Who may receive each data domain and the control that releases it Phase C fixes dissemination and security with the data itself: every data domain names the audience it may reach and the release control that governs it, so access rules are settled inside the architecture rather than retrofitted afterwards at far greater cost.
Who may receive each data domain and the control that releases it
A five-row matrix of data domains against dissemination and control, under three headers: data domain, who may receive it, and release control. Each row names a domain, the audience it may reach, and the release control in an accent-tinted cell that carries the emphasis. Customer data reaches service and support teams under consent and least privilege; product data reaches most internal teams under read-only publication; operational data reaches operations and analytics under role-based access; financial data reaches finance and audit only under strict access and logging; reference data is shared across the enterprise under a governed master copy.
The release control decides who each domain reaches
Customer Service and support teams Consent and least privilege
Product Most internal teams Read-only publication
Operational Operations and analytics Role-based access
Financial Finance and audit only Strict access and logging
Reference Shared across the enterprise Governed master copy