Classify data by risk

Public, internal, confidential and highly sensitive data need different rules. Classification should make sense to owners and users, not security specialists alone.

Control should match the consequences of leakage or error.

Grant access by role and purpose

Standard roles receive standard permissions; exceptions need an owner, justification and expiry.

  • Least privilege
  • Regular review
  • Automatic exception expiry
  • Usage logging

Prepare controls for analytics and AI

Combined data may become more sensitive than individual sources. Access to a model or agent must also respect permissions on its context.

Security designed with the data accelerates delivery instead of blocking it at the end.