Zero-Copy Sharing
Recipients query your data live, in place. No data movement, no replicas, no integrity drift — and revoke access at the click of a button.
Make data available across teams and organizational boundaries with permissions and lineage that travel with it.
Recipients query your data live, in place. No data movement, no replicas, no integrity drift — and revoke access at the click of a button.
Publish datasets, AI models, and dashboards to your private marketplace with managed approval workflows and consumption metering.
When a consumer transforms shared data, lineage stays connected — auditors see the full path from source to derived asset.
A share is a governed view over data that never leaves your tenancy. Recipients query it live, each seeing only the rows and columns their agreement permits — and when a partner transforms what they receive, the lineage stays connected across the boundary.
A share is a contract with an expiry rather than a file handed over, which is why revoking it actually takes effect.
Choose the rows, columns, and masking that a given recipient receives. The underlying table is never duplicated.
Route through an approval workflow with an expiry date, usage terms, and optional consumption metering attached.
Recipients query current data in place. There is no extract to go stale and no pipeline to keep synchronised.
Withdrawal takes effect on the next query, because there was never a copy sitting on someone else's storage.
Emailing an extract is easy. Proving two years later exactly who saw what is the hard part.
Recipients read the live table through a governed view. No replicas exist to drift, leak, or outlive the agreement.
The same share returns different rows and masked columns per recipient, enforced in the engine rather than by agreement.
Publish datasets, models, and dashboards for discovery, with request-and-approve workflows and consumption metering.
Derived assets built by a consumer remain linked to their source, so impact analysis crosses the organisational boundary.
Every read against a share is recorded with identity, time, and the exact rows returned, retained for the audit window.
Shares carry an end date. Continuing access requires a renewal decision rather than nobody remembering to revoke.
Most data leaves organisations as a spreadsheet attachment. This is the alternative.
Give a partner a scoped, live view of exactly the data your agreement covers, with an expiry that matches the contract term.
No files in transit, no copies to chase later.
Every read against every share is recorded per query, so a retrospective access question is answered from the log.
Disclosure history reconstructible on demand.
Replace bespoke extract jobs for each downstream team with governed shares over the one governed copy.
Fewer pipelines, and none that can go stale.
Every extract you send is a copy you no longer control and cannot recall.
| Dimension | Before Genedata | With Genedata |
|---|---|---|
| Delivery | Scheduled extracts pushed to each recipient | Live queries against one governed copy |
| Freshness | As current as the last successful export | Current as of the query |
| Revocation | A request to please delete the file | Effective on the next query, in under a second |
| Scoping | A separate extract built per recipient | One share, filtered and masked per recipient |
| Audit | A record that a file was sent | Per-query record of exactly what was read |
Genedata Sharing turns your platform into a controlled distribution channel. Every consumer sees fresh, governed data — and you keep a complete audit of who accessed what, when, and why.
What data owners and compliance teams ask before opening a boundary.
Recipients query the live table through a governed view rather than receiving an extract. No replica exists to drift, leak, or outlive the agreement — which is also why revocation actually takes effect.
It takes effect on the recipient's next query, in under a second, because there was never a copy sitting on someone else's storage to chase down.
Yes. One share returns different rows and masked columns per recipient, enforced in the engine rather than by contractual agreement and good intentions.
Lineage stays connected across the boundary, so a derived asset built by a consumer still traces back to its source. Impact analysis crosses organisational lines rather than stopping at them.
Every read against every share is recorded with identity, time, and the exact rows returned, retained for the audit window — so a retrospective question about who saw what is answered from the log.
By default, yes. A share carries an end date, so continued access requires a renewal decision rather than depending on someone remembering to revoke it.
Identity federation, scoping, and the share contract model.
GuidePublishing, approval workflows, and consumption metering.
GuideKeeping provenance intact when a partner derives new assets.
RelatedThe policy layer every share is scoped and audited against.
Set up a scoped, expiring share against live data in a working session — or read the protocol specification first.