Skip to content

Security & Governance

Access model, data protection and lineage controls applied consistently across every workspace.

Principle

Access is granted to groups, never to people.

Individual grants are invisible six months later and impossible to audit. Roles are defined once, mapped to groups, and reviewed on a schedule.

Structure

Identity

GroupsRoles

Workspace

AdminContributorViewer

Data

Row-level securitySensitivity labels

Access layers from identity to data.

Procedure

  1. 01

    Define the role model

    Enumerate the roles the platform needs before granting anything. Placeholder body copy to be completed.

  2. 02

    Map roles to groups

    Each workspace role is held by a group with a named owner. Placeholder body copy to be completed.

  3. 03

    Apply data-level controls

    Row-level security and labelling are defined in the semantic model, not per report. Placeholder body copy to be completed.

  4. 04

    Schedule the access review

    Membership is re-attested on a fixed cadence. Placeholder body copy to be completed.

Verification

  • No workspace role is assigned to an individual account.
  • Every group has a named owner.
  • Row-level security is tested with a role-impersonation run.
  • An access review date is booked and recorded.