tenfold CE adds shared file reviews and event auditing
tenfold Software has added two features to the free Community Edition (CE) of its Identity Governance and Administration (IGA) platform. The first gives administrators oversight of content shared in Microsoft 365. The second adds centralized auditing of identity events.
The announcement was published as sponsored content written by tenfold, so the product claims below are the vendor's own.
IGA covers the processes and tools that decide who gets access to which systems and data, and how that access is checked and removed over time. tenfold argues that this becomes harder as IT environments grow more fragmented. Organizations need to give staff, suppliers and guests the access they need, and no more, while still protecting critical data.
A gap between spreadsheets and enterprise suites
According to tenfold, manual governance starts to fail once an organization grows past a few dozen users. Typical symptoms include slow onboarding, users with more privileges than they need, stale accounts that are never cleaned up, and no clear view of who can access what. The company says this slows IT work and raises the risk of data leaks and breaches.
The vendor also points out that most IGA products are designed for large enterprises. That makes them too expensive and too complex for smaller IT teams. As a result, many mid-sized organizations are stuck between manual administration and full automation.
tenfold says it built its platform around no-code configuration and a range of ready-made plugins to lower that barrier. The Community Edition is free for organizations with fewer than 150 managed users, and that count includes admin and service accounts. The company says CE includes every feature and integration from its top licensing tier, with no usage limits beyond the user cap. Organizations request it through tenfold's website.
The vendor highlights three further points about CE:
- Setup: a setup wizard and built-in integrations for Active Directory and Entra ID, Microsoft's on-premises and cloud identity services, along with video tutorials for first steps.
- Feature parity: CE receives new features and updates at the same time as the paid tiers, with no delayed or premium-only releases.
- Community support: an official CE subreddit where users can get help from each other and from tenfold staff.
Reviewing what users share in Microsoft 365
The first new feature targets shared content in Microsoft 365. tenfold calls this a security blind spot for many organizations and says the native governance tools are not granular enough. In its view, it is hard even to see what users are sharing, let alone audit that access.
The feature has two parts. One is a central overview of shared files across Teams, OneDrive and SharePoint. It covers content in SharePoint sites, Teams channels, one-on-one chats and files shared from personal OneDrives.
The other is recurring access reviews. Owners of files, channels or sites are asked to check who can still reach content they shared in the past. Each reviewer gets a link to a personal dashboard with a checklist of every in-scope item they have shared, where they can confirm or revoke access. tenfold says the aim is to prevent oversharing and lingering cloud access while still letting staff use M365's sharing features.
Event auditing for identity threats
The second addition pairs governance with real-time log analysis. tenfold argues that governance and passive risk reduction alone are no longer enough against modern identity threats, and that organizations need live event data to spot attacks as they happen.
With the event auditing feature, administrators can:
- ingest and analyze event log data
- record chosen event types in tenfold's database
- filter events by user, system or event type
- save and share queries for repeated searches
- flag suspicious activity, such as spikes in logins or newly created admin accounts
The company says this lets teams respond to threats before they escalate.
Our Take
Identity has become one of the main battlegrounds in enterprise security, and smaller organizations often lack the budget and staff for dedicated governance tooling. A free tier that tenfold says matches its top licence could help those teams move away from manual access management. Readers should still remember that the claims come from the vendor's own promotional text and have not been independently tested.
The shared content feature tackles a familiar problem. Access that outlives its purpose keeps showing up as a risk, from forgotten M365 shares to AI agents that keep data access after their tasks are done. Recurring owner reviews are a sensible control, but they only work if reviewers actually respond to them.
It is worth watching whether the 150-user cap fits real-world environments once service accounts are counted. It is also worth watching how event auditing works alongside Microsoft's own changes, such as recent moves in Microsoft Entra ID to harden the sign-in process.
