Kiteworks Agent Marketplace
Which AI assistant do you use?
Brief

Review sharing exposure with AI

A practical brief for discussing folder-level sharing signals, human review, and the limits of access and compliance conclusions.

Imagine a business owner asks, “What in our Vendor Share folder is exposed through sharing?” That is a useful question for a conversation with an AI agent, as long as everyone agrees what “exposed” means. Sharing Auditor works from Kiteworks folder metadata. It can surface a folder-level sharing signal, walk the visible tree, and offer a report. It cannot turn that signal into a complete access review.

What the signal can show

Kiteworks folder records carry an isShared flag when a folder is shared. The flag cascades to descendant folders, so a file inherits the exposure of the folder containing it. The agent resolves a share origin where the visible ancestry permits it and reports counts for the part of the tree it walked. This is an observed metadata signal, not a measured example or a conclusion about a particular customer’s data.

The same source sets the limits. File records do not carry the flag, and a file shared directly is invisible to this mechanism. The connector does not say who the members are or whether they are internal or external. A scan also begins within the scanning user’s visible access; folders above that top are not visible. A partial walk or an unreadable root flag should remain a limitation in the report.

Keep the business question precise

Ask whether a folder tree is marked as shared, which share origin is visible, and what portion of the requested scope was walked. Do not rewrite those answers as “everyone can access this,” “the link is external,” or “the organisation is compliant.” Membership, identity context, direct file shares, policy exceptions, and processes outside the folder are separate questions. A human owner should review the report, confirm the intended audience, and decide whether to investigate further.

If the question includes privacy obligations, GDPR Compliance Check can add file-visible signals such as personal-data terms, sharing exposure, and files older than a stated retention policy. Its own listing says that this is a slice of the framework. It cannot assess the full legal, organisational, or control context. Treat the output as a prompt for review, with the scope and limitations attached.

Questions for a review meeting

  • What exact folder and time of review are in scope?
  • Was the scan root’s sharing state read, or is it not assessed?
  • Is the reported origin complete within the visible ancestry?
  • Which files or subfolders were actually seen, and could direct file shares be missing?
  • Who will verify membership and business purpose through an approved source?
  • What decision, ticket, or follow-up belongs to the folder owner?

Keep illustrative scenarios labelled as illustrative. Do not add a member count, external-domain claim, risk score, or compliance conclusion unless your own evidence supports it. The agent can help organise observations; the accountable team supplies context and judgment.

For help framing a folder review, email sales@kiteworks.com or start a conversation. No Claude or MCP setup is needed to ask about the scenario. See the Sharing Auditor catalog entry, GDPR Compliance Check, and assistant support.