Governance and Controls

Everyone can ask. Not everyone sees the same answer

Roles, departments, per-person permissions, sharing inside and outside the organisation, identity, usage and spend — set in one place, enforced everywhere, and every change to them written down with who made it.

Structure

The org chart is the access model

Departments nest as deep as your organisation actually does, and a person is assigned to one. Everything else — what they can open, who they can share with, which sources they reach — is read from where they sit.

Counts roll up, because the question an owner asks is about the branch and not the row: how many people sit under Operations, how many of them are admins, how many departments a grant would reach. A department admin holds the subtree, and never the branch beside it.

Any depthSubtree countsAdmins per branchMove without re-granting
ORGYour organisation7 departments · 126 people
Scope of Operations
58People in the subtree3Departments it covers4Admins who can grant

Roles

Three roles, and four rights under each

Owner, Admin, Member. A permission is not one switch but four — create, read, update, delete — held per capability, which is how an admin can invite people and edit the widgets in their scope without being able to delete the accounts underneath them.

The owner governs the organisation: billing, departments, and the controls on this page. An admin runs a branch of it. A member works inside the scope their department allows — and nothing on the grid is implied, it is set.

Per person

Then, narrower still

Under the role sits the individual grant: which surfaces this person sees at all — set one by one, and one of them not the owner's to hand out at all.

Widget accessNewsfeedDashboardPortfolio performanceDashboardPortfolio chartsDashboardPortfolio builderPortfolioChart builderPortfolioStatistical analysisPortfolioReports tabDataClient managementDashboardComplianceOwner only
Marketplace — create access

Who may bring new material in

Using a source and adding one are different rights. Only the owner grants the second, and only an admin who has been trusted with it can pass any of it down to their own sub-departments.

Data sourcesWarehouses, lakes, buckets and drivesAugmentation sourcesWhat enriches a source once it is inNews sourcesFeeds the whole organisation then seesFoundation modelsWhich models are available at all
Delegation

An admin can be given the pen

Sub-department permission management is its own switch: with it, a department admin grants inside their branch without coming back to the owner. Without it, every grant stops at the top.

Sharing

Across the corridor, or out of the building

Collaboration between departments is a setting, not an assumption — allowed or restricted per person, and narrowed further by a whitelist of the departments they may share into.

Sharing outside is a separate grant again. What leaves does so as a link with an expiry, addressed to a named recipient, carrying one widget or one report — and the person on the other end becomes an external user with permissions of their own, not a hole in the wall.

Per-person settingDepartment whitelistExpiring linksNamed recipient

External users

A guest is a person with permissions, not an exception

Anyone you share with outside the organisation gets a profile: who added them, from which department, with custom fields your organisation defines. What they can do inside the thing they were sent is set switch by switch.

Table AIViewExportEdit cellsManage sheetsCreate charts
Statistical AIViewExportEdit cellsCreate charts
Chart AIViewExportCreate charts
Document AIViewExportManage sectionsTemplate editor
ChatEnabledChosen models onlyFile attachments
MessagingEnabledFile sharing
Suspend

Access ends with one switch

Suspension is recorded with who did it and when, and can be lifted the same way. The share history stays; the access does not.

Their own fields

Ask what you need to know

Define the fields every external user must carry — entity, mandate, jurisdiction — and the answers travel with the profile.

Their own models

Chat, but only with what you allow

An external user's chat can be turned on with a named list of models and attachments left off — the same assistant, a narrower door.

Identity

Who is asking is part of the control

Permissions only mean something if the account is the person. Two-factor, recovery codes, devices and sessions sit under the same settings as everything else here.

Two-factor

A code every sign-in

Time-based codes from any authenticator app, with the date it was turned on.

Recovery

Single-use codes, counted

Each usable once, with a warning when the set runs low and a way to regenerate.

Devices

More than one, deliberately

Register a second device from inside the account rather than around it.

Reset

Admins can help — on the record

An admin can clear a locked-out member's two-factor, and the reset is written to the audit log with their name and address.

Usage and spend

Every request, attributable

Requests, input and output tokens and cost are recorded per model, per provider and per person — with your own unit cost per thousand tokens, so the estimate is the one your finance team recognises. Export it whenever you need to.

Estimated $0 this month
Claude Sonnet 4.6Anthropic48,210612.4M$4,820
GPT-5.6 TerraOpenAI31,905388.1M$3,104
Gemini 3.1 ProGoogle22,640265.7M$1,993
Claude Haiku 4.5Anthropic40,118151.2M$604
Gemini 2.5 Flash LiteGoogle26,77488.6M$212

The record

And who changed the rule

A control nobody can audit is a promise. Sensitive administrative actions are written down as they happen — the admin, the person affected, the address it came from and the time.

It sits beside the other record: what the agents did, kept by Compliance AI. One follows the work, the other follows the people who set the rules for it.

Admin audit logTwo-factor reset for a memberR. Alvarez · Owner · 10.4.2.1909:41Research removed from the whitelistR. Alvarez · Owner · 10.4.2.1909:12External user suspendedM. Okafor · Admin · 10.4.7.83YesterdayCreate access granted on a data sourceR. Alvarez · Owner · 10.4.2.19YesterdayModel review created under RiskM. Okafor · Admin · 10.4.7.83Mon
Residency

Where the data sits is yours to name

The organisation records its own storage location, and the deployment follows it.

Tenancy

Your accounts, your keys

Every source is reached through credentials you hold, in the tenancy you run.

Status

Pending, active, suspended

A seat has a state, and an invitation that was never accepted is not an account.

Turn weeks of expert work into minutes

See how Scalata fits your team, your data, and your controls.

Contact Sales