Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    DataSec Command Center
    Identities

    Identities

    The DataSec Command Center (DCC) Identities page provides a consolidated view of all identities with access to sensitive data across your connected data stores. Use this page to review identity categorization, evaluate access patterns, and identify potential risks associated with internal, external, and unlinked users.

    Identity Categorization

    DCC categorizes identities into three types. Both internal and external users are assumed to be human identities only.

    • Internal Users: A human identity with an email address matching your organization’s internal domain (e.g., employee@company.com). Internal users may or may not be connected to User Management (IDP).
    • External Users: A human identity with an email address not matching your internal domain (e.g., vendor@externalcompany.com). External users may or may not be connected to User Management (IDP).
    • Unlinked: An identity that can’t be classified as internal or external (e.g., no internal domains configured), or can’t be classified as human or non-human. Unlinked is the catch-all category.

    Data Sources

    DCC aggregates identity data from three sources. Each source contributes different identity types and attributes. The availability of specific identity details depends on which sources you configure in your tenant:

    • User Management (IDP): Provides identity provisioning and organizational attributes.
    • CASB API: Provides identity data from connected SaaS applications.
    • DSPM: Provides identity data from IaaS, PaaS, on-premises, and data platform environments.

    Identity Table

    Select an identity type from the left navigation panel to filter the table. The heading displays the identity type and total record count.

    The identity table displays the following columns:

    ColumnDescription
    NameThe identity’s name and email address.
    Data TypesThe data type classifications of files the identity has access to, displayed as tags. When more than three data types exist, a +N indicator shows the remaining count.
    IDP StatusThe identity’s status in User Management (e.g., Active, Suspended, Locked Out, Deactivated). A dash indicates the identity isn’t connected to User Management (IDP).
    Linked AccountThe number of linked accounts associated with the identity. A dash indicates no linked accounts.

    Identity Details

    Click an identity in the table to open a drill-down side panel. The panel contains two tabs: Overview and Data Store/Destination.

    Overview Tab

    The Overview tab displays basic information about the identity:

    • Email: The identity’s email address.
    • Organizational Unit (OU): The organizational unit the identity belongs to. (Available only if the identity is connected to User Management (IDP))
    • IDP Status: The identity’s status in User Management. (Available only if the identity is connected to User Management (IDP))
    • UCI Score: The User Confidence Index score, sourced from UEBA (behavior analytics).

    Data Store/Destination Tab

    The Data Store/Destination tab lists the data stores the identity has access to, including:

    • The data types detected per data store.
    • The last active time for the identity within each data store (sourced from DSPM).
      • Note: This field is not available for SaaS application data stores. 
    In this Topic
    • Identities