Skip to main content
Goal: a written who-sees-what matrix that both the DBA and the workspace admin have agreed to — the input for everything that follows.

2.1 · The matrix

One row per persona; be concrete about the attribute that drives each restriction — that attribute is what the guard will key on:
PersonaRow scopeColumn handlingGrainEnforced by
Finance analystAll regionsFullDetailWarehouse role
Regional analyst — [East][region = East] onlyIdentity fields maskedDetailWarehouse policy or ontology guard
ExecutiveAll regionsAggregates onlySummarySecure aggregate view
External [vendor/tenant][their tenant] onlyApproved columns onlyPer contractOntology guard + tenant scope
Prompt
You’ll see: the draft matrix. Argue about it now, in a document — every later module implements exactly this table, and scope arguments during implementation are how gaps ship.
One attribute, one owner — Every row restriction keys on an attribute (region, line_of_business, tenant_id). For each one, write down where it comes from and who owns it — an IdP group, a warehouse role mapping, an entitlement table. An attribute nobody owns becomes a boundary nobody maintains.

✅ Checkpoint

  • The matrix exists in writing with every persona’s row scope, column handling, and grain
  • Each restriction names its driving attribute and that attribute’s owner
  • DBA and workspace admin both signed off