Skip to main content

Check out Interactive Visual Stories to gain hands-on experience with the SSE product features. Click here.

Skyhigh Security

DSPM Data Explorer Scan Modes

Skyhigh Security Data Security Posture Management (DSPM) uses specialized data discovery mechanisms within the Data Explorer dashboard. These scanning modes help admins achieve complete visibility into enterprise data footprints without relying solely on active blocking rules.

Key Differences

The following table lists the differences between the Unified Expanded Scan and Policyless Scan mechanisms:

Attribute Unified Expanded Scan Policyless Scan
Primary Objective Extends visibility beyond active policy criteria during the scan Discovers files and data types automatically without requiring any preset policies
Policy Dependency Requires an existing, active primary DLP policy (such as CASB or Web DLP) to trigger the initial scan Operates in both conditions:
  • No active policies
  • Active policies with Unified Expanded Scan
Classification Scope Scans for additional pre-canned data classifications (like Source Code, HIPAA, or PHI) when a file triggers a primary policy scan Captures and categorizes all file-based Near Real-Time (NRT) events. Also, automatically evaluates data against all pre-canned data classifications
Incident Generation Does not generate new DLP incidents for the additional classifications found; it logs data exclusively in the DSPM Data Explorer Does not generate DLP incidents; it populates visibility matrices for proactive risk profiling

NOTE: Unified Expanded Scan and Policyless Scan run only for the services you enable on the Service Management page. 

Understand the Unified Expanded Scan

The Unified Expanded Scan extends visibility beyond your active policy by scanning data for secondary data classifications.

When a user triggers an active Data Loss Prevention (DLP) policy—such as uploading a document to a generative AI application that contains a Social Security Number (SSN)—the Data Security Posture Management (DSPM) simultaneously scans that document for other data categories, such as source code or financial identifiers. For details, see Improved Data Visibility with Unified Expanded Scan.

Understand the Policyless Scan

Unlike traditional DLP methods that only track data matching specific rules, the Policyless Scan automatically processes all file-based Near Real-Time (NRT) events across your Cloud Service Providers (CSPs). The DSPM continuously extracts metadata and inspects file content regardless of whether the files touch an active policy. This mode helps you map out where sensitive information lives across your hybrid or multi-cloud infrastructure before you create policy enforcement rules. For details, see Integrated Policyless Data Discovery for NRT-based Events.

  • Was this article helpful?