Archive · Frictionless Decisions

The Business Owns the Data

Building Trust by Handing Over Control

2026-07-14 · Zane Hall · 875 words · 1 reactions · 0 comments · original

Building Trust by Handing Over Control

Frictionless Decisions brings you counterintuitive, original, jargon-free ideas for connecting data to decisions.

Subscribe now


You might think that administrating people’s access to data is the most boring part of working in IT, but it’s one of the coolest parts of the job for me.

Business people usually approach security reviews as a necessary evil, a list of items on a policy compliance checklist. That’s not the case with a good data strategy. When you sit down with a business leader and ask who should see their data, it’s like you’ve given them a gift. You’ve recognized their authority and told them that they can hide data from anyone, at any level of detail they decide, making their decisions effective everywhere.

You’ve given them control. After all, it’s their data.

Flip the Script

CIOs know low-level service tasks can improve or destroy an IT department’s reputation; people grade you by their experience when they contact the help desk. Managing data security falls squarely in that category. You can flip the script on this narrative and use data security to build partnerships with leaders. You can transform people’s daily lives by giving them exactly the data they need to do their jobs.

Imagine a world where nobody complains about not having enough access, and nobody worries about exposing more data than they should. That’s the promise of a good analytics security solution.

Companies often assign technical people the responsibility for managing internal data security. Think about it. Do IT people understand other employees’ jobs well enough to know what data they need? Of course not. Do they know which data is sensitive or benign? No. IT people just see files on a server. When you put IT people in charge of securing internal data, they just ask people what data they need (through far too many emails) and give it to them.

Who Knows the Data?

The most granular way to secure business data is called “cell-level” security: controlling data access at the intersection of the rows and columns within your database tables. To do that, you need to know your data, who owns decisions about it, and who needs it for their job. IT people aren’t experts in either area; you need to find business owners to make these decisions.

You need two people involved in every access decision, one who knows the data (data owner) and another who knows the people (role owner):

Data Owners. These people know the meaning of the data (like pricing or costs) and have management authority to decide which types of job roles need to see that data. For example, the VP of Marketing (Helly R., in my illustration below) owns all pricing data. As the data owner, she decides if financial analysts, sales analysts, product engineers, and HR staff (for example) need access to pricing data. She isn’t concerned about which individuals get access to pricing data; she only cares about which job roles need the data.

Role Owners. These people know who is qualified to work in a given job, and they usually manage people working in that role. For example, the VP of Product Engineering (Mark S., in my illustration below) owns the “product engineer” role used to assign access to data. When someone (like a new employee) wants access to data, he approves their request to become a member of that role. If he thinks product engineers need pricing data to do their jobs, he can discuss it with Helly on behalf of all product engineers.

Here’s an example of how these permissions look in a table:

This matrix demonstrates a fundamental feature of scalable, granular, understandable security: it relies on logically structured master data.

It also relies on an effective “identity management” solution, like Windows Integrated Security. People should be free to use whatever tool they want to visualize, pivot, or simply report from the data. That’s a core tenet of a frictionless data strategy: pushing security enforcement to the lowest level of the system makes your data “tool agnostic” for end users.

Beyond Compliance

Giving people control of security decisions builds a partnership that goes far beyond managing permissions.

Two dozen executives from all areas of the company - finance, sales, manufacturing, marketing, and even R&D - welcomed me into their offices every quarter to review the permissions. We’d usually spend the first ten minutes of that hour reviewing people and their permissions, identifying a few updates along the way. Then we’d spend the rest of the hour discussing upcoming plans for the data warehouse. It was a great time to ask them what new data they could use for their team’s decisions.

Often, those discussions turned into brainstorming new project ideas, using whiteboards to sketch out relationships between data sets, and thinking together about what new insight they might inspire.

Just saying that the “business owns the data” isn’t enough to convince people to trust you. If you invest in these administrative processes and system features, you show them that you really believe they own the data.


To remind you of this week’s data concept, enjoy Career Opportunities by The Clash from the Frictionless Data Spotify playlist.

For the full story about making data flow faster and better, check out Frictionless Data on Amazon.