This guide reflects KAUST IT policy as it stands today. If you need advice for your own situation, contact IT through VITA or the IT Contact Us page.
The data you create, store, and share while you are at KAUST belongs to KAUST. Think of yourself as its steward, not its owner. That shapes every choice you make about where to keep a file, who to share it with, and how carefully to protect it.
Know what you have
Not all KAUST data carries the same weight. Knowing how data is classified is the first step to handling it well.
Store it in the right place
Where a file lives decides who can reach it, and what happens to it when you leave.
Share with intention
Pick the most limited option that still lets the work get done.
Keep access current
Giving someone access and never checking it again is not good stewardship.
I am:
Pick a level to see what it means and how to handle it.
KAUST's Data Classification Procedure sets out four levels. If you are not sure which one applies, treat the data as Restricted.
Rule of thumb: research data, staff records, financial records, and contracts are all Restricted. Ask IT before you share a dataset you are unsure about.
Pick a situation on the left to see the right tools for it.
Personal work files
Drafts and files that are yours
Team collaboration
Shared content for groups
Large research datasets
PIs, centers, core labs
Sensitive or regulated data
Encrypted, compliance grade
Sharing outside KAUST
External collaborators
Cloud and research computing
Azure and specialist kit
Share only with people who need it. Pick the tightest option. Review it later.
| Link type | Who can open it | Use it when |
|---|---|---|
| Anyone | No sign-in needed. Can be forwarded. 90 days maximum. | The content is Public. |
| People in KAUST | Needs a KAUST account. | Internal content for the KAUST community. |
| Specific People | Named people only. People outside KAUST get a one-time passcode. | Most sharing at KAUST. Make this your default. |
| Direct Access | No link at all. Managed through Manage Access. | Restricted content that needs the tightest control. |
Can edit
Open, change, save, and delete.
Can review
Comments only. Word, Excel, PowerPoint.
Can view
Read only. Can still download unless you block it.
View, no download
Browser only. No saving and no printing.
In OneDrive on the web, open Shared, then Shared by Me. To check one file, right-click it and choose Manage Access.
Owners have full control, and every site needs two of them. Members can edit. Visitors can read. If you need different permissions, break inheritance at the library level, not on single files.
External access to SharePoint is switched off by default. Contact IT if you need it. Site owners cannot turn it on themselves.
Viewer
Read only.
Commenter
Can comment but cannot edit.
Editor
Can make changes. Use it only when it is needed.
Use Share and type in specific people. Avoid Anyone with the link unless the content really is Public.
KAUST does not offer Google Shared Drives. Every Google Drive here is personal. Team content that has to outlast one person belongs in SharePoint.
Access does not update itself. Someone has to manage it.
What happens to each platform when someone leaves
Microsoft 365: add them through Teams and they get SharePoint, Planner, and Teams at once. If they only need to read a SharePoint site, add them to the Visitors group instead.
Google Workspace: share the files or folders directly. There are no Google Shared Drives at KAUST, so team content belongs in SharePoint.
DataWaha and SDataWaha: the folder owner manages access. Add the new person at the right level.
Google Drive: deleted the moment the account closes. Nothing can be recovered. Move team files to SharePoint first.
OneDrive: you get 60 days. Move team content to SharePoint before the person leaves, not during that window.
Move Microsoft 365 team files to SharePoint, not to someone's personal OneDrive.
Move Google Drive files to SharePoint before the account closes. Nothing can be recovered afterwards.
Hand over any Google Docs, Sheets, or Slides that colleagues still need.
Update the DataWaha and SDataWaha access lists.
Check that every Team or SharePoint site they owned still has an active owner.
Access does not update itself. Review what they can still reach and remove the old access on or just after the change.
Taking someone out of a Team does not take them out of its private channels. Those have their own membership and you have to manage them separately.
Go through the access list for every workspace the project used. Remove anyone who was only there for the project. Then decide whether to archive the workspace or close it.
A workspace nobody uses still has members and open permissions. That is a risk. Archive it or close it.
Check with IT before you connect any outside tool to your KAUST account.
Pasting Restricted or Highly Restricted content into a public or unapproved AI tool is not permitted under KAUST's Acceptable Use Policy. This includes research data, personnel information, financial data, and contractual content.
KAUST IT controls which third-party add-ins and AI tools work inside Microsoft 365. Only tools IT has reviewed stay available. These controls are being extended to other KAUST platforms.
Not permitted
Pasting Restricted or Highly Restricted content into a public or unapproved AI tool.
Not permitted
Connecting other apps with Sign in with Microsoft or Sign in with Google, without IT approval.
Not permitted
Personal AI tools recording meeting audio or reading your KAUST account, without IT approval.
Permitted
AI tools IT has approved, used within the limits of that approval. Most needs are already covered.
Need a tool that is not approved yet? Ask through VITA or the IT Service Center. IT will approve it, suggest something else, or explain the problem.
Every KAUST-issued device gets security controls, patching, and compliance settings applied by IT.
You can only reach SDataWaha from a KAUST IT managed device. That is a deliberate security control. Ask for a device through VITA or the IT Service Center.
Some GPU models fall under U.S. BIS export control rules. KAUST reviews all of this hardware before it is bought.
Data that comes off an export controlled system can carry export control duties of its own. Talk to IT before you store it or share it on a standard platform.
KAUST uses Cisco Secure Client. You need it off campus to reach DataWaha, SDataWaha, and internal systems. Microsoft 365 and Google Workspace work without it. Duo is required for Microsoft 365 when you are off campus.
DataWaha, WahaDrive, and workstation home folders are backed up every day by KAUST IT Research Computing. You do not need to set anything up.
Version history in Microsoft 365 and Google Workspace is not a backup plan for research data.
These apply to everyone at KAUST.
Know what kind of data you have, and protect it based on its classification level.
Check who actually needs the file before you share it. Picking the widest link type without thinking about it is not good enough.
Keep Restricted and Highly Restricted data out of unapproved AI tools and personal cloud storage.
Keep access current. Giving someone access and never reviewing it is not acceptable stewardship.
Secure team content before you leave KAUST. This matters most for Google Drive, which is deleted straight away with no way to get it back.
Non-compliance can result in disciplinary action up to and including termination of employment.
The four data roles at KAUST
Open a role to see what it covers and what is expected.
Data Owner
A senior leader accountable for a category of data
See responsibilitiesData Steward
A manager or team lead applying the Owner's rules day to day
See responsibilitiesData Custodian
The IT or systems team looking after the technical side
See responsibilitiesData User
Anyone who works with KAUST data as part of their job
See responsibilitiesSearch, or filter by topic.
Every time you save, share, or open a file at work, you are making a decision about data. Data responsibility means knowing what kind of data you have, keeping it in the right place, sharing it only with people who need it, and checking that access from time to time.
Yes. Data you create, collect, or process as part of your work at KAUST belongs to KAUST. That covers research data, working documents, messages, and anything else your work produces here.
Public data is safe to share with anyone. Internal data is for the KAUST community. Restricted data could cause real harm if the wrong people see it, and that covers most research data, staff records, and financial documents. Highly Restricted data carries legal protections or serious security risk. If you are not sure, treat it as Restricted.
Microsoft 365 and Google Workspace are both approved. Staff and most faculty work mainly in Microsoft 365 and Outlook. Researchers, post-docs, MS and PhD students, and faculty whose email runs on Google Workspace work mainly in Google and Gmail. Team content that has to last belongs in SharePoint either way.
OneDrive starts at 25 GB and can go up to 50 GB. On Google Workspace, faculty whose email is on Google, researchers, post-docs, and MS and PhD students share a 100 GB pool across Drive, Gmail, and Google Photos, so a large mailbox eats into your file storage. Staff get 5 GB on Google, meant for working with colleagues who use Google Workspace.
Both are private until you share something. If your account closes, OneDrive is held for 60 days and your manager can move files during that time. Personal Google Drive is deleted straight away, with no window at all.
DataWaha is the KAUST platform for large research datasets. It is open to PIs, research centers, and core labs. Each allocation gives you 20 TB of active storage plus 80 TB of archive. It is not built for running compute jobs. Request it through VITA or the IT Service Center.
SDataWaha is the secure version, built for research data that needs stronger protection, including human genome data. It shares the same 100 TB quota as DataWaha. It adds full encryption and it only works from KAUST IT managed devices. Request it through VITA or the IT Service Center.
No. Personal cloud services sit outside KAUST's control and are not approved for KAUST data. Keep KAUST work in KAUST systems.
Use Specific People as the link type, and pick the lowest permission that still lets the work happen. View only unless someone really needs to edit. If the access is temporary, set an expiry date.
An Anyone link needs no sign-in and can be forwarded to anybody. Only use it for content that is genuinely Public. Never use it for Internal, Restricted, or Highly Restricted data.
Contact IT first. External access is switched off by default and site owners cannot turn it on themselves. If the person only needs to join a meeting, send them a meeting link instead.
Use ExRCSDrive to share research data by link. For bulk transfers to another research institution, use the Scientific DMZ. Ask IT which one fits your case.
That is how it works. Every Team sits on a Microsoft 365 Group, so adding someone to the Team also gives them the SharePoint site and the Planner boards. If they only need one meeting, send a meeting link instead.
Your personal Google Drive is deleted the moment your KAUST account closes. There is no recovery window and no way to get the files back. KAUST does not offer Google Shared Drives, so move any team files to SharePoint well before your last day.
OneDrive is held for 60 days after your account closes. Your manager gets a notice and can move files during that time. After 60 days everything is deleted permanently. Team content should already be in SharePoint before you go.
You can use AI tools IT has approved, within the limits of that approval. Check with IT before you connect any AI tool to your KAUST account. Pasting Restricted or Highly Restricted content into a public or unapproved AI tool is not permitted.
Export controls are rules from the U.S. Department of Commerce that limit how certain technologies can be shared. They matter most to researchers working with specific GPU hardware and other listed technologies. If that sounds like your work, talk to IT.
The named site owners. IT provides the platform, but the owners decide who gets in. They keep the membership list current, manage permissions, and review access whenever the team changes. Every site needs at least two owners.
If you can remove or tighten the access yourself, do that first. Then contact IT straight away through any channel on the IT Contact Us page. Reporting early gives IT far more options.
It is a device that IT sets up and keeps patched, with security controls in place. SDataWaha requires one. Reaching Restricted data from a device IT does not manage creates a risk that KAUST's controls cannot cover.
No questions match that search.
Find your situation and work through the list.
Open OneDrive on the web and go to Shared, then Shared by Me. Look for Anyone links and old access.
Remove or update any share you no longer use.
Set an expiry date on new shares that are only temporary.
Move files your colleagues use regularly out of OneDrive and into a SharePoint site.
Go through what you have shared and take away access nobody needs anymore.
Move team and research files out of personal Google Drive and into SharePoint.
If you are leaving, hand over any Google Docs, Sheets, or Slides that others still need.
Check the access list and remove anyone who has left or changed role.
Make sure you have a data management plan. Data you are not actively using should move to Tier 2.
Review your WahaDrive share links and remove any you no longer use.
Check that you have two active owners. If you are the only one, add a second today.
Go through Members and Visitors. Remove anyone who has left, changed role, or finished the project.
Look for Restricted content sitting in a general library. If you find some, give it a dedicated library with its own permissions.
Check that Microsoft 365 team files are in SharePoint, not in their personal OneDrive.
Move Google Drive team files to SharePoint before the account closes. Nothing can be recovered afterwards.
Get ownership of any Google files the team still needs transferred over.
Update the DataWaha and SDataWaha access lists.
Know the classification of the data you handle most often.
Check with IT before you connect a new tool to your KAUST account.
If you are leaving KAUST, move team content before your last day.
Tell IT straight away if you have any concern about data.
Report a concern or get help. Contact IT through any of these channels.
Reporting early matters. There are far more ways to contain a data incident in the first few hours than there are days later.