Data Governance · Access · Component

The permissions

Who may see what, granted by role — because individual grants accumulate with tenure and are never reviewed.

The deliverable

What it is

Access granted per person accumulates: someone who has changed role three times holds the permissions of all four positions.

Role-based access solves this structurally, because permissions change when the role does rather than requiring a separate decision nobody makes.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. The grants

    What access exists.

    3 attributes: Role · Data set · Basis

    Learn
  2. The sensitivity

    How sensitive each data set is.

    3 attributes: Sensitivity · Reason · Personal data

    Learn
  3. The exceptions

    Individual grants outside the role model.

    3 attributes: Granted to · Reason · Expires

    Learn

A growing count of individual access exceptions means the role model does not match how people work.