A lineage graph is most useful when you can tell at a glance whether a file is somewhere it should belong. Managed Locations is how Data Lineage makes that distinction.
A location is the place a file instance lives, such as a cloud application instance, or a device. Data Lineage records a managed status for every location it sees and marks unmanaged locations in the graph, so a file leaving corporate control stands out without you having to read every node.
What Counts as “Managed”
Data Lineage does not maintain its own list of approved applications and devices. It uses the classifications you already set elsewhere in Netskope.
-
Applications are managed when the application instance is tagged Sanctioned. An instance tagged Unsanctioned is unmanaged. This is per instance, not per application, which is what lets Data Lineage tell your corporate Google Drive tenant apart from a user’s personal one. An instance with neither tag is recorded as Unknown.
-
Devices are managed when their device classification is Managed, and unmanaged when it is Unmanaged. A device whose classification is Not configured is recorded as such, and a device Data Lineage cannot classify is recorded as Unknown.
When the Status Is Set
Managed status is recorded when each activity arrives, using the instance tag or device classification in effect at that moment. It is stored with the activity and is not re-evaluated later.
Tagging an instance as Sanctioned or classifying a device as Managed changes how new activity is recorded. Activity that was recorded before the change keeps the status it had. A graph of past activity shows the classifications that were in place when each event happened.
Reviewing Your Managed Locations
Select Managed Locations from the Data Lineage landing page or from the toolbar in any graph view. A guided walkthrough opens and shows you in order:
- Applications: Every application instance tagged Sanctioned, listed as application name and instance name. From here you can open your application instance configuration to add or change tags.
- Devices: Every device currently classified as Managed, listed by hostname. From here you can open Device Management to review or change classifications.
- Finish: A summary of what Data Lineage will treat as corporate based on the above.
The walkthrough is a review. Changes are made in application instance configuration and Device Management, and the walkthrough links directly to both.
How Locations Appear in a Graph
Each node shows its location, such as the application instance or the device hostname. Unmanaged locations carry an orange unlocked marker on the node, on the node’s timeline header, and on each timeline activity that took place there. The graph legend describes it as “Files with this icon are located in an unmanaged location.” Only Unmanaged locations are marked. Managed, Unknown, and Not configured locations show no marker.
Why This Matters for Investigations
Two patterns are the usual reason to look:
-
Corporate to personal: A file moves from a Sanctioned instance to a personal instance of the same application. Both nodes carry the same application icon; the instance name plus the unmanaged marker is what tells them apart.
-
Managed to unmanaged devices: A file is copied from a corporate laptop to a device that is not enrolled. The destination shows as unmanaged, which is often the last visible point in the file’s journey.
Known Limitations
An instance that has not been tagged, or a device that has not been classified, is not marked as unmanaged. It shows no marker at all. If you rely on the marker to spot exfiltration, review your Sanctioned tags and device classifications first, so that the absence of a marker means what you expect. Managed status is set from inline and CASB API activity. Endpoint-sourced activity does not currently carry it, so nodes built only from endpoint events show no marker and appear as Unknown in search.

