Access requests
Request access to a restricted dataset or project, approve requests, and audit the trail.
When someone needs data they cannot reach, they request it rather than being told to ask around. Requests are approved in-product and recorded permanently in the activity feed.
Request access
Restricted datasets appear in search and in the catalogue with a lock, but their contents stay hidden. Click Request access and supply:
| Field | Why it matters |
|---|---|
| What | The dataset or project |
| Which project | Where it will be used — approval is scoped to it |
| Reason | Free text; shown to the approver and kept in the audit trail |
| Duration | Permanent, or time-boxed to 7 / 30 / 90 days |
Time-box by default
A 30-day grant for a one-off analysis avoids the slow accumulation of access nobody remembers granting. Expiry is automatic and the requester is warned three days ahead.
Approve or decline
Approvers are team Admins plus the dataset’s designated owner. Requests arrive by email and in Needs attention on the catalogue overview.
Each request shows the requester, their existing access, the target project and its member count, and the stated reason.
Check who else gains access
Approving grants the project, not the person. If the project has 12 members, all 12 can read the dataset. The dialog states this plainly.
Decide the scope
Approve as requested, reduce the duration, or grant a narrower alternative — a filtered view of the dataset rather than the whole thing.
Approve or decline with a note
The note is delivered to the requester and stored with the decision.
Approval grants project-wide access
This is the most common permission mistake. If only one person should see a dataset, put it in a project only they belong to.
Time-boxed grants
| State | Meaning |
|---|---|
Active |
In force |
Expiring |
Fewer than 3 days remain; requester notified |
Expired |
Revoked automatically; charts show a permission marker |
Revoked |
Ended early by an admin |
Renewal is a fresh request — expiry deliberately does not auto-renew.
The audit trail
Every request, approval, decline, expiry, and revocation is written to the activity feed with actor, target, reason, and timestamp:
Edgars approved access to CRM Contacts 28 mins ago
→ project: Auto dīleriem POC
→ reason: "dealer campaign attribution"
→ expires: 11 Sep 2026
Filter by object type or actor from View all, and export the filtered log to CSV from the same screen.
The audit log is append-only
Entries cannot be edited or deleted, including by Owners. Retention is 12 months on Pro and unlimited on Enterprise.
Review access periodically
Settings → Access review lists every standing grant, sorted by age, showing who approved it and when it was last used. Grants unused for 90 days are flagged.
Revoking from this screen takes effect immediately and notifies everyone affected.