IDENTITY, ACCESS & ACTIVITY

Who can reach your data, who did, and whether they should have

Theom reconciles grants against what the data actually contains, baselines what each identity does, and turns the answer into a finding you can act on, inside the store.

Entitlements describe possibility, not behavior

Your data platform’s own access controls decide who may reach data, and stop there. An access review proves an identity could reach a table. It says nothing about whether the reads that followed made sense, and the picture blurs when a BI tool, a service account, or an agent sits between the person and the data. Theom reconciles grants, roles, group membership, and ownership against the classification, baselines observed activity per identity, and joins the two, so access is judged in context rather than on paper.

Findings against named objects, not a score

Reconcile access to content

Grants, roles, group membership, and ownership reconciled against what the data actually contains, so over-broad and inherited grants, dormant privileges, and shared identities surface as findings against named objects, with owners attached.

Baseline what identities do

Observed activity baselined per identity and joined to classification and ownership, with alerts on first access to a sensitive object, on volume and pattern change, and on reads by identities with no business relationship to the data.

Compound identity, resolved

The compound path — a user through a BI tool or agent, through to the object — resolved into one reviewable chain, so alerts carry the query context, not just an event ID.

Act, your way

The tag drives a native platform control — row and column policies, masking — or the finding routes to your security team, your ticketing system, and your SIEM.

Watch first, enforce when you are ready

These are not competing products or a licensing tier. Most teams run observability first — it has no blast radius, and a few weeks of findings is how classification earns the trust that enforcement requires. Enforcement is then enabled class by class rather than estate-wide.

  • Observability changes nothing in the query path. Tags are written; access is unchanged.

  • Enforcement lets those tags drive the platform’s own row, column, and masking policies.

  • At the data layer Theom is never in the query path, so nothing it does can affect query performance or availability.

Not what an identity can reach, but whether it still makes sense

Identity governance tells you what an identity can reach. Theom tells you whether that still makes sense for the data, and how the access is actually being used.

  • Service accounts authenticating interactively, or without a network policy

  • Logins without a second factor reaching sensitive objects

  • Privileged access to sensitive objects that no longer matches its purpose

Show the mechanism, not just the claim

Exfiltration is a set of concrete signals, and Theom watches for them where the activity happens.

  • Bulk export and copy-out monitoring, and large interactive downloads

  • Secrets exposed in query text, and exposed developer credentials

  • Unmasked sensitive columns and masking-policy conflicts

  • Sensitive-data access followed into collaboration paths like Microsoft 365, OneDrive, and SharePoint

Common questions

How is this different from an access review?

An access review proves an identity could reach a table. Theom reconciles that grant against what the data actually contains and against what the identity actually did, so you get a ranked, named list of grant-to-content mismatches with owners attached — the input to a revocation you can defend, rather than a review that removes nothing.

Can we watch before we enforce?

Yes. Observability mode writes tags and changes nothing in the query path, so you can run it across the whole estate from week one. Enforcement is enabled class by class, where the label is trusted and the cost of over-blocking is low, and at the data layer Theom is never in the query path.

Does Theom see AI and agent activity the same way?

Yes. An agent is treated as an identity like any other — classified content, observed reads, baselined behavior, and the compound path back to whoever initiated it — so agent traffic gets the same access assurance as human traffic.

See who is reaching your data, and whether they should be

We will run observability on a bounded subset of your own production and show you what comes back.

Book a Demo