still performed largely through slow, manual processes.
At this stage, the expertise required shifts to a diagnostic approach involving personnel who can analyze access permissions and content data, interpret what metrics reveal, and prioritize the highest-risk repositories. However, this capability represents the skill to read and evaluate risk rather than remediate it systematically, and it typically resides with only a handful of security or IT analysts. Plus, the people in the line of business who understand the data and the access needs best are left out of the process altogether.
Operationally, the characteristics of the Visibility state reflect an environment where sensitive data is identified and classified, access permissions and group memberships can be analyzed and reported, and high-risk repositories are prioritized. Despite this visibility, exposure is not consistently controlled, configuration drift is only visible when a new scan is run, and remediation still requires manual effort.
Ultimately, this phase delivers a distinct business impact through a clear understanding of data risk, faster audit preparation, better-targeted effort, and raised executive awareness of exposure.
Key characteristics of visibility
- Sensitive data can be discovered and classified
- Access permissions can be analyzed and reported
- High-risk repositories can be identified
- Data exposure is visible but not consistently remediated
- Governance processes remain largely manual
- Configuration drift is detected through periodic scans
- Business stakeholders remain minimally involved in governance activities
How to begin improving data access governance
One of the most common reasons data access governance programs stall is the assumption that the entire data estate must advance together. It doesn’t. The most effective programs start with the data that matters most: identify the data sets that carry the greatest business risk, understand who can reach them, and apply controls in proportion to that risk.
Established methodologies can help structure that prioritization. Gartner’s Data Security Governance (DSG) framework is one worth investigating, particularly for organizations with access to Gartner research. Whichever approach you adopt, the principle is the same: let business risk decide where governance starts.
Applied to the maturity model, that means maturity can be deliberately uneven. The repositories holding your most sensitive data can advance to Enforcement or Certified Governance while lower-risk data remains at Visibility. Not every data set needs to reach Continuous Governance; the goal is to match maturity to risk.
The payoff is early, measurable return. Risk falls fastest where it is highest, results reach leadership quickly, and each success funds the next phase. The same logic applies to AI rollouts: clean and connect your highest-priority repositories first. Every cycle brings more of the estate onto the curve. Prioritization tells you where to start; the maturity model tells you how far to go.
Coming in part two
Understanding where your organization stands today is only the first step. In our next post, we will climb the maturity curve to explore how forward-thinking companies transition from mere awareness to active control. We will dive deep into Level 3: Enforcement and Level 4: Certified Governance, mapping out how to transform manual workflows into automated, policy-driven defenses. Finally, our concluding post will unveil the ultimate destination for unstructured data management and security: Continuous Governance. Stay tuned as we break down how to stop chasing data risks and start preventing them entirely. Assess your current state and identify the next practical step for reducing data access risk.










