- Brooklyn, New York, April 2025You might think that administrating people’s access to data is the most boring part of data management, but it’s one of the coolest parts of the job for me.
Business people usually approach security reviews as a necessary evil, a list of items on a policy compliance checklist. That’s not the case with a good data strategy. When you sit down with a business leader and ask who should see their data, it’s like you’ve given them a gift. You’ve recognized their authority and told them that they can hide data from anyone, at any level of detail they decide, making their decisions effective everywhere.
You’ve given them control.
CIOs know low-level service tasks can improve or destroy an IT department's reputation, and managing data security falls squarely in that category. I want to show you how to flip the script on this narrative and use data security to build partnerships with leaders. You can transform people’s daily lives by giving them exactly the data they need to do their jobs.
Imagine a world where nobody complains about not having enough access and nobody worries about exposing more data than they should. That’s the promise of this solution.
Ownership Where It Belongs
Companies often assign technical people the responsibility for managing internal data security. Think about it. Do IT people understand other employees' jobs well enough to know what data they need? Of course not. Do they know which data is sensitive or benign? No. IT people just see files on a server. When you put IT people in charge of securing internal data, they just ask people what data they need (through far too many emails) and give it to them.
The most granular way to secure business data is called “cell-level” security, which I wrote about last week. That means controlling data access at the intersection of the rows and columns within your database tables. To do that, you need to know your data and who needs to use it. IT people aren’t the experts in either area; you need to find business owners for both decisions.
You need two people involved in every access decision: one who knows the data (data owner) and another who knows the people (role owner):
Data Owners. These people know the meaning of the data (like pricing or costs) and have management authority to decide which types of job roles need to see that data. For example, the VP of Marketing (Helly R., in my illustration) owns all pricing data. As the data owner, she decides if financial analysts, sales analysts, product engineers, and HR staff (for example) need access to pricing data. She isn’t concerned about which individuals get access to pricing data; she only cares about which job roles need the data.
- Role Owners. These people know who is qualified to work in a given job, and they usually manage people working in that role. For example, the VP of Product Engineering (Mark S., in my illustration) owns the “product engineer” role used to assign access to data. When someone (like a new employee) wants access to data, he approves their request to become a member of that role. If he thinks product engineers need pricing data to do their jobs, he can discuss it with Helly on behalf of all product engineers.
Beyond Compliance
Giving people control of security decisions helped me, too.
Two dozen executives from all areas of the company - finance, sales, manufacturing, marketing, and even R&D - welcomed me into their offices every quarter to review the permissions. We’d usually spend the first ten minutes of that hour reviewing people and their permissions, identifying a few updates along the way. Then we’d spend the rest of the hour discussing upcoming plans for the data warehouse. It was a great time to ask them what new data they could use for their team’s decisions.
Often, those discussions turned into brainstorming new project ideas, using whiteboards to sketch out relationships between data sets, and thinking together about what new insight they might inspire.
Managing data security can be fun, I promise. Don’t treat it like a compliance chore. Instead, use it to empower the people you work with and become their trusted business partner.