Data Store Discovery
The Data Store Inventory page is found in the Management section of the left navigation.

- When no data stores are connected to Netskope DSPM, the Super_Admin can connect a new data store. Depending on the type of data store, the Super_Admin may or may not need to onboard infrastructure to Netskope DSPM. When connecting Cloud Service Provider platforms such as AWS, GCP, or Azure, the Super_Admin can enable Auto-Discovery. Once Auto-Discovery is enabled, Netskope DSPM automatically discovers all data stores and displays them for review.
- Discovered Data Store list with the Data Service and Endpoint details can we found under the Discovered tab.

- The admin can now connect to each of the listed data stores by providing the right credentials. Once the admin performs the discovery, the data store auto-discovery feature is turned on for the future with a default scan frequency of 60 minutes.
- Additionally, Netskope DSPM performs daily scans of Amazon Elastic File System (EFS), Amazon Elastic Block Storage (EBS), and Google Persistent Disk volumes to identify and display unmanaged data stores such as MySQL, PostgreSQL, MariaDB, Oracle and SQL Server installed within these volumes. These unmanaged volumes can be discerned from other data stores using the “Unmanaged Data Store is true” filter.
- Data store auto-discovery is only supported on CSP Platforms (AWS, GCP, and Azure). Depending on platform roles, Super_Admins can control permissions other platform users have for connecting to a data store and getting visibility into the connected and discovered data store inventory.
- When a data store is connected, you will see it in the Connected tab with data store metadata details: platform, service, data owners, region, sensitivity score, and data store risk rating, along with the number of Entity Data Types, number of sensitive fields or files, number of sensitive records, and associated data tags. Use the Column icon dropdown to reveal other possible column headers, such as total size, sensitive data size, account, and endpoint.

- The Overview section details data store size, sensitive data size, and query and alert counts.
- Each connected data store also displays a tooltip with status details on the last scan, including whether the scan was successful, failed, in progress, or aborted. It also shows time and date details for last and next scans. View the tooltip by hovering over the colored status icon to the right of the data store name.

- When a data store is connected, Netskope DSPM also performs configuration analysis to determine misconfiguration risk and privilege analysis to determine data store access. Comparing data store access with a user’s last access time helps determine their Over Privileged Risk Score. These are also displayed by expanding the data store display using the black right-facing arrow to the left of the data store name.
Visit our Configuration Analysis article for details on misconfiguration risk calculations.
Maintaining Connected Data Stores
Once connected to a data store, the administrator can use the Edit icon under Actions to update configurations if needed. These configurations are identical to the ones selected when they first connected the data store. Other supported actions include:
- Turning on/off auto-scan
- Initiating a manual scan
- Applying or removing Data Tags on the object-level (databases, schemas, and tables) or file-level. To learn more, please visit Using the Classification Management Page.
- Assigning sidecar pools
- Disconnecting data stores
- Quick-filtering to show only scans in progress

Data Catalog Hierarchy
Data Stores for Structured Data
Each data store can be drilled down into its data set hierarchy to the respective databases, schemas, and tables. At each level of the data set hierarchy, you can see the respective metadata details:
- For a database, you will see the database-level owners, schemas, tables, fields, sensitive fields, sensitive records, and database-level data tags.

- For a schema, you will see the schema-level owners, tables, fields, sensitive fields, sensitive records, and schema-level data tags.

- You will see the table-level owners, fields, sensitive fields, total records, sensitive records, and table-level data tags at the table level.

- Clicking on a table name will take you to the Classification Management page, with fields filtered for this schema. Visit our Classification Management Overview article for details and to see our built-in classifiers.
Data Stores for Unstructured Data
From the Data Inventory page, an unstructured data store expands to show the total size and sensitive data size for the data store, number of files, file extensions, and file types, along with standard configuration and privilege analysis. The number of sensitive files appears in the Sensitive Fields/Files field.
- Clicking on the data store name reveals all information for recently sampled files in the data store, including classifiable file types, size, sensitivity level, associated data tags, and occurrence count (at last scan).

- Clicking on the number of Entity Data Types associated with an unstructured data store from the Data Store Inventory page will show a smaller snapshot of the view above. Clicking on the number of sensitive files will take you to the next page:

Shadow Data Analysis
If supported by the data store, the Shadow Data Analysis section will show the size of stale data, when it was last accessed, and by whom.
This can be enabled and configured when connecting a new data store from the Capabilities page. Customize the last access time and period for stale data.
![]() |
![]() |
![]() |
Deleted Objects
When objects are deleted from your remote system, they can be identified at each level of your Data Set hierarchy by clicking the Show Deleted button. The object will appear with a deleted icon to the right of its name.

Bulk Actions to Data Stores
By clicking on the left side pick-list, you can take the following actions on multiple data stores at once:
- Edit tags
- Enabling or disabling auto-scan
- Editing owners
- Disconnecting (details in section below)

Using the method described above, you can adjust tags and owners in bulk throughout the Data Catalog hierarchy. Once you’ve saved the bulk action, you’ll be informed if it was successful or only partially applied.
Saved Views
The Data Store Inventory supports defining saved views. Each saved view is a saved configuration of displayed columns & applied filters, which you can switch between as you operate within different contexts. For example, one saved view might allow you to research data stores with certain scan results, while another saved view lets you focus on data stores with specific tags. Saved views can also support your team outside of the Netskope DSPM application by letting you repeatedly create CSV exports of specific columns and rows.
Each saved view is a custom configuration of displayed columns and applied filters. You can use them to switch contexts quickly (e.g., researching high-severity fields vs. reviewing unverified classifications) or to repeatedly export specific CSV reports.
There are two view types:
- Default View: Displays the most important columns with no filtering applied.
- Saved Views: Private, user-created views that enforce your specific filters and column layouts.
Saved views appear as clickable boxes within a view ribbon. The currently active view is highlighted in light purple.


Create a Saved View
- Click the Add button (
+). - In the modal, enter a unique name.
- (Optional) Check Set as Preferred View, and click Save.

Rename a Saved View
- Select the view
- Click the context menu icon (⋮), and select Rename.
- Update the name and click Save.

Update Filters and Columns for a Saved View
- Select the view.
- Adjust your filters/columns.
- Click the context menu icon (⋮), and select Save Changes.

Designating a View as Preferred
- Select the desired view
- Click the context menu icon (⋮)
- Select Set as Preferred.

Delete a Saved view
- Select the view
- Click the context menu icon (⋮), and select Delete.

Disconnecting Data Stores
There are instances where you may no longer need Netskope DSPM to monitor a connected data store, including data stores that may be empty, decommissioned, or mistakenly connected. Netskope DSPM allows for disconnecting of data stores, removing their data from other screens. The application will then only display information related to connected and scanned data stores.
Disconnecting a data store results in the following outcomes:
- The data store is moved from the “Connected” tab to the “Archived” tab. It can later be reconnected.
- The data store’s data is removed from other screens within the application, including:
- Classification Management (fields)
- User Assessment (Usernames, historical queries)
- Privileges Analysis (Data Store)
- Alerts & Tasks (alerts are auto-resolved)
- Employee Management (Usernames, user-to-employee mappings)
- Service Accounts (Usernames)
- A user activity record is created in the Activity Logs.
- All associated Data Owners are notified using their preferred workflow, as defined in the [User Profile]().
The ability to disconnect data stores is limited to anyone with the RBAC permission to delete data stores, including users with the “Super_Admin” role.
– Update the policy to no longer reference the data store; or
– Deactivate the policy.
To disconnect a data store:
- Navigate to the Data Stores > Data Store Inventory screen.
- Click on the Connected tab to display a list of connected data stores.
- Under the Actions column, click the menu icon for the data store you wish to disconnect.
- Select the Disconnect option.
- The UI will display counts of records that will be impacted by the disconnection. To proceed, click the Disconnect button.
- The affected Data Store will be moved from the “Connected” tab to the “Archived” tab.
To disconnect data stores in bulk:
- Navigate to the Data Stores > Data Store Inventory screen.
- Click on the Connected tab to display a list of connected data stores.
- Click the check boxes in the far left column to select which data stores to disconnect
- Click Disconnect from the options shown in gray above the connected data stores.
- The UI will display counts of records that will be impacted by the disconnection. If you need to adjust policies for a data store disconnection, that alert will display, and you can proceed with the disconnecting the data store(s) not affecting policy.
- To proceed, click the Disconnect button.
- The affected Data Store will be moved from the “Connected” tab to the “Archived” tab.

When disconnecting an unstructured data store, the disconnect modal displays the number of classified sensitive files that will be removed from Netskope DSPM.
Archiving Data Stores
In some cases, there may be discovered data stores you do not wish to ever connect to Netskope DSPM. You can move such data stores from your main views, which then permits you to focus on those you care to monitor.
Archiving a Data Store
- Go to the Discovered sub-tab.
- For the Data Store you wish to archive, in the Actions column click its Archive icon.
- The Archive Data Store modal is displayed.
- In the modal, enter a Reason value (optional) that explains why this Data Store is being archived.
- Click the Archive button.
At this point, the Data Store is moved from the Discovered tab to the Archived tab.
Viewing Archive Details
- Go to the Archived sub-tab.
- For the Data Store you wish to investigate, click its View Archive Details icon.

Unarchiving a Data Store
You can connect a previously archived data store by taking the following steps:
- Navigate to the Archived tab.
- For the data store you wish to reconnect, click Connect.

Once you’ve completed the steps to connect, the Data Store is moved from the Archived tab back to the Connected tab.




