
Data Governance
Do you know who can see what in your reporting?
Payroll, customer details, margin by account. Most reporting grew one request at a time, and so did the access. Governance sorts your data by sensitivity, keeps like data together, and makes sure the right people see the right numbers.
The Problem
Access grew one request at a time.
Someone needed a report, so they got access. Then the next person. A contractor. A new hire who inherited a departed employee's workspace. Nobody decided that a plant supervisor should be able to open payroll, or that customer addresses should sit in the same workspace as the production dashboard. It happened one reasonable request at a time.
If someone asked today who can see your payroll data, how long would it take to answer? Governance makes that a five-minute question.
Why It Matters
What our governance audits actually find
These are the patterns our governance audits turn up most often at mid-size manufacturers. None of them are visible to leadership until someone goes looking.
Access
Former employees still holding Admin rights weeks after their last day, because offboarding never reached the BI tenant
Grants
Access handed out one person at a time instead of through security groups, leaving no practical way to audit who can see what
Tiers
Sensitive records sharing a workspace with general reporting, because a data classification boundary was never set
Drift
The same core table copied and re-derived across many reports, so every number carries a slightly different lineage
How It Works
Sort by sensitivity. Keep like data together.
Every kind of data gets one of four sensitivity tiers. Data in the same tier lives together, in its own workspace, with one named owner. People get access through groups instead of one at a time, so when someone changes roles or leaves, their access changes with them.
Business data with no PII. A broad internal audience is fine.
Production metrics, QA data, SKU and inventory tracking
Business-sensitive. Restricted to the relevant department plus leadership.
Sales quotas, GL and finance detail, margin analysis
Contains customer or employee PII.
Customer names and addresses, HR and payroll data
Modeled attributes that imply a sensitive characteristic. The tier most frameworks miss.
Churn scores or purchase patterns that infer household or health signals
1 · Classify
Each data domain gets exactly one sensitivity tier, decided once by the people who own it.
2 · Group
Data in the same tier lives together in its own workspace. Restricted data never sits next to general reporting.
3 · Own
Every workspace has one named owner who approves what gets published and who gets in.
4 · Grant
Access goes to groups, never to one person at a time. People change roles and leave; groups persist.
Who holds which role
Most BI platforms ship four roles. Most organizations hand them out backwards.
Admin
Your IT tenant admin plus one named workspace owner. Nobody else, and never a departed employee.
Member
The workspace owner's delegates. People accountable for what gets published.
Contributor
Report builders and analysts who create content but should not manage access.
Viewer
Everyone else, granted through a security group, never one person at a time.
Run the thirteen checks yourself first.
The same questions we ask in a paid audit, as a free 15-minute self-audit. Access, classification, definitions, model hygiene.
Two Ways In
Audit what you have, or build it right from the start
Governance audit
You already have Power BI, Tableau, or a reporting estate that grew report-by-report. We audit every workspace, member, role, and dataset. You get a findings report like the tiles above, a tier classification for your data, and an ordered remediation roadmap your IT team can execute.
Build your governance system
You are rolling out BI now and want to skip the cleanup phase entirely. We design the tier framework, workspace structure, security groups, and ownership model before the first report ships, so access never has to be re-litigated report-by-report.
The Results
When governance works
You can answer who sees what
Access lives in a handful of groups, so the list of who can see sensitive data is a report you can pull, not a project.
Sensitive data stays in its lane
Payroll, customer details, and margin analysis sit in their own workspaces, away from everyday production and inventory reporting.
People leave, and their access leaves with them
Offboarding removes someone from a group, and every report they could open closes behind them.
New reports start in the right place
Classify the data once, and every report built on it inherits the right boundaries without anyone re-deciding access.
And the numbers still agree
One governed copy of each core table, instead of a dozen re-derived ones, means Finance and Operations pull the same number.

You talk to Mitch.
Find out who can see what.
Whether you need an audit of what already exists or a governance system designed from scratch, it starts with a 30-minute conversation about your data, your systems, and who has access to what.