About governance workflows

Governance workflows let you set up automated controls and approval mechanisms for organizational data resources. With such workflows, you can ensure that access to your data products is managed by authorized individuals or teams.

Using governance workflows for managing access requests has the following benefits:

  • Data consumers can find relevant data products and request access directly within Knowledge Catalog, replacing manual support ticketing processes.
  • Upon request approval, the system automatically grants the required IAM roles and group memberships, eliminating manual administrative overhead and reducing time-to-access.
  • System logs capture complete audit trails of all requests, justifications, approver decisions, and timestamps to simplify regulatory compliance auditing.
  • Centralized approval mechanisms for sensitive data assets ensure access is restricted to authorized users and teams.

Use cases

Governance workflows support automated access management across various industry scenarios:

  • Retail and e-commerce: A marketing manager requests access to a regional sales data product (for example, a curated theLook eCommerce dataset) to analyze customer behavior and build a targeted ad campaign. Upon approval, the required IAM roles are automatically provisioned.
  • Healthcare: A clinical research analyst requests access to a de-identified patient outcomes data product (for example, a curated anonymized patient records dataset) to evaluate treatment efficacy across patient demographics. Upon approval, the required IAM roles are automatically provisioned.
  • Finance: A risk analyst requests access to a transaction history data product (for example, an aggregated credit activity and fraud monitoring dataset) to build predictive risk models and ensure compliance auditing. Upon approval, the required IAM roles are automatically provisioned.

In each use case, the system provides the required IAM roles when the approver accepts the request.

Use governance workflows in Knowledge Catalog

You can use governance workflows to request access to data products and suggest changes to business glossaries and Knowledge Catalog entries.

For more information on how to request access to data products, see request access to data products.

Governance workflows processing path

Knowledge Catalog tracks requests throughout their lifecycle using workflow status values (NEW, APPROVED, REJECTED, DELETED).

The following table lists the steps in the request processing path, their corresponding status values, and descriptions:

Step Status Description
Request creation NEW A requester submits a new request (for example, to access a data product). The system logs the request and assigns it the NEW status.
Review NEW The request remains in NEW status while awaiting evaluation by an authorized approver.
Approver decision APPROVED or REJECTED The approver evaluates the request and decides to approve or reject it:
  • Request approved: The system automatically provisions the requested access or applies the metadata changes, and notifies the requester by email.
  • Request rejected: The status updates to REJECTED. The requester receives an email with the decision justification.
Expiration or deletion DELETED A request transitions to DELETED in the following scenarios:
  • The request remains unaddressed in NEW status for the 90-day time to live (TTL) period.
  • The target resource associated with a pending request is deleted.
  • A requester or workflow administrator manually deletes the request.

Governance workflows roles

Governance workflows roles include requesters, approvers, and workflow administrators. The following table describes the roles in detail:

Role Description
Requester A requester creates and submits requests.
Approver An approver approves or rejects requests.
Workflow administrator Ensures compliance, configures workflow policies, and maintains the request backlog. Administrators can view audit trails across all request states and have administrative deletion permissions to remove requests in any state.

Limitations

What's next