Four machined trays stacked in tiers, the bottom tray locked, representing data sorted by sensitivity

Data Governance

Do you know who can see what in your reporting?

Payroll, customer details, margin by account. Most reporting grew one request at a time, and so did the access. Governance sorts your data by sensitivity, keeps like data together, and makes sure the right people see the right numbers.

The Problem

Access grew one request at a time.

Someone needed a report, so they got access. Then the next person. A contractor. A new hire who inherited a departed employee's workspace. Nobody decided that a plant supervisor should be able to open payroll, or that customer addresses should sit in the same workspace as the production dashboard. It happened one reasonable request at a time.

If someone asked today who can see your payroll data, how long would it take to answer? Governance makes that a five-minute question.

Why It Matters

What our governance audits actually find

These are the patterns our governance audits turn up most often at mid-size manufacturers. None of them are visible to leadership until someone goes looking.

Access

Former employees still holding Admin rights weeks after their last day, because offboarding never reached the BI tenant

Grants

Access handed out one person at a time instead of through security groups, leaving no practical way to audit who can see what

Tiers

Sensitive records sharing a workspace with general reporting, because a data classification boundary was never set

Drift

The same core table copied and re-derived across many reports, so every number carries a slightly different lineage

How It Works

Sort by sensitivity. Keep like data together.

Every kind of data gets one of four sensitivity tiers. Data in the same tier lives together, in its own workspace, with one named owner. People get access through groups instead of one at a time, so when someone changes roles or leaves, their access changes with them.

Internal

Business data with no PII. A broad internal audience is fine.

Production metrics, QA data, SKU and inventory tracking

Confidential

Business-sensitive. Restricted to the relevant department plus leadership.

Sales quotas, GL and finance detail, margin analysis

Restricted

Contains customer or employee PII.

Customer names and addresses, HR and payroll data

Restricted - Derived

Modeled attributes that imply a sensitive characteristic. The tier most frameworks miss.

Churn scores or purchase patterns that infer household or health signals

1 · Classify

Each data domain gets exactly one sensitivity tier, decided once by the people who own it.

2 · Group

Data in the same tier lives together in its own workspace. Restricted data never sits next to general reporting.

3 · Own

Every workspace has one named owner who approves what gets published and who gets in.

4 · Grant

Access goes to groups, never to one person at a time. People change roles and leave; groups persist.

Who holds which role

Most BI platforms ship four roles. Most organizations hand them out backwards.

Admin

Your IT tenant admin plus one named workspace owner. Nobody else, and never a departed employee.

Member

The workspace owner's delegates. People accountable for what gets published.

Contributor

Report builders and analysts who create content but should not manage access.

Viewer

Everyone else, granted through a security group, never one person at a time.

Run the thirteen checks yourself first.

The same questions we ask in a paid audit, as a free 15-minute self-audit. Access, classification, definitions, model hygiene.

Two Ways In

Audit what you have, or build it right from the start

Governance audit

You already have Power BI, Tableau, or a reporting estate that grew report-by-report. We audit every workspace, member, role, and dataset. You get a findings report like the tiles above, a tier classification for your data, and an ordered remediation roadmap your IT team can execute.

Build your governance system

You are rolling out BI now and want to skip the cleanup phase entirely. We design the tier framework, workspace structure, security groups, and ownership model before the first report ships, so access never has to be re-litigated report-by-report.

The Results

When governance works

You can answer who sees what

Access lives in a handful of groups, so the list of who can see sensitive data is a report you can pull, not a project.

Sensitive data stays in its lane

Payroll, customer details, and margin analysis sit in their own workspaces, away from everyday production and inventory reporting.

People leave, and their access leaves with them

Offboarding removes someone from a group, and every report they could open closes behind them.

New reports start in the right place

Classify the data once, and every report built on it inherits the right boundaries without anyone re-deciding access.

And the numbers still agree

One governed copy of each core table, instead of a dozen re-derived ones, means Finance and Operations pull the same number.

Mitch Cauthron

You talk to Mitch.

Find out who can see what.

Whether you need an audit of what already exists or a governance system designed from scratch, it starts with a 30-minute conversation about your data, your systems, and who has access to what.