2.1 · The matrix
One row per persona; be concrete about the attribute that drives each restriction — that attribute is what the guard will key on:| Persona | Row scope | Column handling | Grain | Enforced by |
|---|---|---|---|---|
| Finance analyst | All regions | Full | Detail | Warehouse role |
| Regional analyst — [East] | [region = East] only | Identity fields masked | Detail | Warehouse policy or ontology guard |
| Executive | All regions | Aggregates only | Summary | Secure aggregate view |
| External [vendor/tenant] | [their tenant] only | Approved columns only | Per contract | Ontology guard + tenant scope |
Prompt
You’ll see: the draft matrix. Argue about it now, in a document — every later module implements exactly this table, and scope arguments during implementation are how gaps ship.
✅ Checkpoint
- The matrix exists in writing with every persona’s row scope, column handling, and grain
- Each restriction names its driving attribute and that attribute’s owner
- DBA and workspace admin both signed off