Data Governance · Access · Component
The permissions
Who may see what, granted by role — because individual grants accumulate with tenure and are never reviewed.
The deliverable
What it is
Access granted per person accumulates: someone who has changed role three times holds the permissions of all four positions.
Role-based access solves this structurally, because permissions change when the role does rather than requiring a separate decision nobody makes.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
The sensitivity
How sensitive each data set is.
3 attributes: Sensitivity · Reason · Personal data
LearnThe exceptions
Individual grants outside the role model.
3 attributes: Granted to · Reason · Expires
Learn
A growing count of individual access exceptions means the role model does not match how people work.
The other components in access
The review
When access was last checked and what was removed — because permissions are granted readily and revoked rarely.
LearnThe workarounds
Where people are routing around access controls, and why — because exported spreadsheets are a symptom rather than a violation.
Learn