Decoding the world of cybersecurity

AvePoint links data classification to recovery

AvePoint is linking continuously updated sensitivity classification with sequenced recovery, although its new Kinetic Classification capability remains in private preview.

AvePoint links data classification to recovery
Summary
  • Kinetic Classification is intended to reassess data sensitivity as ownership, access, lifecycle, and AI use change.
  • AvePoint is connecting classification data with recovery recommendations, pre-built restoration sequences, and Entra ID recovery.
  • The classification capability remains in private preview, and the performance claims have not been independently tested.

AvePoint is connecting continuously updated data classification with recovery sequencing, seeking to address two related problems created by expanding AI access: identifying which information is sensitive now and determining which identities, services, and data should return first after an incident.

The company announced Kinetic Classification alongside additions to its Rapid Recovery System. The classification capability is in private preview, rather than generally available, while several recovery and resilience features are being released or previewed on different schedules during August.

Kinetic Classification is intended to replace periodic or one-time labelling with an assessment that changes as new information emerges. AvePoint says it can apply sensitivity and retention labels, then revise its view as ownership, access policies, content, risk signals, lifecycle status, and interaction with AI agents change.

The proposed coverage includes Microsoft 365, Google Workspace, GitHub, ServiceNow, Jira, Confluence, Box, Okta, Smartsheet, Monday.com, DocuSign, Bitbucket, and Amazon S3. That breadth reflects the difficulty of applying a consistent classification model when corporate information is distributed across collaboration platforms, code repositories, identity systems, storage services, and business applications.

Static classification can become inaccurate even where the original label was reasonable. A document may acquire commercially sensitive content, move into a different project, gain a wider audience, pass its retention date, or become accessible to an AI agent after changes elsewhere in the environment.

The reverse problem also exists. Excessive or outdated classifications can obstruct legitimate use, increase storage and review costs, and create a large volume of warnings that no longer corresponds to current risk. A continuously recalculated model must therefore establish not only how labels change but who is accountable for disputed or incorrect decisions.

AvePoint is linking that classification data to its recovery system. New features include recommendations intended to identify the most important information to restore, a wizard for building and sequencing recovery plans in advance, and Express Recovery support for Microsoft Entra ID objects and configurations.

The company describes the priority set as a “minimum viable company”: the smallest combination of identities, services, systems, and data required to resume critical operations. The term is AvePoint’s own framing, but the underlying principle is established in operational resilience planning. Recovery time is constrained, dependencies matter, and restoring all available data simultaneously may not be possible or desirable.

Classification could improve that decision if it reliably identifies critical information and remains current. It could also misdirect recovery if labels are incomplete, ownership is wrong, business dependencies are absent, or AI-generated recommendations are accepted without testing.

Identity recovery adds another dependency. Restoring files or applications is of limited value if the organisation cannot re-establish trusted users, groups, roles, applications, and access policies. Conversely, restoring identity configurations without establishing a known-good state can reintroduce compromised privileges or relationships.

The combination therefore moves classification away from being solely a compliance or data-loss-prevention control. It becomes an input into incident response, continuity planning, recovery order, and the evidence used to explain why particular services returned before others.

AvePoint cited findings from its third annual State of AI research, conducted with Osterman Research. It said 82.7 per cent of surveyed organisations were very or extremely confident in their ability to prevent unauthorised data access, while 72 per cent of the “very confident” group still reported an AI-related unauthorised-access incident during the previous year.

Those figures are vendor-sponsored, self-reported survey results rather than independently verified incident statistics. They indicate a gap between confidence and reported experience but do not establish that classification failures caused the incidents or that AvePoint’s products would have prevented them.

The announcement follows wider industry efforts to govern AI agents as identities with access to corporate systems. Cyber Insider has examined how AI-agent deployment is straining existing identity governance, particularly where organisations cannot maintain an accurate inventory of agents, owners, permissions, and downstream data access.

Kinetic Classification extends that problem into the content layer. Knowing that an agent exists does not establish whether the information it can retrieve remains appropriate for its role as the data, project, and access model change.

AvePoint has not published independent performance evidence showing the accuracy of the classification process, the quality of its recovery recommendations, or the time saved during a real incident. The private-preview status also means the capability may change before broader release. Its immediate value is therefore as an operating-model proposal: classification, identity, backup, and recovery treated as connected controls rather than separate administrative functions.

×