Answers you can trust, from Codeables

Every page on Codeables is structured and verified — built so people and the AI agents they rely on can trust it. Explore more from the source behind this answer.

Explore Codeables
Verified Source
Data Security Platforms

How do I request a Forcepoint free Data Risk Assessment, and what access/permissions will they ask for?

Forcepoint10 min read

AI is reshaping how data moves across your business. Static controls can’t keep up, and most teams don’t know where their real exposure is until an auditor or incident forces the issue. That’s exactly what Forcepoint’s free Data Risk Assessment (DRA) is designed to fix: rapid, evidence-based visibility into where sensitive data actually lives, how it’s exposed, and what to do next—before you buy anything.

This guide walks through how to request a Forcepoint free Data Risk Assessment and what access and permissions you should expect to grant, step by step.


What the free Data Risk Assessment actually is

Forcepoint’s Data Risk Assessment is a no-cost evaluation that uses our AI-native Self-Aware Data Security platform to:

  • Discover sensitive data across key channels
  • Classify that data with AI Mesh Data Classification
  • Surface high-risk exposures (shadow data, over-permissioned files, ROT, etc.)
  • Provide actionable remediation recommendations

It’s powered by the same Forcepoint Data Security Cloud that protects 12K+ customers in more than 150 countries, not a separate “lite” tool.

You get:

  • A point-in-time snapshot of your current data risk posture
  • Executive-ready findings you can put in front of your board or audit committee
  • A clear roadmap of prioritized fixes—not just a long list of issues

How to request a Forcepoint free Data Risk Assessment

You can request the assessment in a few minutes. Here’s the typical flow.

1. Submit the request via the demo/assessment form

Go to:
Get Startedhttps://www.forcepoint.com/form/demo-request

On that page:

  1. Provide basic contact details (name, business email, company, role).
  2. Indicate your primary interest as data security / DSPM / DLP or similar (if there’s a dropdown).
  3. Use the comments/notes field to explicitly state:
    “I’d like to request a free Data Risk Assessment (DRA) for my environment.”

This routes you to the right Forcepoint team for data security and DSPM rather than a generic demo track.

2. Initial scoping call with Forcepoint

Once your request is in, a Forcepoint specialist will contact you to:

  • Confirm that the free Data Risk Assessment is the right fit for your environment.
  • Align on scope: which data sources, which regions, and which business units to include.
  • Clarify your primary drivers:
    • AI adoption and LLM tools (e.g., Copilot, ChatGPT usage)
    • Compliance focus (e.g., GDPR, HIPAA, PCI, CCPA)
    • Cloud/SaaS expansion (e.g., Microsoft 365, Salesforce, Box)
    • Database/data lake exposure (e.g., SQL, Snowflake, Databricks)
  • Agree on timelines and internal stakeholders (security, IT, data owners, compliance).

You should come prepared with:

  • A rough inventory of priority platforms (cloud apps, email, endpoints, data stores).
  • Any hard constraints (regions where data must not be scanned, legal restrictions).
  • Your preferred method of deployment (agent-based, API-based, or a mix).

3. Assessment design: what you want to see

During or shortly after the scoping call, Forcepoint will help you tailor the DRA around specific questions, such as:

  • “Where is our regulated data (PCI, PHI, PII) actually stored and who can access it?”
  • “How much shadow data and ROT is sitting in our collaboration tools?”
  • “Which over-permissioned files could be exfiltrated through AI tools or cloud apps?”
  • “Are we aligned with specific regulatory obligations across regions?”

This is where the work shifts from a generic scan to something that reflects your governance, risk, and compliance needs—while staying within your comfort zone on access and permissions.


What access and permissions Forcepoint will typically ask for

The DRA is about visibility, not full-scale control. Forcepoint will request the minimum access required to discover and classify data, identify exposures, and present findings. The exact permissions depend on the systems in scope, but they generally fall into three categories:

  1. Read-only visibility into data locations and metadata
  2. Scoped access to content for classification
  3. Limited administrative access for configuration—not enforcement

Below is what that usually looks like by channel.

1. Cloud apps and SaaS (e.g., Microsoft 365, Google Workspace, Box)

For SaaS and collaboration tools, Forcepoint will typically request:

  • Read-only API access to:

    • File metadata (location, owner, sharing settings, permissions)
    • Folder structures and sharing configurations
    • Audit logs for access and sharing events (where available)
  • Content inspection access (scoped) for:

    • Scanning file contents to detect sensitive data (e.g., PII, PHI, PCI, IP)
    • Applying AI Mesh Data Classification for explainable tagging
  • Admin/API permissions needed to:

    • Register the Forcepoint app or connector
    • Authorize scanning of specific repositories, sites, or drives

What Forcepoint does not require for a DRA:

  • No blanket “Global Admin” control if a more granular role will work.
  • No enforcement actions (e.g., blocking, quarantining) unless explicitly requested.
  • No configuration changes to your production policies—visibility first, controls later.

You remain fully in control of which tenants, SharePoint sites, OneDrive locations, or Google Drives are in or out of scope.

2. Databases and data lakes (e.g., Microsoft SQL, Oracle, MySQL, Snowflake, Databricks)

For structured data sources, the DRA typically uses a service account with:

  • Read-only access to:

    • System catalogs and schemas (so we know what tables/columns exist)
    • Sampled or full data from selected tables, depending on your risk appetite
  • No write/update/delete permissions, unless you specifically authorize limited remediation in a pilot phase.

This access lets Forcepoint:

  • Discover where sensitive fields live (e.g., CARD_NO, SSN, DOB).
  • Use AI Mesh Data Classification and policy templates to tag data types.
  • Identify risk patterns like:
    • Sensitive tables open to too many roles
    • Production data copied into non-production environments
    • Databases exposed to broader networks than necessary

You can restrict:

  • Which databases/instances are included.
  • Which schemas/tables can be inspected.
  • Whether full content or samples are used for classification.

3. File shares, NAS, and on-premises repositories

For on-prem file systems, Forcepoint typically requests:

  • Access via a service account with:
    • Read permission to directories and files in scope
    • Ability to enumerate folder structures and ACLs

No write access is needed for the assessment phase. This is enough to:

  • Discover legacy sensitive data on file servers.
  • Identify ROT (redundant, outdated, trivial) data that can be cleaned up.
  • Surface over-permissioned shares (e.g., “Everyone” or large groups with access).

Again, the scope is controlled by you—specific shares, business units, or regions.

4. Email and web channels

If you choose to include email or web channels, Forcepoint may request:

  • Email (e.g., Exchange Online, Gmail):

    • Connector/API access allowing analysis of:
      • Message metadata
      • Samples or selected mailboxes for content classification
    • No global journal requirement if that’s not acceptable; scoping is negotiable.
  • Web traffic (via proxies/SSE):

    • Configuration to route or mirror traffic through Forcepoint Data Security Cloud.
    • Read access to URLs and content for DLP and classification during the assessment window.

In many DRAs, email/web analysis is more limited and focused on representative samples rather than full capture, especially in highly regulated or sensitive environments.

5. Endpoint and network visibility (optional)

If part of your goal is to understand endpoint and network data movement:

  • Endpoint agents (optional, scoped):

    • Deployed to a specific pilot group or segment.
    • Grant visibility into:
      • File movements (USB, local copies)
      • Application usage (including AI tools and copilots)
    • Configured in monitor-only mode during the assessment.
  • Network taps/mirror ports (optional):

    • Read-only capture of relevant traffic for content inspection.
    • No inline blocking unless explicitly agreed.

How Forcepoint limits and governs access during the DRA

A credible assessment has to be secure by design. Forcepoint’s approach is built around least privilege, transparency, and auditability.

1. Least-privilege, scoped access

For each system in scope:

  • Forcepoint will:

    • Work with you to use the narrowest possible roles instead of blanket admin roles.
    • Limit connectors to specific tenants, instances, mailboxes, or file shares.
    • Use time-bound access where your platform supports it (e.g., tokens with expiry).
  • You can:

    • Exclude classes of data (e.g., certain legal matters, board materials).
    • Restrict access by geography or business unit to align with data residency rules.
    • Revoke access at any time via your own admin consoles.

2. Data handling and privacy-by-design

The DRA uses the same AI-native platform that’s governed by Forcepoint’s Compliance Hub and Trust Center:

  • Privacy and security certifications (e.g., SOC 2 Type II, ISO) are available through the Trust Center.
  • “AI Mesh Data Classification” uses a Small Language Model (SLM) approach:
    • Efficient and explainable.
    • Designed for auditable classification logic—not opaque black-box decisions.
    • Does not require moving your entire datasets into a public LLM.

You should expect:

  • Data in transit secured with strong encryption.
  • Configuration aligned with your data residency requirements where possible.
  • Strict separation between your data and other customers’ data within the platform.

3. No surprise enforcement during the assessment

The DRA is about discovery, classification, and prioritized risk insights—not flipping production controls on without your consent.

By default:

  • Connectors and agents run in monitor/observe mode.
  • No blocking, quarantining, or permission changes are applied automatically.
  • Any remediation (e.g., permission right-sizing, ROT cleanup) is:
    • Modeled in reports.
    • Only executed in your environment if you explicitly request a pilot of Risk-Adaptive Protection or automated remediation.

What you get from the assessment: outputs and deliverables

When the scan and analysis phase is complete, Forcepoint will provide:

1. Executive-level summary

A board-ready narrative that answers:

  • Where your most sensitive data lives (cloud apps, email, endpoints, databases, data lakes).
  • How much of it is exposed (e.g., open links, public sharing, over-permissioned access).
  • How AI tools and copilots may be amplifying that exposure.
  • Top 5–10 remediation moves that materially reduce risk.

2. Risk heatmaps and dashboards

View of:

  • Regulated data exposure (e.g., PCI, PHI, PII) by system and business unit.
  • Shadow data and ROT concentrations.
  • High-risk sharing patterns (e.g., external collaborators, public links).
  • Trends by geography or data owner where available.

These are aligned to Forcepoint’s Self-Aware Data Security loop—discover, classify, prioritize, remediate, protect.

3. Policy and control recommendations

Based on Forcepoint’s library of 1,800+ templates and classifiers, you’ll see:

  • Which policy templates map to your compliance requirements.
  • Where single-policy enforcement (“create once, enforce everywhere”) can replace fragmented rules across web, email, SaaS, endpoints, network, and AI tools.
  • How Risk-Adaptive Protection could reduce friction by enforcing based on behavior, data sensitivity, and context.

4. Optional proof-of-value path

If you choose to move beyond assessment:

  • You can pilot:
    • Continuous discovery and classification.
    • Automated remediation (e.g., permission repair, quarantining, data movement).
    • Risk-adaptive controls that protect data in near real time, not just through reports.

But the DRA itself is designed to stand alone as a clear, actionable snapshot of your current state—even if you’re not ready to change tools.


How to decide what access to grant

When you’re evaluating the access/permissions request for the DRA, use this decision frame:

  • Mandatory visibility: What you must include to answer your core questions?
    • Example: Microsoft 365 + key databases for PCI/PHI posture.
  • Pilot visibility: What you’re comfortable testing in a limited scope?
    • Example: A subset of SharePoint sites or specific file shares.
  • Out of scope (for now): What must stay out due to legal, contractual, or political constraints?
    • Example: Sensitive legal repositories or certain geo-restricted workloads.

Discuss each category with Forcepoint during scoping. The goal is to get enough coverage to produce meaningful, board-level insight without breaching organizational guardrails.


Next step

If you’re ready to see your real data risk—across AI tools, cloud apps, web, email, endpoint, and network—without committing to a full deployment, the free Data Risk Assessment is the fastest way to start.

Get Started
https://www.forcepoint.com/form/demo-request

Use the notes field to request a “free Data Risk Assessment (DRA),” and Forcepoint will work with you to define the right scope and access model for your environment.

How do I request a Forcepoint free Data Risk Assessment, and what access/permissions will they ask for? | Data Security Platforms | Codeables | Codeables