Governance
Decide who sees what, once. Every answer follows it.
Every table has a place.
Your organisation is split into departments. A department groups its tables into scopes, and each table comes from a connector, a tool you already use, or from a file you upload.
A new department starts closed.
People join a department with a role: Department Lead, Maintainer or Member. A role sees nothing until the lead opens it. Here Maintainers were let into everything; Members see nothing yet, and anyone outside the department never does.
Open it for a role.
One rule on the department opens every table in it for one role, here Members. Nothing is written for the tables themselves, so they follow the department until something lower says otherwise. Every other role stays as it was.
Deny what's sensitive.
A deny on a scope closes just that part. Here Members lose Planning's two tables and keep the Ledger.
Make one exception.
Give one person their own rule on one table. A person's rule is read before their role's, so it wins there and nowhere else.
Set a rule. Watch who sees what.
Pick a permission, point at any square and set it: deny, follow the row above, or allow. Everything below answers again, and the check beside it shows how.
Whether someone can see a table at all: find it, open it and ask Mira about it. Without it, the table simply isn't there for them.
Dan Mercer on budgets
- Is Dan the lead or an organisation admin?No. Read the rules.
- budgets: set for Dan?Nothing set here, look higher
- budgets: set for Members?Nothing set here, look higher
- Planning: set for Members?Denied here. Stop.
- Finance: set for Members?Not checked
- Nothing set anywhere?Not checked
Denied
The four permissions.
Every rule is one of these, allowed or denied for a role or a person.
- Data access
- See a table at all: find it, open it and ask Mira about it.
- Manage context
- Change a table's name, its description and what each column means.
- Manage data
- Add tables, replace an uploaded file or remove a table. Set for the whole department.
- Manage members
- Add people to the department and change their roles. Set for the whole department.
More permissions are on the way.
Checked on every question.
The rules are not a filter on the screen. Mira checks them on its servers before it reads a single row.
Chat only searches what you can see.
Mira answers from the tables your rules open. If the answer sits somewhere you can't reach, it says it can't find it.
Dashboards and the catalogue follow suit.
The data catalogue lists only the tables you can see, and every chart reads through the same check.
A change holds on the next question.
Rules are read fresh with every request, so taking access away works straight away. If a check can't be made, nothing is shown.
View the documentation
Departments, roles and who can see what, step by step.
- How departments workA department has people and tables. Who can see what, and the two kinds of role.
- People and rolesThe people in a department, changing a role, what each role may do, and adding someone.
- Department dataThe department's tables and their groups, where uploads land, and tables shared from the organisation.
Run your company on its own numbers.
Half an hour is enough to see Mira running on your own tools, with your own data.
Get in touch