I'm an engineer preparing for a certification exam, not a sysadmin or IT employee. I searched our company's SharePoint for salary ranges related to a potential future role, and a PDF appeared containing every employee's exact salary and bonus information. It seems to be accessible to anyone in the organization.
I submitted an IT ticket explaining that the document appears to be improperly exposed and contains private employee information. Now I'm worried that searching for it or reporting it could get me reprimanded. Has anyone dealt with a similar situation, and is there anything else I should do?
3 Answers
Whether salary information is legally public depends on the country, employer, and whether the organization is public or private. Some government and university employers publish individual salaries, while private companies often treat exact pay and bonuses as confidential. Either way, you weren’t wrong to report an unexpected company-wide exposure, especially since the file contained exact compensation details.
A ticket is a reasonable first step, but because this involves compensation and personal data, you could also notify the appropriate HR, privacy, compliance, or information-security contact through an established reporting channel. Keep the message factual: explain what you searched for, what appeared, when you noticed it, and that you stopped viewing it. Don’t include copies of the salary information or discuss it with coworkers.
You did the right thing by reporting it. SharePoint search normally only shows files that your account already has permission to access, so you probably didn’t bypass any security controls. The likely issue is that someone gave the file broad access or stored it in a site available to the whole organization. Keep the ticket number and avoid opening, downloading, copying, or sharing the document further.
The access logs may show that you viewed it, but reporting it promptly gives you a clear record that you acted responsibly. The bigger concern would be accessing it repeatedly or sharing it after discovering the mistake.

If your organization has an ethics hotline or security-reporting process, that can provide another documented route. A responsible company should focus on fixing the permissions rather than blaming the person who raised the alarm.