In a collaboration-suite audit trail, a departing engineer touched 900 files in their final week, all within their entitlements — what does it support?
answer
- entitled access is not evidence of wrongdoing
- event type first, count second
- baseline the person against themselves
- sync clients manufacture bulk downloads
- external sharing link is the strong signal
basics
~20 sThat specific accesses happened, through a specific channel, at specific times — not that anything wrong occurred. Entitled access is normal, so any claim rests on event type, volume, timing and channel measured against that person's own history.
solid answer
~50 sStart by separating the event types, because they are not equally strong. A preview or view is weak; a browser download, a sync-client download to an unmanaged device, a copy into a personal drive, or a new external or anonymous sharing link is stronger, because each puts a copy outside the tenant's control — which entitlement never granted. Then baseline against the same person over twelve months and their team, not an absolute number: 900 events may be a normal week. Check the trail's artefacts before saying anything about a human: a sync client re-downloading a long-synced folder after a device rebuild emits thousands of download events with nobody behind them, and backup or indexing service principals appear as access too. Finally, be explicit about limits: the trail cannot show intent, cannot show whether a copy still exists off-tenant, and cannot show that anything was read. Write the events and the deviation; keep interpretation separate and labelled.
go deeper
Know that these audit trails record distinct operations — view, download, sync, share — and that a download or an external share is a different fact from opening a file in a browser.
Explain how you would build a baseline for one person and their team, and name the machine sources — sync clients, backup and indexing identities — that produce bulk access with no human behind it.
Show how you construct a defensible claim: strong event types, deviation against a stated window, alternatives eliminated, and an explicit list of what the trail cannot establish.
Own the separation of record from interpretation in anything that leaves the security team, so that an audit extract about a named individual is never circulated as a conclusion.
## Why entitlement makes this hard Most SaaS file cases have no permission violation in them. The person was allowed to open everything they opened; a technical control was never bypassed; no rule fired. So the evidence is not "they got in" — it is *what kind of access, how much, when, and through which channel*, judged against what that same person normally does. Getting this right matters because the output feeds a process where a person's reputation and job are at stake, and where a sloppy sentence is very expensive. ## Not all access events are equal Collaboration suites record distinguishable operations, and their evidentiary weight differs sharply: | Event | What it supports | |---|---| | Preview / view in browser | The item was rendered; no copy left the tenant | | Download | A copy exists on an endpoint | | Sync-client download | A copy exists on a device, possibly automatic | | Copy or move to a personal or unmanaged location | A copy left the governed area | | Sharing link created, especially external or anonymous | A copy is reachable by someone outside | | Permission grant to an external account | Continuing access after the person leaves | The last three are the interesting ones. Entitlement authorises a person to *use* material; it does not authorise them to make it reachable from outside, and a new external sharing link over a folder of proprietary material is a specific act with a specific record, not an ambient consequence of having access. ## Baseline before volume "900 files" is not a finding. Three baselines turn it into one, or dissolve it: 1. **The person against themselves.** What does a normal week look like for this engineer over the past year? Some roles touch thousands of files routinely. 2. **The person against their peers.** If everyone on the team shows similar activity, the number is a property of the role. 3. **The week against the year.** A burst that begins after the resignation date, or that runs outside their normal hours, is a deviation you can state; a flat continuation is not. State the comparison, not the raw count, and state the window you measured over — an interviewer will ask what your denominator was. ## Machine behaviour that looks exactly like exfiltration This is where careless analysts do the most damage: - **Sync-client re-download.** A rebuilt or newly enrolled laptop re-syncs every folder the user had, generating thousands of download events over a few hours with no human decision behind them. Check the client identity on the events and correlate with device-enrolment records before writing a line about the person. - **Service principals.** Indexing, backup, eDiscovery and data-loss-prevention tooling access files as an application identity, and unfamiliar tooling often looks alarming. - **Delegated and shared access.** An assistant, a shared account or a team drive can attribute activity to an identity that was not driving it. - **Bulk operations.** A single move or restore can expand into per-item events, inflating counts by an order of magnitude. A credible answer names at least two of these unprompted, because ruling them out is what makes the remaining events worth discussing. ## What the trail can never say - **Intent.** Downloading a specification the week before leaving is consistent with theft and with finishing a handover document. The record cannot distinguish them. - **Persistence of the copy.** The trail ends at the tenant boundary. Whether the files are still on a personal device is answerable only by device evidence, if any exists. - **Reading.** A download is a transfer, not comprehension — the same direction-of-claim discipline as everywhere else in this domain. - **Channels it never sees.** A phone photograph of a screen, a printout, or dictation into a personal note leaves no SaaS record at all. A clean trail therefore means "no deviation in this trail over the retained window", never "nothing left the company". ## Writing the finding Separate the layers explicitly, in this order: the records (event types, counts, times, client, device), the comparison (baseline and window), the alternative explanations you tested and eliminated, and only then the assessment, labelled as an assessment. Include what you could not determine. That structure is what lets the finding be re-examined by someone else later, and it is what stops an audit extract from being read as an accusation.
- Which single event type would change your assessment the most?Creation of an external or anonymous sharing link over proprietary material, or a copy into a personal, unmanaged location. Both put material outside the tenant's control and outlive the person's account, which is something entitlement never granted — unlike a view, which leaves the copy exactly where it was.
- How do you avoid attributing a sync client's bulk download to the person?Check the client identity on the events and whether the folder had been synced for months, then correlate against device-enrolment and rebuild records. A burst of thousands of downloads in a few hours from the sync client immediately after enrolment is machine behaviour; a human pattern is spikier, browser-driven and selective.
- The trail shows no deviation at all. Can you clear the person?You can state that the tenant's file-access trail shows no deviation over the retained window. That is a statement about one source, not about the person: photographs of a screen, printing, or a personal device holding a copy synced long ago leave nothing in this trail. Report the scope of what you checked alongside the result.
saying these in an interview costs you the question
- Treats a raw file count as a finding without a baseline
- Reads sync-client bulk downloads as deliberate exfiltration
- Claims the audit trail demonstrates intent
- Ignores that a view leaves the copy inside the tenant
- Says a clean trail proves nothing left the company
- Never checks whether a service principal generated the events