Data Access Models
Role, attribute and purpose-based access over analytical data, and how they compose.
5 to work through
-
beginner Multiple choice
A team masks national identity numbers inside each BI tool's data model so analysts see only the last four digits. Security asks them to move the masking into the warehouse instead. Why does the location of the rule matter more than the rule itself?
2 min answer -
beginner
An analyst can query the customer table. A regulator asks whether she was allowed to use it for the marketing model she built. Role-based access answers one of those questions and not the other. What is the difference between role-, attribute- and purpose-based access, and what does purpose add?
2 min answer -
advanced
A data platform carries four years of accumulated standing grants: about 900 analysts in roughly 300 groups with permanent read on 6,000 tables. Legal now requires that purpose be recorded and access be time-boxed. You cannot stop analysts working for a day. Give the sequence.
3 min answer -
advanced Multiple choice
A file collaboration platform must decide how to model data access across personal files, shared folders, team spaces and external sharing. Which model fits?
1 min answer -
advanced
Review this emergency data access design. A shared role called prod_break_glass grants read on every production table. Any team lead can approve a request in a chat channel. The grant has no expiry and is removed when someone remembers. Every use writes a row to an audit table in the same warehouse. It was used 140 times last year. What would you remove, what would you change, and what would you leave alone?
3 min answer
3 terms in this topic
Data Access Model
The scheme by which permission to data is granted, whether by role, by attribute, by purpose, or by request with expiry.
patternJust-in-Time Data Access
Replacing permanent read grants with short-lived grants issued on request with a recorded purpose, so that entitlement decays by default instead of a…
patternPurpose-Based Access
Granting access for a stated and recorded purpose rather than by role alone, which is what several data protection regimes actually require.
Neighbouring topics
Data Governance & Semantics
General material on ownership, meaning, quality and control of data at enterprise scale.
Data Mesh
Domain ownership, data as a product, self-serve platform, and federated governance.
Data Products
A dataset with an owner, an interface, an SLO, and consumers who can rely on it.
Data Contracts
Producers committing to schema, semantics and freshness, and breaking builds when they do not.
Data Catalog
Discovery, ownership and technical metadata, and why catalogues go stale.
Business Glossary
Agreeing what a term means before arguing about which number is right.
Semantic Layer
Metric definitions held once and served to every tool that asks.
Master Data Management
One authoritative record for a customer or product across systems that each have their own.
Reference Data
Code lists, hierarchies and currencies — small, shared, and quietly load-bearing.
Data Quality Dimensions
Completeness, accuracy, timeliness, consistency, validity and uniqueness as testable claims.
Data Observability
Freshness, volume, schema and distribution monitoring for pipelines that fail silently.
Data Stewardship
The operating model that makes ownership a role rather than a slide.
Row & Column-Level Security
Restricting slices of a table rather than the whole table, and where it is enforced.
Tokenisation & Masking
Dynamic masking, deterministic tokens, and preserving joinability without exposure.
Retention & Purge
Deleting from an append-only estate, and proving the deletion happened.
Data Sharing & Clean Rooms
Collaborating on data neither party may hand over, with computation as the interface.
Sensitivity Labelling
Propagating a classification through joins and derived tables so controls follow the data.
BI Governance
Dashboard sprawl, certified reports, and the number the board is allowed to see.
Self-Service vs Governed
Letting analysts move fast without four teams reporting four different revenues.