Governance & approvalsGENEDATA / 01

Move with confidence.Govern with clarity.

Connect policies to the data and decisions they protect. Bring access, approvals, and evidence into the work itself.

Shared context · Lineage · Governance
Connected
Your sources
Identity & roles
Classification
Business policies
Connected intelligencePolicy engine
Governance
Business impactAccess & evidence
Shared contextLineageGovernance
+Illustrative workflow01 / 03
1 / 3
01

Attribute-Based Access

Define who can see what using user attributes, data tags, and contextual policies — far more expressive than role tables alone.

02

Continuous Compliance

Real-time evidence collection for SOC 2, ISO 27001, HIPAA, and GDPR — auditors get a live dashboard, not a quarterly fire drill.

03

Universal Enforcement

The same policy is enforced at warehouse, BI, AI, and API layers. No bypass paths, no shadow data, no gaps to apologize for later.

Enforcement Model

Every request passes the same four gates.

Policy is evaluated in the control plane, in the request path, for every access route into the data — SQL, BI, API, notebook, or AI agent. There is no side door that skips a layer, which is what makes the audit record complete rather than merely extensive.

Governed datasingle copyIdentityWho is asking, and on whose behalfPolicy decisionAttributes and tags evaluated per requestRow + column filteringResults narrowed before they are returnedAuditDecision and outcome recorded immutably
How It Works

Author, tag, enforce, evidence.

Policies are written against attributes and data tags rather than enumerated table grants, so they keep applying as new datasets arrive.

  1. Author the policy

    Express rules in terms of user attributes, data classifications, and context — purpose, region, time — rather than static role tables.

  2. Tag the data

    Classification from the catalog supplies the tags policies match against, so a newly landed PII column is covered on arrival.

  3. Enforce in the request path

    Decisions are evaluated inline at every access route, filtering rows and masking columns before results leave the engine.

  4. Produce the evidence

    Every decision is recorded with its inputs, so control effectiveness is a query rather than a sampling exercise.

Capabilities

Controls that hold up under audit.

The difference between a policy and a control is whether you can prove it was applied to every request, not most of them.

Attribute-based access control

Combine user attributes, data tags, and request context into policies far more expressive than role membership alone.

Dynamic masking

Sensitive columns are masked, tokenised, or redacted per requester, with the unmasked value never leaving the engine.

Row-level security

The same query returns different rows to different users, enforced in the planner rather than in application code.

Access request workflow

Time-bound, approved elevation with automatic expiry — no permanent grants issued for a one-week project.

Framework mapping

Platform controls mapped to SOC 2, ISO 27001, HIPAA, and GDPR requirements, with evidence attached per control.

Policy version history

Every policy change is versioned and attributable, so you can show what rule was in force on any past date.

In Practice

Who this is for.

Governance succeeds when it makes the compliant path the easy one.

Compliance / Legal

Replace the quarterly evidence scramble

Pull control evidence continuously from the platform's own decision log rather than assembling screenshots before each audit.

Evidence that is current by definition.

Data Owner

Grant access without granting everything

Approve time-bound, attribute-scoped access to exactly the rows and columns a request needs, with automatic expiry.

Least privilege that survives contact with deadlines.

Data Analyst

Work without waiting on approvals

Query governed datasets directly — policy narrows results automatically instead of blocking access until a ticket clears.

Self-service inside the compliance boundary.

What Changes

What changes when policy lives in the control plane.

Policy re-implemented per tool is policy that will eventually disagree with itself.

DimensionBefore GenedataWith Genedata
DefinitionRules duplicated in warehouse, BI, and application codeAuthored once, evaluated centrally
New datasetsUncovered until someone remembers to grantCovered on arrival via classification tags
Bypass pathsDirect warehouse access skips BI-layer rulesEvery access route passes the same gates
Audit evidenceSampled screenshots assembled before an auditA continuous, queryable decision record
Elevated accessPermanent grants nobody revisitsTime-bound elevation that expires automatically
SOC 2 controls mappedFrameworks
ABAC + RBACPolicy Engine
7 yearsAudit Retention
Before rows are readEnforcement Point
The next step

Compliance as code. Audit as evidence.

Stop reconciling spreadsheets at quarter-end. Genedata Governance turns your control framework into executable policy — and gives auditors a live, queryable record of every decision the platform has ever made.

FAQ

GeneCatalog, answered.

What compliance, security, and data owners ask before adopting a policy engine.

What is GeneCatalog?

GeneCatalog is the governance member of the GeneFlow family. Policy, classification, lineage, and audit live in the control plane and are enforced in the request path — so a rule written once applies to SQL, BI, API, notebook, and AI-agent access alike.

Why attribute-based access rather than roles?

Role tables enumerate grants, which means every new dataset is uncovered until someone remembers to grant on it. Attribute-based policies match user attributes against data classifications, so a newly landed PII column is covered the moment it is classified — no grant required.

Are there bypass paths?

No. Direct warehouse access, BI, notebooks, and agents all pass the same four gates: identity, policy decision, row and column filtering, then audit. That is what makes the audit record complete rather than merely extensive.

What does audit evidence actually look like?

Every policy decision is recorded with the inputs that produced it, retained for the audit window. Control effectiveness becomes a query over that record instead of a sampling exercise assembled before each assessment.

How do temporary access needs work?

Access requests route through approval and grant time-bound, attribute-scoped elevation that expires automatically. Nobody ends up with a permanent grant issued for a one-week project.

Which frameworks are mapped?

Platform controls are mapped to SOC 2, ISO 27001, HIPAA, and GDPR requirements with evidence attached per control. Adding a framework is a mapping exercise against the same decision record rather than a new evidence pipeline.

Take the next step

See policy enforced end to end.

Watch one policy apply across SQL, BI, and an AI agent in a single session — or start with the control mapping pack.