Veritas Data Insight User's Guide
- Section I. Introduction
- Section II. Data Insight Workspace
- Navigating the Workspace tab
- Analyzing data using the Workspace views
- Viewing access information for files and folders
- Viewing user activity on files or folders
- About visualizing collaboration on a share
- Viewing access information for users and user groups
- Section III. Data Insight reports
- Using Data Insight reports
- About Data Insight security reports
- Permissions reports
- Permissions Search report
- Creating a Permissions Query Template
- Permissions Query Template actions
- Ownership Reports
- About Data Insight storage reports
- About Data Insight custom reports
- Managing reports
- Viewing reports
- Using Data Insight reports
- Section IV. Remediation
- Configuring remediation workflows
- Managing workflow templates
- Creating a workflow using a template
- Managing workflows
- Using the Self-Service Portal
- About the Self-Service Portal
- Managing data
- About managing data using Enterprise Vault and custom scripts
- About adding tags to files, folders, and shares
- Managing permissions
- Configuring remediation workflows
- Appendix A. Command Line Reference
About control points
A control point is the level in a file system heirarchy where permissions must be changed. A control point on a share is defined as a folder which is primarily accessed by a set of users who are either a subset of or are completely different from the users who access its sibling folders within the share. The users are grouped into sets using well describing attributes.
Control points can be any of the following:
Folders where permissions deviate from the parent folders, either the folder does not inherit permission from the parent folder or unique permissions are assigned at that level in the hierarchy.
Folders where the active users differ significantly from active users of its sibling folders.
To identify control points within a share, Data Insight starts its analysis from the defined folder depth within the share. Data Insight then compares the user set that is accessing such a folder for similarity with its ancestors. The control point is defined at the level below which the similarity breaks significantly. The default folder depth for computing control points within a share is 5. This means that by default, Data Insight evaluates the folder hierarchy 5 levels deep to calculate the control points within a share.
For more information on configuring the depth for calculating control points, see the Veritas Data Insight Administrator's Guide.
You can use information about control points within a share to provide recommendations to improve existing permissions.