1. Row & Column-Level Security advanced

    A data platform must enforce that analysts see only permitted rows and columns across thousands of tables and hundreds of users. How should this be designed so it is enforceable and auditable?

    2 min answer access-controlabacmaskinggovernance
  2. Row & Column-Level Security advanced

    A financial platform must restrict which rows and columns each analyst can see. Where should that be enforced?

    2 min answer razorpayrlsaccess-controlenforcement
  3. Row & Column-Level Security advanced

    Design field-level and record-level access controls for a business application where each customer configures their own rules.

    1 min answer rlscolumn-securitypolicymulti-tenancy
  4. Row & Column-Level Security advanced

    Row-level security on the orders table restricts each regional analyst to their own region. An audit shows a Berlin analyst's dashboard returning French rows. The policy is present and correct on the table, the analyst's attributes are right, and the query in the dashboard selects from `orders_summary`. What happened?

    3 min answer rlsmaterialised-viewspolicy-bypassaudit
  5. Row & Column-Level Security advanced

    Salesforce's published Force.com design keeps many customers' records in shared tables described by metadata, rather than giving each tenant its own schema. Weissman and Bobrowski's SIGMOD 2009 paper describes the platform supporting tens of thousands of organisations this way. What does that choice force about access control, and where would copying it be a mistake?

    2 min answer salesforcemulti-tenancyrow-level securitymetadata
  6. Self-Service vs Governed advanced

    A collaboration company wants every team to analyse data freely, and finance needs numbers that reconcile. How do you satisfy both?

    1 min answer self-servicegovernancetieringtrust
  7. Semantic Layer advanced

    A recommendation team maintains separate feature computation for offline training and online serving, and skew between them is degrading model quality. How does a feature store with point-in-time correctness fix this, and what does it cost operationally?

    3 min answer airbnbchrononfeature-storetraining-serving-skew
  8. Semantic Layer advanced

    Three teams report different numbers for the same metric and each is confident. What is the architectural cause, and what fixes it?

    2 min answer meeshosemantic-layermetricsdefinitions
  9. Semantic Layer advanced Multiple choice

    Where should shared metric definitions live so that a dashboard, a notebook and an API all produce the same number?

    1 min answer semantic-layermetricsconsistencygovernance
  10. Semantic Layer advanced

    You build a semantic layer with governed metric definitions. Six months later teams are still writing their own SQL. Why, and what do you do?

    2 min answer governanceadoptionmetrics
  11. Sensitivity Labelling advanced

    Your catalogue labels columns Public, Internal, Confidential and Restricted, and propagation takes the maximum label of all inputs. A team joins a Restricted table of health claims to an Internal table of postcodes and publishes weekly counts by postcode and condition. What does the label say, what should it say, and what goes wrong with the rule?

    2 min answer classificationpropagationaggregationk-anonymity
  12. Tokenisation & Masking advanced

    A communications platform must reduce the systems handling customer phone numbers and message content. Tokenisation or field-level encryption?

    1 min answer tokenisationencryptionscope-reductionpii