How to control internal access while preparing records for licensing

Limit who can touch exports during a licensing project: name a small team, stage files in one locked area, log every access, and delete working copies once handover is confirmed. Internal handling is where leaks tend to start, so set these controls before the first export runs, not after.

Why internal access is the part owners forget

Most owners think about what the buyer will see. Fewer think about who inside the company will see the records while they are being gathered. Exports pull email, chat, tickets and finance files into one place, and a folder that is readable by the whole company is a leak waiting to happen.

The controls below apply whether the company hands over files from its own storage, as SourceX expects for large deliveries, or ships on encrypted drives. Because SourceX does not hold multi-terabyte datasets, working copies live in the company's own environment, and protecting them is the company's job.

Partners are not part of this. A partner introduces the company and never exports, uploads or describes confidential records.

What do you need in place first?

Before the first export, confirm these prerequisites:

  • A written decision from the authorized sponsor (owner, CEO, CFO or authorized representative) that the project is going ahead to the inventory stage.
  • Agreed scope: which systems, which date range, which exclusions.
  • A named project lead who is not the person running the exports.
  • The redaction and de-identification requirements, which are agreed with the company before any work begins.
  • A list of who in IT can run exports for each system.

Step-by-step controls

  1. Name the handler group. Pick the smallest group that can do the work, usually one IT administrator per system plus a reviewer. Write the names down. Anyone else asking for access goes through the project lead.
  2. Use least privilege. Give each handler access only to the systems they must export from, only for the project window. Remove the access when their task ends, not when the project ends.
  3. Build one staging area. Create a single restricted location for working copies, separate from shared drives and personal folders. No one uploads to it from a laptop's local disk unless the policy says so.
  4. Separate duties. The person who exports should not be the person who approves what leaves the staging area. Two sets of eyes catch mistakes.
  5. Log every access. Turn on audit logging for the staging area and export tools. Keep the logs for the length of the project and the agreed term in the contract.
  6. Block copies. Disable downloads to personal devices and personal email forwarding for the staging area. If the company already has data loss prevention tooling, apply it here.
  7. Review a sample. Run the agreed rules on a small slice and have a named reviewer sign off before scaling up.
  8. Record the handover. When files go to the buyer or are made available in the seller's own storage, write down what was handed over, when, by whom and how it was verified. The delivery manifest template is a starting point.
  9. Delete working copies. After handover is confirmed, delete the staging area and any local copies, and record the deletion with a date and an approver. Keep only what the agreement says the company must keep.

Who gets access to what?

RoleTypical accessNever
Authorized sponsorDecisions, approvals, summary reportsRaw exports unless needed
Project leadScope, schedule, access listRunning exports themselves
IT administratorExport tools for assigned systemsStaging area review rights
ReviewerStaging area, read onlyExport tools
CounselScope, redaction rules, sample resultsDay-to-day file handling
HRRules on employee communications and noticesRaw message content

What mistakes cause leaks?

MistakeWhy it hurtsFix
Exporting to a shared drive "just for now"Anyone with drive access can read itCreate the staging area first, then export
Admin credentials passed in chatCredentials persist in logs and screenshotsUse a vault and per-person accounts
Keeping working copies after handoverCopies outlive the project and the agreementDelete on a dated checklist
Letting managers "peek" at samplesSpreads sensitive content informallyRoute requests through the project lead
No audit trailYou cannot show who saw whatTurn on logs before the first export
Staff first hear about it from a leakDistrust and rumorsTell the right people early; see who to involve first

Do formal security rules apply?

It depends on the industry. Companies that are financial institutions covered by the FTC's Safeguards Rule must maintain a written information security program, as explained in the FTC's guide to the Safeguards Rule. A licensing project is a good moment to check that the staging area fits that program. This is general information, not legal, tax or financial advice. Confirm with your own counsel, tax adviser or professional body before acting.

Other contracts, such as client security addenda, may also limit who can handle certain records. Check them before the export starts. The stakeholder objection map lists the concerns different teams usually raise, and the guide on notifying outside parties covers who outside the company should know.

Example: a 140-person engineering firm

Illustrative and fictional. A 140-person engineering services firm decides to explore a license of project records. The CFO names an IT manager as project lead and asks the systems administrator to export from the ticketing tool and the document store only. A restricted folder is created with a reviewer holding read-only rights. The first sample is checked against the agreed rules, and a second reviewer in finance signs off. After handover, the folder is deleted and the deletion is recorded.

Nothing in this example is a benchmark; it simply shows how few people need to be involved.

What if the project is already under way?

Pause new exports, list who has touched what, move any stray files into a staging area and delete the rest. Tell counsel if sensitive material was exposed internally. Then restart with the controls above. A pause is cheaper than a leak.

What to tell the IT team

Keep the briefing short and specific, and put it in writing so the scope is not renegotiated verbally.

When do the controls start and stop?

StageControl focusDone when
InventoryList systems only; no content copiedInventory approved by sponsor
SampleStaging area live, logging on, reviewer namedReviewer signs off the sample
Full preparationHandler group fixed, downloads blockedCounsel confirms scope matches the agreement
HandoverManifest recorded and verifiedBuyer confirms receipt or access
CleanupWorking copies deleted, access revokedDeletion recorded with date and approver

Next step

If an owner you know wants to explore licensing but worries about how the project is run internally, point them to the portfolio reputational risk guide and the finance workflow assessment guide. Then register as a partner and make the introduction. The referral FAQ explains the rest.

  1. Step 1Share your linkSend your personal link to a company you know.
  2. Step 2Company appliesThe company applies itself at /apply.
  3. Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
  4. Step 4You get your rewardYour share of SourceX fees becomes payable.

Common questions

How many people should have access to exports?

As few as the work allows: usually one IT administrator per system, a reviewer and a project lead. The exact number depends on how many systems are in scope. Write the names down and remove access as each person's task ends.

Where should working copies live?

In one restricted staging area inside the company's own environment, separate from shared drives and personal folders. Until handover, the working data sits in the company's storage or on encrypted drives, so that is where the controls need to apply.

Do we need to tell employees about the project?

Often yes, and early. HR and counsel can advise on notices and on which communications to exclude. Learning about a project from a rumor is worse than hearing about it from leadership with clear scope limits.

When should working copies be deleted?

After handover is confirmed and recorded, unless the agreement requires the company to keep something. Put a dated deletion step and an approver on the project checklist, and keep the record.

Does the partner who introduced us need any access?

No. Partners make the introduction and give basic fit information only. They never export, upload or describe confidential records, and they should not appear on any access list.

Free resources

By SourceX Partnerships Team · Published 2026-10-09 · Updated 2026-10-09

Know a US company with valuable proprietary data?

Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.

Refer a company →

I own a business

Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.

Start an assessment