Governance

Decide who sees what, once. Every answer follows it.

Priya Raman
Finance lead · sees Ledger, Planning, Pipeline
  1. Every table has a place.

    Your organisation is split into departments. A department groups its tables into scopes, and each table comes from a connector, a tool you already use, or from a file you upload.

  2. A new department starts closed.

    People join a department with a role: Department Lead, Maintainer or Member. A role sees nothing until the lead opens it. Here Maintainers were let into everything; Members see nothing yet, and anyone outside the department never does.

  3. Open it for a role.

    One rule on the department opens every table in it for one role, here Members. Nothing is written for the tables themselves, so they follow the department until something lower says otherwise. Every other role stays as it was.

  4. Deny what's sensitive.

    A deny on a scope closes just that part. Here Members lose Planning's two tables and keep the Ledger.

  5. Make one exception.

    Give one person their own rule on one table. A person's rule is read before their role's, so it wins there and nowhere else.

KestrelFinance
Finance
FinanceDepartment · A team and its data
LedgerScope · A group of tables
invoicesTable · The data Mira reads
billsConnector · Where a table syncs from, like Xero
payments
refunds
Planning
budgets
revenue_plan

Set a rule. Watch who sees what.

Pick a permission, point at any square and set it: deny, follow the row above, or allow. Everything below answers again, and the check beside it shows how.

Whether someone can see a table at all: find it, open it and ask Mira about it. Without it, the table simply isn't there for them.

KestrelFinance
Finance
Finance
Ledger
invoices
bills
payments
refunds
Planning
budgets
revenue_plan

Dan Mercer on budgets

  1. Is Dan the lead or an organisation admin?No. Read the rules.
  2. budgets: set for Dan?Nothing set here, look higher
  3. budgets: set for Members?Nothing set here, look higher
  4. Planning: set for Members?Denied here. Stop.
  5. Finance: set for Members?Not checked
  6. Nothing set anywhere?Not checked

Denied

Set hereFollows the row aboveWould change with itPoint at a square to open its switch: deny, follow the row above, or allow.The squares ringed in blue are the ones that change with it.Click a name at the top to see everything that role or person can reach.

The four permissions.

Every rule is one of these, allowed or denied for a role or a person.

Data access
See a table at all: find it, open it and ask Mira about it.
Manage context
Change a table's name, its description and what each column means.
Manage data
Add tables, replace an uploaded file or remove a table. Set for the whole department.
Manage members
Add people to the department and change their roles. Set for the whole department.

More permissions are on the way.

Checked on every question.

The rules are not a filter on the screen. Mira checks them on its servers before it reads a single row.

  • Chat only searches what you can see.

    Mira answers from the tables your rules open. If the answer sits somewhere you can't reach, it says it can't find it.

  • Dashboards and the catalogue follow suit.

    The data catalogue lists only the tables you can see, and every chart reads through the same check.

  • A change holds on the next question.

    Rules are read fresh with every request, so taking access away works straight away. If a check can't be made, nothing is shown.

Run your company on its own numbers.

Half an hour is enough to see Mira running on your own tools, with your own data.

Get in touch