Access requests

Request access to a restricted dataset or project, approve requests, and audit the trail.

When someone needs data they cannot reach, they request it rather than being told to ask around. Requests are approved in-product and recorded permanently in the activity feed.

Request access

Restricted datasets appear in search and in the catalogue with a lock, but their contents stay hidden. Click Request access and supply:

Field Why it matters
What The dataset or project
Which project Where it will be used — approval is scoped to it
Reason Free text; shown to the approver and kept in the audit trail
Duration Permanent, or time-boxed to 7 / 30 / 90 days

Time-box by default

A 30-day grant for a one-off analysis avoids the slow accumulation of access nobody remembers granting. Expiry is automatic and the requester is warned three days ahead.

Approve or decline

Approvers are team Admins plus the dataset’s designated owner. Requests arrive by email and in Needs attention on the catalogue overview.

Each request shows the requester, their existing access, the target project and its member count, and the stated reason.

Check who else gains access

Approving grants the project, not the person. If the project has 12 members, all 12 can read the dataset. The dialog states this plainly.

Decide the scope

Approve as requested, reduce the duration, or grant a narrower alternative — a filtered view of the dataset rather than the whole thing.

Approve or decline with a note

The note is delivered to the requester and stored with the decision.

Approval grants project-wide access

This is the most common permission mistake. If only one person should see a dataset, put it in a project only they belong to.

Time-boxed grants

State Meaning
Active In force
Expiring Fewer than 3 days remain; requester notified
Expired Revoked automatically; charts show a permission marker
Revoked Ended early by an admin

Renewal is a fresh request — expiry deliberately does not auto-renew.

The audit trail

Every request, approval, decline, expiry, and revocation is written to the activity feed with actor, target, reason, and timestamp:

Text
Edgars approved access to CRM Contacts        28 mins ago
  → project: Auto dīleriem POC
  → reason: "dealer campaign attribution"
  → expires: 11 Sep 2026

Filter by object type or actor from View all, and export the filtered log to CSV from the same screen.

The audit log is append-only

Entries cannot be edited or deleted, including by Owners. Retention is 12 months on Pro and unlimited on Enterprise.

Review access periodically

Settings → Access review lists every standing grant, sorted by age, showing who approved it and when it was last used. Grants unused for 90 days are flagged.

Revoking from this screen takes effect immediately and notifies everyone affected.