
Data Lineage is a new product designed to give its customers unparalleled visibility into their organization’s data. It provides a comprehensive, visual map of the data’s entire lifecycle, from its origin, through various stages of modification and transformation, all the way to its usage and potential exfiltration.
By giving a full picture of the data’s journey, Data Lineage helps to:
- Enhance incident context: Quickly understand the full story behind an incident.
- Facilitate forensic investigations: Conduct more efficient and thorough investigations.
- Identify risky movements: Proactively spot and address potential data exfiltration risks before they happen.
Key Features
Data Lineage works by automatically reorganizing existing events from existing Netskope products, so there’s no upfront configuration required. It captures individual file activity events across cloud and endpoint environments, then correlates them using file identifiers, file metadata, user context, and timestamps. These connected observations are visualized as a directed graph, enabling investigators to trace a file from origin to destination, even across renames, edits and multiple transfers.
It’s centrally managed and available in the Netskope UI. A customer can navigate to Data Lineage by using the link in the DLP Incident page.
- Comprehensive File Activity Tracking: Records a wide range of user-initiated file operations, including copying, creating, downloading, editing, moving, renaming, sharing, and uploading.
- Integrated Incident Investigation: Seamlessly link from a DLP incident page directly to the file’s lineage for deeper context.
- Interactive Lineage Graph: A dedicated tab provides a graphical representation of the file’s lineage with rich, interactive features:
- Zoom and Focus: Easily zoom in and out to control the level of detail and shift the focus point.
- Tooltip: Get more information about either the file or the user activity by hovering the mouse over any element in the graph.
- Expandable View: Hide specific components to reduce clutter or expand them for more detail.
- Graph Manipulation: Drag and rearrange the graph to fit the user’s needs.
- Dynamic File Switching: Effortlessly switch the focus to view the lineage of different files.
How Data Lineage Works
Capturing Activity
Data lineage works by continuously monitoring file activity across your entire ecosystem—from endpoints to cloud applications. Every time a file is created, moved, copied, uploaded, or downloaded, we capture a detailed record of that event, including:
- Who accessed the file
- When it happened
- Where the file came from and where it went
- The file’s unique characteristics
Think of each captured event as a snapshot in time – a single step in the file’s journey.
Connecting the Dots
A file rarely stays in one place. It might be created on a laptop, uploaded to Google Drive, shared to a colleague, downloaded to their device, then uploaded to Slack. Each of these is a separate event, but they represent the same file moving through your environment.
Our platform automatically connects these individual events into a complete journey by correlating signals across them. We leverage file IDs assigned by applications when available. We also look at file metadata such as content hashes to tie events together, even when a file is renamed. When direct identifiers are not available, we rely on heuristics – weighing signals like filenames, user, timestamp, location etc. to determine when different events represent the same file.
Visualizing the Full Picture
When you search for a file’s lineage, the platform assembles its connections into an interactive visual timeline. You get a complete end to end view – trace any sensitive file back to its original source or forward to everywhere it has spread, even if it was renamed, moved between apps or moved between several users.
Visibility Scales With the Sources You Enable
Data Lineage draws from three complementary sources today, and each one fills in what the others can’t see:
- Real-time events – captured inline by the Netskope Client as users interact with the internet over the network.
- CASB API events – retrieved directly from cloud applications, covering activity that happens natively inside the app, including shares, edits, and moves that never cross the network.
Endpoint events – local file activity on managed devices, such as file copy to USB. The richest lineage comes from enabling all three.
Known Limitations
Data Lineage provides visibility into file movement across your cloud applications, but it does not capture every action or scenario. This section outlines the current scope and known gaps to help you set appropriate expectations.
Data lineage tracks file objects like documents, attachments, spreadsheets, presentations, and media and non-file objects such as chat messages, calendar events, and database records are out of scope. Applications and data sources report file activity at different levels of detail. When a source does not expose the identifiers needed to connect events or when those identifiers are ambiguous across files some events may appear as standalone items rather than as part of a single journey.

