Customer 360 Enterprise Data Platform — Denodo on Azure  ·  View 36 of 39  ·  Assurance

Authorisation Model

One policy set per role, and every channel inheriting it without restating it.

Editable source SVG draw.io All views
Datasets granted Column policy Row policy Channels Service Agent Customer360, Support Contact masked to last 4 Own contact-centre queue Desktop REST, assistant Relationship Manager Customer360, Orders, Value Full contact, no payment Own account book Power BI, Excel BI Developer Certified business views Value masked until granted All rows, aggregate only Design Studio, Power BI Data Scientist Integration and business views Pseudonymised keys Sampled cohorts JDBC from notebooks Data Steward Every view and the crosswalk Unmasked, reason recorded All rows Studio, catalog, console Privacy Officer DSAR assembly view only Unmasked, case-scoped One subject at a time DSAR console Platform SRE Metadata and logs only No customer columns No customer rows Monitor, Solution Manager AI Assistant Whatever the caller has Whatever the caller has Whatever the caller has MCP tools only Partner Portal Contracted subset No personal data at all Own contracted accounts REST through APIM Authorisation — One Policy Set, Inherited by Every Channel The assistant row is the whole security argument for AI: it has no grants of its own, so nothing had to be reasoned about twice. v 1.0 · owner Data & AI Global Practice · date 2026-09

The row that carries the argument

  • The AI assistant inherits the caller in all three policy columns. It has no grants of its own, so nothing had to be reasoned about twice and nothing can drift apart.
  • The same is true of every channel: JDBC, REST, GraphQL and MCP read the same grants. A policy is written once, at the integration layer, and enforced everywhere.
  • The platform SRE row is deliberately empty of customer data. Running the platform does not require seeing what is in it.

How row policy is expressed

  • As a predicate over the enterprise customer, derived from the caller's claims — region for agents, account book for relationship managers, case scope for the privacy officer.
  • Aggregate-only access for BI developers means detail rows are unavailable but counts and sums are not, which is what lets a report be built before access to the detail is granted.

Risks

  • The steward role can see everything unmasked. It is the highest-privilege role in the platform, requires a recorded reason per access, and is reviewed monthly.