Governing Access
Esta página aún no está disponible en español. Se muestra la versión en inglés.
Data mesh is a set of ideas for running data in a bigger organization. The people closest to the data own it, datasets are treated as products, teams serve themselves, and the platform carries the rules instead of a committee. You don’t have to reorganize around those ideas to use them. This page shows where each one lives in Querri, and where control stays with admins.
Ownership sits with whoever brings the data in
Section titled “Ownership sits with whoever brings the data in”Whoever connects a source owns that connector. Owners decide who else can use it on the connector’s Sharing tab, and only owners can set its sync Schedule. On plans without connector sharing, that tab shows Pro Feature instead.
Files you upload land in the workspace you’re working in. If you can’t add to that workspace, they’re saved to Private, and a message tells you so. Projects work the same way as connectors: the owner decides who else gets in.
Work others can use
Section titled “Work others can use”When a project or dashboard answers something well, other people can use it too. Share it with named people as viewers or editors, publish a public link, or keep it in a workspace the whole team can see. Scripts and other tools reach data through API keys, which admins create.
See Sharing for each share dialog.
Teams serve themselves
Section titled “Teams serve themselves”People who can add to a workspace can upload a file or connect a source from Add data, then ask questions and build projects and dashboards. Nobody has to file a request first.
Oversight stays with admins
Section titled “Oversight stays with admins”This is the part that isn’t federated. Most rules are set centrally, by organization admins:
- They give everyone an organization role, Admin, Creator or Guest, in People.
- They create workspaces and choose each one’s members and roles.
- They create access policies, which filter rows for each person, and assign people to them. A team can’t set up its own policies.
- They create and revoke API keys.
- They read the Security audit log, which records policy, API key and permission changes, and activity from API keys.
Workspace admins get a smaller share of control. They manage their own workspace and its members, and they can delete or share anything saved in it.
Where each idea lives
Section titled “Where each idea lives”| Idea | In Querri |
|---|---|
| The people closest to the data own it | Connector and project owners, and a workspace per team |
| Data as a product | Sharing, public links and API keys |
| Self-serve | Add data, chat, projects and dashboards |
| Rules carried by the platform | Organization and workspace roles, access policies and audit logs, all set by admins |
Next steps
Section titled “Next steps”- Security & Governance: the layers, and the defaults to check
- Workspaces: roles and membership
- Access Policies: row-level security in practice
- Sharing: share dialogs and public links