Skip to main content
Goal: know exactly where each access rule should live before writing any of them.

0.1 · The doctrine in one line

The warehouse decides what data an identity may retrieve. TextQL decides which resources that identity may use. The ontology makes the authorized analysis accurate and consistent.
LayerEnforcesRole
Warehouse identity + policiesPermitted rows, columns, objects, grainCompliance boundary — the hard floor
TextQL platform (roles, connector scope, query-path dials)Which connectors, surfaces, and query paths a member may useResource authorization
Ontology (.tql guards, governed surfaces)Canonical definitions + optional narrowing beyond the floorSemantics and defaults; the enforcement layer itself when the warehouse can’t be
When enforcement lives at the warehouse, access holds no matter how a query is produced — governed TQL and ad-hoc SQL both run under the user’s identity. When enforcement lives in the ontology, it only binds queries that go through the ontology — which is why Module 6’s TQL-only lock exists.

0.2 · The behavioral trap

A persona file that says “you may only use the East-region surfaces” is an instruction to Ana, not a control. Ana follows it; a determined user with SQL access doesn’t have to. Behavioral scope is real and useful (see The Context Stack) — but nothing in this workshop is done until the boundary holds against a user actively trying to cross it (Module 5).

0.3 · The decision table

ScenarioWarehouse enforcementOntology scopingRaw SQL
PHI/PII, external vendors, tenant isolationRequiredOptional narrowingOnly under a restricted warehouse identity
Internal analysts with entitlements (region / line of business)RequiredRecommended — defaults + semanticsEnabled (their identity constrains it)
Executive aggregate-only accessRequired (secure aggregate view)RecommendedOnly against permitted aggregates
Customer-facing embedded workflowStrongly preferredGoverned API surface with runtime scopeDisabled if the ontology is the only scoping
Prototype while DBA policies are being builtPlanned final controlUseful temporary boundaryDisabled for scoped users
Prompt
You’ll see: your sources mapped to the table above. Most organizations land on: per-member auth for the analyst warehouses (Module 1), ontology guards for embedded/API surfaces and sources without per-member support (Modules 3–4).

✅ Checkpoint

  • You can state the one-line doctrine and what each layer enforces
  • You can explain why a persona file is not a security control
  • Every connected source has a tentative enforcement home from the decision table