Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Wednesday, 19 August 2026

Anthropic training programmes

Over the last week I have completed three Anthropic training programmes to expand my use of AI tools from Copilot and Gemini. While the courses focus on Claude, the value goes far beyond learning a particular AI tool. I completed:

  • Claude 101
  • AI Fluency Framework & Foundations
  • Claude Code in Action
Claude 101 provides a solid grounding in how to work effectively with large language models. It covers prompt design, structuring requests, and understanding where AI can genuinely add value versus where human judgement remains essential.

AI Fluency Framework & Foundations takes a broader view. Rather than concentrating on technology alone, it explores how individuals and organisations can develop the skills, mindset and practices needed to adopt AI successfully. It reinforces an important lesson about becoming AI-enabled is as much about people and ways of working as it is about the tools themselves.

Claude Code in Action was particularly interesting from a practical perspective. It demonstrates how AI can support software development workflows, automate repetitive tasks, assist with code generation and review, and help teams move faster while maintaining quality. Even for those of us who are not full-time developers, it offers valuable insight into how AI is changing the way technical teams work.

The skills I learned on a this tool cover the tool usage but are more about people, skills, governance, and trusted data.



Tuesday, 18 August 2026

What my WorkIQ Persona Sketch taught me about Data Governance


Like most people who have spent years working in data, governance and technology, I am occasionally asked a surprisingly difficult question.

"So, what is it that you actually do?"

It sounds simple enough. After all, I spend my days helping organisations improve the way they govern data and AI. I work with executives, data leaders, governance teams and technology specialists. I write, speak, advise, mentor, and occasionally disappear down a rabbit hole researching some obscure aspect of metadata or organisational complexity. Yet whenever somebody outside the industry asks the question, the answer rarely feels satisfactory.

You can talk about Microsoft Purview, governance operating models, stewardship, responsible AI, data quality, business glossaries and metadata management. You can explain frameworks, programmes and organisational change. Most people are polite enough to listen, but somewhere around the mention of lineage or compliance controls their eyes begin to glaze over.

Recently I decided to create one of the increasingly popular WorkIQ Persona Sketches. I expected it would be an interesting visual exercise and perhaps a useful profile graphic for social media. What I did not expect was that it would force me to reflect on what my work is really about. When the first version appeared, it looked impressive enough. It showed technology platforms, governance activities, speaking engagements, research interests and community involvement. It included the various things I spend time doing and many of the topics I am associated with professionally.

The problem was that it still did not quite feel like me. It described my activities, but not my purpose. As I refined the sketch, removing some elements and emphasising others, a pattern began to emerge. The technology became smaller. The governance themes became larger. The focus shifted away from products and towards outcomes. Instead of listing tools, the sketch started telling a story.

The story was not really about Microsoft Purview, Microsoft Fabric, Power BI or SQL Server, despite all of them appearing on the page. It was about helping organisations build confidence. That may sound like a subtle distinction, but I think it matters.

Many organisations still think of governance as an exercise in control. Policies need writing, roles assigning, rules enforcing and technology deploying. Those things are certainly part of governance, but they are rarely the reason governance exists.

The organisations making the most progress with data and AI are not trying to govern for the sake of governing. They are trying to make better decisions, reduce uncertainty and trying to understand their information well enough to trust it. Increasingly, they are trying to ensure the foundations beneath their AI ambitions are solid enough to support what comes next. Governance is simply the mechanism that helps create that confidence and trust. Looking at the sketch, I realised that almost every part of my career has revolved around that idea.

My doctoral research explored the complexity of database systems and resulted in the development of the CODEX Framework. At the time, I was trying to understand how organisations could make sense of increasingly complex data environments. Years later, those same themes continue to appear in conversations about governance, AI readiness and organisational trust.

My work as a Microsoft Data Platform MVP has never really been about technology advocacy. It has been about helping people understand how technology can support better outcomes.

The conferences, community events, blogs and mentoring activities all stem from the same belief. If we help people understand data better, we help organisations make better decisions. If we improve governance, we improve confidence and the likelihood that data and AI initiatives deliver meaningful value.

The sketch made something else visible too. Many people see specialists through the lens of tools. We become the Purview person, the SQL Server person or the governance person. The reality is usually much broader. The most valuable work often happens between disciplines rather than within them. Good governance sits between business strategy and technology. It sits between risk, innovation, people, processes, culture and platforms. Success rarely comes from solving a technical challenge in isolation. It comes from helping organisations connect those pieces together in a way that makes sense.

That is why the final version of the sketch ended up with a simple statement at its centre:

Helping shape how organisations think strategically about Data & AI Governance and Microsoft Purview.

Microsoft Purview is a powerful accelerator for governance, but it is not the answer to every governance challenge on its own. Organisations still need to make governance decisions with purpose, coherence, and accountability. Governance remains the most important discipline in an organisation because it connects technology, behaviour, and business outcomes.

As I reflected on this, the sketch I was creating shifted. It became less of a personal profile and more of a map of the ideas I care about, the communities I contribute to, and the research, technology, and leadership themes that have shaped my career. Most importantly, it became a reminder that roles are easier to understand when viewed through purpose rather than activity. The common thread running through my work is the ability to connect governance, technology, and business outcomes in a way that creates integrity, clarity, and direction.

The next time somebody asks what I do, I might still mention governance, AI and Microsoft technologies.,  but I suspect I will start with something simpler. I help organisations build confidence in their data and AI so they can make better decisions. Everything else is just how that happens.

Reference 

https://github.com/pnp/copilot-prompts/tree/main/samples/prompts/m365-workiq-persona-sketch

Why Trust Matters more than Discovery: Microsoft Purview Unified Catalog

In the first article in this series, I explored the challenge of visibility and how Microsoft Purview Unified Catalog helps organisations answer a simple but surprisingly difficult question: what data do we actually have?

For many organisations, solving this problem represents a significant milestone. Years of system growth, acquisitions, departmental solutions and technology change often create an environment where information exists but remains difficult to locate. Valuable datasets sit within platforms that few people know about, reports are recreated because earlier versions cannot be found, and knowledge about key information assets becomes concentrated within small groups of specialists.

Improving discovery removes many of those barriers, but it also introduces a new challenge. Once users can locate information more easily, their attention naturally shifts away from finding data and towards understanding it. Very rarely does somebody discover a dataset and immediately begin using it without asking further questions. Instead, they want to know whether the dataset is trusted, who owns it, how it is being maintained and whether it is suitable for the decision, analysis or report they are working on.

In practice, this is the point at which governance becomes far more interesting.

Most organisations do not struggle because they lack information. They struggle because they lack confidence in the information they have. Discovery helps people locate data, but trust determines whether that data is actually used.

Why Data Discovery is only the beginning

Many of the frustrations people experience with data are not caused by technology. They arise because the information lacks sufficient context.

Imagine an analyst searching a catalogue and finding three datasets that appear to contain customer information. All three are current. All three appear relevant. All three contain similar attributes and similar record counts. Discovery has succeeded because the analyst can see that the data exists. Unfortunately, discovery alone does not help determine which dataset should be used.

The questions that follow are usually business questions rather than technical questions.

Which dataset represents the approved source?

Which business area owns it?

What does "customer" actually mean within this context?

How frequently is it updated?

What transformations have been applied since the data was first collected?

Without those answers, users often fall back on familiar behaviour. They email colleagues, consult subject matter experts or continue using whichever data source they trusted previously. The catalogue exists, but confidence has not yet been established.

This is why governance programmes that focus exclusively on discovery often struggle to deliver their full value. Visibility is important, but visibility without context rarely creates trust.

Where Data Curation fits

One of the less discussed aspects of governance is curation. The term itself sounds administrative, which probably explains why it receives less attention than topics such as AI, analytics or compliance. In reality, curation sits at the heart of helping organisations bridge the gap between technical information and business understanding.

Most data assets are created within technology environments. Their names reflect system requirements, integration patterns or development conventions. To the engineers who build and maintain them, those names often make perfect sense. To everyone else, they can be cryptic, ambiguous or completely meaningless.

A curated asset looks different because it includes the information people actually need in order to understand it. Business descriptions explain what the asset represents. Ownership information identifies accountability. Classifications provide context about sensitivity and usage. Associated business terms explain how the asset fits within the language of the organisation.

This process transforms a technical asset into something that can be interpreted and trusted by a much wider audience.

The objective is not simply to document data. It is to create enough context that somebody encountering a dataset for the first time can understand its purpose and relevance without needing to find the person who created it.

The Business Glossary: Creating a Common Language

One of the most valuable governance capabilities within Microsoft Purview is the Business Glossary.

At first glance, a glossary sounds relatively straightforward. Many organisations assume it is simply a dictionary of approved business terms. In practice, its role is significantly more important than that.

Every organisation has terminology that appears obvious until people are asked to define it. Terms such as customer, employee, supplier, resident, contract or revenue are often assumed to have a consistent meaning. Governance workshops frequently reveal the opposite. Different teams use the same words while referring to slightly different concepts. Those differences may be perfectly reasonable within local contexts, but they become problematic when information is shared across departments, reports or analytical models.

A customer services team may define an active customer differently from the sales function. Finance may calculate revenue differently from operational reporting. Legal, risk and compliance teams may use terminology that reflects regulatory requirements rather than business reporting needs.

These are not necessarily disagreements. More often they are examples of organisational complexity becoming visible.

The Business Glossary provides a mechanism for governing this complexity. Within Microsoft Purview, glossary terms can be organised into domains, assigned owners and stewards, enriched with definitions and related terms, and connected directly to assets within the Unified Catalog. This relationship is particularly important because it links business language to the datasets, reports and information products that rely upon it.

When users search the catalogue, they are not simply looking at technical metadata. They can also see the business terminology associated with assets and understand how those assets relate to agreed organisational definitions. Rather than existing as a separate governance artefact that few people reference, the glossary becomes embedded within the discovery experience itself.

This is often where trust begins. People are far more likely to use information when they understand both what it contains and how the organisation expects it to be interpreted.

Why Lineage builds confidence

Even when terminology is clear and ownership is established, there is usually another question users want answered.

How did this data get here?

Most people consume information at the end of a process. They see a dashboard, a report, a model or, increasingly, an AI-generated response. What they do not see is the journey that information has taken through source systems, integrations, transformation processes and analytical platforms before reaching its final destination.

Understanding that journey is the role of data lineage.

Lineage provides visibility into how information moves through an organisation. Rather than viewing a dataset as an isolated asset, users can see its relationship to upstream systems, transformation processes and downstream consumers. This creates a much richer understanding of where information originated and what happened to it along the way.

The significance of lineage becomes particularly obvious when trust is challenged. If a figure changes unexpectedly, lineage helps explain why. If an upstream source system is modified, lineage can help identify which reports, dashboards and analytical processes may be affected. If two datasets appear similar, lineage may reveal that they originate from different systems and have undergone different transformations.

In other words, lineage provides evidence rather than assumption.

Within Microsoft Purview, lineage is captured automatically through integration with supported technologies and services. Data movement, transformation and processing activities within platforms such as Azure Data Factory, Microsoft Fabric, SQL environments and other supported services can be visualised as connected information flows. Instead of relying on manually maintained diagrams that quickly become outdated, organisations gain a dynamic view of how information actually moves through the estate.

For governance teams this increases visibility. For business users it often increases trust because they can see how a reported value is connected to its source.

Trust is what turns Data into value

Discovery remains a critical part of data governance. Organisations cannot govern information that they cannot find, which is why visibility, cataloguing and discovery capabilities provide such an important foundation.

However, discovery alone does not solve the larger challenge.

People create value from data when they are willing to use it. They use it when they understand it. They trust it when they have confidence in its meaning, ownership and provenance.

Business glossaries help establish shared language. Curation provides business context. Lineage explains how information was created and how it moves across the organisation. Together, these capabilities transform a catalogue from a searchable inventory into a trusted source of organisational knowledge.

Finding data is important. Being confident enough to use it is what ultimately matters.



Friday, 14 August 2026

AI is Forcing Organisations to ask Data Governance questions they have avoided for years

When organisations begin exploring generative AI, the early conversations are usually focused on technology. Attention naturally turns towards copilots, agents, large language models, prompt engineering and how existing processes might be automated. The assumption is often that success will depend on choosing the right tools and identifying the right use cases.



Those discussions are important, but they rarely remain the centre of attention for long.

As AI initiatives move beyond experimentation and into real business scenarios, the conversation often shifts in an unexpected direction. Questions begin to emerge about ownership, trust, definitions and accountability. Teams discover that information which appeared well understood within individual departments becomes considerably more difficult to explain when it is surfaced across the organisation through a single AI-powered experience.

This is creating an interesting situation. Many organisations believe they are encountering AI challenges when, in reality, they are encountering long-standing governance challenges that have remained largely hidden until now.

For years it has been possible for businesses to operate successfully despite inconsistencies in the way data is managed. Different departments develop their own reporting processes, terminology and working practices. Over time these approaches become embedded into everyday operations. Finance may calculate a measure one way, while another business unit calculates it differently. Multiple systems may contain records relating to the same customer, product or asset. Ownership may be understood informally without being clearly defined.

None of these situations are unusual. In fact, they are common in organisations of every size and sector.

What has changed is that generative AI is exposing these inconsistencies in ways that traditional reporting platforms rarely did. Information that once remained within the boundaries of a specific application, report or team is increasingly being brought together and presented through a single interface. As soon as that happens, differences in meaning, ownership and interpretation become much more visible.

One of the more striking developments over the past year has been how quickly discussions about AI become discussions about data governance. An organisation may start by exploring how employees can use Copilot more effectively, only to find itself debating which definition of a business term should be treated as authoritative. A workshop intended to focus on automation can quickly become a conversation about data ownership. Questions about whether users can trust AI-generated responses often lead directly to questions about where underlying information originated and how it is managed.

These are not new concerns. Governance professionals have been dealing with them for decades. The difference is that they are no longer confined to governance programmes.

AI is bringing them into boardrooms, project teams and business conversations that might previously never have engaged with governance at all.

The issue is not that AI is creating poor governance. Rather, it is making gaps in governance more difficult to ignore.

A useful parallel can be found in the idea of technical debt. Most organisations understand that technology decisions made years ago can create future complexity. Shortcuts that seem reasonable at the time often require greater effort to address later. Data governance follows a similar pattern. Business definitions are left undocumented because everyone believes they share the same understanding. Ownership remains informal because responsibilities appear obvious. Metadata is treated as a technical concern rather than a business asset. Lineage documentation is postponed because delivery deadlines take priority.

Individually, these decisions rarely feel significant. Collectively, they create an environment where information becomes harder to understand, trust and govern over time.

Historically, organisations could continue operating with this ambiguity because people compensated for it. Experienced employees knew which reports to trust and who to contact when figures did not align. Unwritten knowledge often filled the gaps that formal governance processes had not addressed.

Generative AI changes that dynamic because it lacks this organisational context. It relies on information being discoverable, understandable and consistent. When definitions vary between teams, when ownership is unclear or when information carries little context, those weaknesses become more apparent. The technology is simply revealing what has always been there.

This is one reason metadata has suddenly become a much more strategic conversation. Business glossaries, catalogues, classifications, stewardship models and lineage are often viewed as traditional governance disciplines. Increasingly, they are becoming recognised as fundamental enablers for AI adoption. Organisations are realising that it is difficult to scale AI responsibly when basic questions about information cannot be answered consistently.

The organisations making the strongest progress with AI are not always the ones investing the most heavily in AI technology itself. More often, they are organisations that have a reasonable understanding of their information landscape. They know which data matters to the business, who is accountable for it, how it is defined and where it comes from. They have established enough structure and context to create confidence in the information being consumed.

That confidence matters because successful AI adoption is ultimately a trust exercise. Users need confidence that information is accurate, that responses can be explained and that decisions can be justified. Without trust, adoption slows regardless of how capable the underlying technology may be.

Perhaps the most interesting outcome of the current AI wave is that it is forcing organisations to revisit some of the fundamentals of information management. After years of being viewed as a compliance activity or a specialist discipline, data governance is finding itself at the centre of conversations about innovation, productivity and business transformation.

The irony is that many organisations began their AI journey expecting to focus primarily on technology. Instead, they are being asked to confront questions about data that have existed for years. They have questions about ownership, meaning, accountability,  and trust. Those are governance questions, and they are becoming increasingly difficult to avoid.

AI may not have been designed to improve data governance, but it is proving remarkably effective at showing organisations where governance needs attention. In many cases, the most valuable insight generated by AI is not contained within a response or recommendation. It is the realisation that understanding data remains one of the most important prerequisites for using it effectively.

Thursday, 6 August 2026

Finding what your Organisation already knows: Microsoft Purview Unified Catalog

Most organisations have no shortage of data. What they lack is a clear view of which of it is relevant, current and trustworthy. Across almost every organisation there are databases, reports, data warehouses, data lakes, spreadsheets, business applications and operational systems containing information that somebody, somewhere, relies upon every day. New platforms arrive, legacy systems remain, departments develop their own solutions and the information landscape gradually expands year after year.

The challenge is rarely the absence of data. More often, the challenge is knowing what already exists. This becomes particularly visible whenever a new initiative begins. A project team starts looking for customer data. An analyst needs information to support a reporting requirement. An AI initiative requires access to trusted business information. The data almost certainly exists somewhere within the organisation, but locating it often becomes an exercise in networking rather than discovery. Emails are sent. Teams messages are exchanged. Conversations take place with individuals who have accumulated knowledge about particular systems over many years. Eventually the data is found, but the process raises an uncomfortable question. Why was finding it so difficult in the first place?

Many organisations have become accustomed to a culture of data by request. Access to information frequently depends on knowing who to ask rather than knowing where to look. Knowledge becomes concentrated within particular teams and individuals, creating operational dependencies that often remain invisible until those people move roles, leave the organisation or become unavailable. This is one of the problems Microsoft Purview Unified Catalog is designed to address.

The difference between knowing data exists and being able to find it

When people first hear the term data catalogue, they often imagine a searchable inventory of assets. That description is not wrong, but it is incomplete. A catalogue only has value if it remains current, accurate and connected to reality. Historically, many organisations attempted to maintain data inventories through spreadsheets, documents and manually curated repositories. These often delivered some value initially, but keeping them aligned with constantly changing technology estates proved difficult. Systems changed, databases evolved and new projects appeared long before documentation could be updated.

Microsoft approached the challenge differently. At the foundation of the Purview governance platform sits the Data Map, a service that scans connected data sources on a scheduled or on-demand basis and collects metadata from across the estate. Whether information resides within Azure, Fabric, SQL Server, Databricks, Power BI or a growing list of supported technologies, the Data Map provides the automated discovery capability that allows Purview to understand what exists within the environment. Importantly, what is collected is metadata rather than the data itself: Purview builds a picture of the estate without copying or exposing the underlying content.

This distinction is important because the Unified Catalog is not the scanning engine itself. The Data Map performs the discovery. The Unified Catalog turns that discovery into something users can explore, search and understand. Without the Data Map, the catalogue would quickly become another manually maintained inventory. Without the catalogue, the information collected by the Data Map would remain difficult for most users to consume. The value comes from the relationship between the two.

From technical metadata to business understanding

Discovering an asset is only the beginning of the journey. Knowing that a database table exists tells a technical user something useful, but it often tells a business user very little. A name, a schema and a collection of columns rarely explain whether a dataset is trusted, who owns it, how it is used or whether it should be used at all.

This is where the Unified Catalog begins to move beyond traditional metadata management. The Unified Catalog brings together technical information and business context within a single discovery experience. Datasets can be associated with business terms, classifications, ownership information, descriptions, lineage and governance information. Rather than presenting users with a list of technical assets, it starts to answer the questions people naturally ask when looking for data.

What does this dataset contain?

Who owns it?

Is it approved for reporting?

How does it relate to other assets?

Where did the information originate?

Can it be trusted?

These are fundamentally business questions rather than technical questions, which is why discoverability has become such an important governance capability. People rarely struggle to search for information. They struggle to determine whether the information they have found is the right information.

The Unified Catalog in Microsoft Purview

Within Microsoft Purview, the Unified Catalog serves as the central discovery experience for governed data assets. Users can search for datasets using business language rather than system names. They can explore information by domain, classification, glossary term or data product. Ownership information, lineage relationships and governance context are surfaced alongside technical metadata, helping users understand not only where data exists but also how it fits within the broader information landscape.

The catalogue is also more than a search box. Assets are organised into governance domains owned by the business, and packaged as data products that bundle related datasets with a described purpose, an accountable owner and terms of use. Alongside this sits data quality and health reporting, so stewards can see where definitions are missing, ownership is unclear or quality rules are failing, and consumers can request access to a product through a governed workflow rather than an email.

The introduction of the Unified Catalog is particularly significant because Microsoft is increasingly positioning it as the primary discovery and governance experience across the Microsoft data ecosystem. As organisations adopt Microsoft Fabric, OneLake, Purview and other platform services, the need for a common discovery layer becomes increasingly important. The catalogue provides a way of connecting data consumers with information assets without requiring detailed knowledge of the underlying technologies.

In many respects, the Unified Catalog represents a shift in governance thinking. Historically, governance initiatives often focused on controlling data. Increasingly, organisations are recognising that understanding and discoverability are equally important. Information that cannot be found, understood or trusted delivers little value regardless of how well it is protected.

Why this matters in the Age of AI

The renewed interest in data catalogues is not happening by accident. Generative AI is changing how people expect to interact with information. Employees increasingly assume that organisational knowledge should be discoverable, understandable and available at the point of need. They are less willing to navigate multiple systems, departments and processes simply to locate information that they believe already exists somewhere within the organisation.

At the same time, AI systems themselves depend heavily on context. Data without ownership, definitions or appropriate metadata becomes harder to interpret consistently. Many organisations are discovering that successful AI adoption is closely linked to their ability to organise and describe information in a way that makes sense beyond the boundaries of individual systems. An assistant grounded in an undocumented estate will answer confidently from whichever copy of the data it reaches first — and nobody will be able to say whether that copy was the right one. What appears to be an AI challenge often turns out to be a discoverability challenge.

More than a catalogue

The strongest data governance programmes are not built around catalogues. They are built around understanding. The value of Microsoft Purview Unified Catalog is not that it creates another inventory of information assets. Its value lies in helping organisations connect people with data more effectively, reducing reliance on undocumented individual knowledge and making information easier to discover, understand and trust. For many organisations, that represents a significant cultural shift. The goal is no longer to request information from the people who know where it lives. The goal is to create an environment where discovery becomes a normal part of working with data because in most organisations, the problem is not that valuable information is missing. The problem is that nobody realised it was already there.

 



Saturday, 1 August 2026

Microsoft Purview Audit: The Record of What Actually Happened

Governance frameworks define how information should be managed. The security controls determine who should have access and establish what must be monitored and evidenced. The challenge is knowing whether those expectations are being met in practice. When a security incident occurs, a regulator asks questions, or an investigation begins, assumptions quickly lose their value. Understanding what was expected to happen is important and understanding what actually happened is essential. That is where audit data becomes indispensable, providing a factual record of actions, changes, access events, and activity across the environment.

What It Is

Microsoft Purview Audit is the foundational tracking engine that logs, stores, and exposes activity across the entire Microsoft 365 ecosystem. It records the precise operational footprint of what users and administrators are doing across platforms like Exchange, SharePoint, OneDrive, Teams, and AI-driven interactions via Microsoft Copilot. This capability is entirely diagnostic, not preventative. It does not block user actions, modify permissions, or alter workflows in real time. Instead, its sole purpose is to build an unalterable, structured, and legally defensible record of activity.



What It Actually Does

The auditing ecosystem functions as a continuous, four-stage loop that transforms raw system events into clear organizational visibility:

  • Capture: The system automatically logs every critical interaction across the tenant. This includes explicit user actions (like downloading a file or sharing a document), administrative changes (like adjusting global permissions), and background automated system events.

  • Retain: Collected event logs are committed to secure, tamper-proof storage. Depending on your operational needs and licensing tier, retention windows are configured to keep data accessible anywhere from 180 days up to 10 years to meet compliance mandates.

  • Explore: Advanced querying tools allow compliance and security teams to slice through millions of log lines instantly filtering by specific user identities, exact IP addresses, precise timeframes, or specific actions.

  • Understand: Isolated events are correlated into sequential timelines. This transforms fragmented data points into a cohesive chronological narrative, allowing investigators to reconstruct exactly how an incident unfolded.

Where the Real Value Sits

Most organizations treat audit configurations as an afterthought until an emergency forces their hand usually a suspected security breach, an aggressive regulatory inquiry, or an internal HR investigation. The true value of this logging layer is not the mere existence of data; it is the immediate ability to answer four non-negotiable questions with absolute certainty:

  • Who interacted with the file or system?

  • When did the interaction occur?

  • What specific modifications or actions were executed?

  • Where did the target data move afterward?

Without a centralized, automated auditing engine, answering these questions requires manual, fragmented reconstruction that yields unreliable results. With it, there is a time-stamped, defensible record of reality.

Why This Matters More Now

The way information moves around a business has changed dramatically. Data no longer remains within a handful of systems managed by a small group of users. It flows between cloud platforms, collaboration tools, partners, suppliers, and increasingly through AI-powered experiences that can access and process information at scale. Understanding how that information is being used has become significantly more challenging. This modernization introduces two primary risk factors:

  • Distributed Footprints: Data actions happen across highly interconnected platforms, making visibility difficult to maintain without a centralized collection point.

  • Indirect Interactions: Generative AI solutions can query, summarize, and synthesize enterprise files on behalf of a user. Traditional file-access logs cannot accurately track these abstract interactions.

Purview Audit addresses this evolution by standardizing activity logging across all vectors including AI prompts and responses shifting audit management from a passive compliance checkbox into an essential baseline for behavioral visibility.

Where It Fits in the Bigger Picture

Auditing does not operate as an isolated silo. It serves as the primary data telemetry engine that powers and validates the rest of your security and governance framework:

  • eDiscovery: Relies directly on deep audit histories to build legal review sets and establish chain-of-custody tracking.

  • Insider Risk Management: Ingests automated audit signals to flag anomalies and risky user behavioral patterns before an asset leaves the network.

  • Information Protection & DLP: Uses historical audit trails to verify whether data classification rules and loss prevention boundaries are performing as intended.

The Business Problem It Solves

The underlying operational challenge for most enterprises is simple: they cannot definitively prove what has occurred within their own cloud environment. When a crisis occurs, relying on fragmented infrastructure or local machine logs exposes the organization to massive liability, resulting in:

  • Crippled incident response timelines.

  • An inability to satisfy mandatory regulatory notification windows.

  • A fundamental lack of forensic confidence when presenting findings to external auditors, boards, or legal bodies.

The auditing infrastructure solves this visibility gap by ensuring that user and system activity is captured uniformly, protected against alteration, and remains immediately searchable under pressure.

Audit vs. Compliance Manager

To properly position this capability within corporate governance, it helps to look at how it contrasts with policy tools:

Governance LayerPrimary FocusCore Question Addressed
Compliance ManagerPolicy, frameworks, and assessment mappingAre we doing what we structurally said we would do?
Purview AuditEmpirical tracking and technical telemetryCan we legally prove what actually happened?

Getting Started Safely

A frequent mistake is assuming that because an enterprise license is active, auditing requirements are completely covered out of the box. While basic logging is typically enabled by default, organizations often face blind spots because:

  • Default retention timelines may be too short to catch slow, long-tail data exploitation tactics.

  • High-value forensic logs (such as tracking when an email item was read rather than just accessed) require explicit configuration.

  • The response team has never stress-tested their export and query workflows during a simulated live incident.

Recommended Steps

  1. Map Log Scopes: Audit the current tenant configurations to identify exactly which cloud workloads are actively contributing to the central log repository.

  2. Align Retention with Law: Adjust log retention policies to ensure they legally match the minimum timelines dictated by the industry’s regulatory compliance frameworks.

  3. Turn on Premium Telemetry: Activate high-fidelity auditing features to capture deep behavioral indicators, giving investigators a clear forensic picture if an event occurs.

  4. Run Readiness Drills: Regularly test the security and compliance teams' ability to isolate, download, and interpret specific event sequences under realistic crisis timelines.

The Reality

Auditing infrastructure remains completely invisible during normal day-to-day operations. It alters no user interfaces, applies no blocks, and creates no internal friction but when an incident inevitably triggers an investigation, it quickly becomes the most critical asset in the entire environment because in the moments that matter most to leadership, the question is never: What should have happened? It is always: What actually did?

References

Wednesday, 29 July 2026

AI Security & Governance Certification

Always interested to check out different learning routes. This was a good introductory course and certification for AI Security & Governance to demonstrate awareness of AI challenges.

Having spent many years working in Data Governance and, more recently, AI Governance, I found the Securiti AI Security & Governance Certification to be a particularly worthwhile programme. The course does an excellent job of connecting governance principles with the practical realities of AI adoption. Topics such as AI model discovery, risk assessment, data and AI mapping, governance frameworks, and regulatory compliance are presented in a way that feels relevant to the challenges organisations are dealing with today. My biggest takeaway was that successful AI governance requires far more than policies and controls. It depends on understanding how data, models, processes, people, and regulations intersect across the organisation. The certification provides a strong foundation for anyone looking to develop a broader and more operational view of AI governance.
hashtag