> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Module 2 · Model the Policy

> Goal: a written who-sees-what matrix that both the DBA and the workspace admin have agreed to — the input for everything that follows. (~15 min)

**Goal:** a written who-sees-what matrix that both the DBA and the workspace admin have agreed to — the input for everything that follows.

## 2.1 · The matrix

One row per persona; be concrete about the *attribute* that drives each restriction — that attribute is what the guard will key on:

<table><tr><th>Persona</th><th>Row scope</th><th>Column handling</th><th>Grain</th><th>Enforced by</th></tr>
<tr><td>Finance analyst</td><td>All regions</td><td>Full</td><td>Detail</td><td>Warehouse role</td></tr>
<tr><td>Regional analyst — \[East]</td><td>\[region = East] only</td><td>Identity fields masked</td><td>Detail</td><td>Warehouse policy or ontology guard</td></tr>
<tr><td>Executive</td><td>All regions</td><td>Aggregates only</td><td>Summary</td><td>Secure aggregate view</td></tr>
<tr><td>External \[vendor/tenant]</td><td>\[their tenant] only</td><td>Approved columns only</td><td>Per contract</td><td>Ontology guard + tenant scope</td></tr></table>

```text Prompt theme={null}
Help me build an access-policy matrix for [source]. Personas: [list them]. For each: which rows they may see (and the column/attribute that decides it), which columns are masked or excluded, and the coarsest grain they need. Format as a table I can put in front of our DBA and workspace admin for sign-off.
```

<Check>
  **You'll see:** the draft matrix. Argue about it *now*, in a document — every later module implements exactly this table, and scope arguments during implementation are how gaps ship.
</Check>

<Warning>
  **One attribute, one owner** — Every row restriction keys on an attribute (`region`, `line_of_business`, `tenant_id`). For each one, write down where it comes from and who owns it — an IdP group, a warehouse role mapping, an entitlement table. An attribute nobody owns becomes a boundary nobody maintains.
</Warning>

### ✅ Checkpoint

* [ ] The matrix exists in writing with every persona's row scope, column handling, and grain
* [ ] Each restriction names its driving attribute and that attribute's owner
* [ ] DBA and workspace admin both signed off
