01Discovery across managed devices
The agent scans the machines it is installed on and identifies regulated and sensitive content wherever it has come to rest: local drives, synchronized folders, and the archives and exports that accumulate on the desktops of people who were only ever trying to get their work done.
02Exposure expressed in money
Findings are converted into a monetary risk figure per device and per organization. This is the form the question has to take before a board will act on it, and it is considerably more persuasive than a count of files whose significance nobody in the room can weigh.
03Enforcement written against reality
The encryption attaches to the file itself and not to whichever folder it happens to sit in, while channel control decides the routes by which anything may depart. Because the rules are written after a discovery period, they are shaped by what your organization actually does rather than by a template's assumption about how it ought to work.