BI access & data governance in Australia: Assign a business owner to each key dataset with clear use and audience rules; Apply row-level security and export controls in Power BI to protect sensitive data; Record all changes with triggers, approvals and impact analysis per APP 11 requirements
Image: Business Insight Stack

Data Governance

BI access and data governance

Set owners, access boundaries and review triggers for BI datasets, metrics and exports, with Australian privacy considerations.

BI governance starts with a practical question: who needs which information to make a decision, and who is accountable when access or the information changes? Give each important dataset a business owner, define its intended audience and use, and review how people can view, build from and export it.

Set the boundary around each dataset

An access decision needs more than a list of dashboard viewers. Record the dataset's purpose, the people or groups it describes, whether it contains personal or commercially sensitive detail, and the reports that depend on it. Distinguish viewing a report, creating a report from its model, changing the model and taking data out of the BI environment. A person may need one activity without needing all four.

For Australian entities covered by the Privacy Act, the Australian Privacy Principles address the use, disclosure and security of personal information. Coverage depends on the entity and activity; some small businesses are covered. Confirm the rules that apply to the dataset.

DecisionResponsibilityRecord to keep
Who may use the dataset?Business data ownerApproved purpose, audience and exceptions
Who implements access?BI or platform ownerGroups, roles and effective permissions
What does a measure mean?Metric ownerCurrent definition and change history
Who may take detail out?Data owner, with security or privacy input where neededExport approval, purpose and review trigger

Under the Privacy Act 1988, Australian Government agencies and organisations with an annual turnover of more than $3 million have responsibilities, subject to exceptions. Some small business operators are also covered. These include private sector health service providers, businesses that sell or purchase personal information, credit reporting bodies, contracted service providers for Australian Government contracts, and employee associations registered under the Fair Work (Registered Organisations) Act 2009.

An APP entity must have a clearly expressed and up-to-date privacy policy. The policy must cover the kinds of personal information it collects and holds, the purposes for which it collects, holds, uses and discloses it, how individuals may access and correct their information, and how complaints are handled. The policy must be available free of charge.

Privacy Act 1988 Coverage Thresholds (Australia)

Annual turnover threshold
$3 million
Covered entities include
Private health providers, credit reporting bodies, contracted service providers to Australian Government
Small businesses may be covered if
Involved in selling/purchasing personal information or registered employee associations

Control the data at the right layer

Dataset access decides whether someone can use a model. Row-level security limits which records an eligible user can see. A separate reporting dataset can omit personal fields that managers do not need. Export controls address copies made outside the reporting environment.

A dashboard filter alone does not establish a security boundary. In Power BI, row-level security applies to users with Viewer permissions, but not to workspace Admins, Members or Contributors. Power BI also has separate controls for summarised and underlying-data exports. These are product-specific examples; check effective access for each audience in your platform, including grants through groups, apps and shared models.

Choose one sensitive dataset and list its routes into reports, model access, workspaces, scheduled output and exports. Ask the owner which routes have a current purpose. Where individual records are needed for a legitimate task, approve that path separately from routine management reporting.

Power BI can export data from visualisations to Excel. When report data is exported to Excel, PowerPoint or PDF, sensitivity labels from Microsoft Purview Information Protection can carry protection settings that Power BI applies. Only authorised users can open the protected files.

Security and Power BI administrators can use Microsoft Defender for Cloud Apps to monitor access, perform real-time risk analysis, and set label-specific controls, such as preventing downloads to unmanaged devices.

Make changes traceable

Access, data and meaning change independently. A staff move can make an earlier grant inappropriate, a new field can make a reporting dataset more sensitive, and a changed metric formula can make a trend hard to compare. Give each change a review trigger and a decision maker.

For consequential changes, record what changed, why, when it took effect, which reports or audiences may be affected, who approved it and whether historical figures were recalculated. A dependency view can identify reports to investigate, but it cannot confirm that their figures remain correct.

Power BI's semantic model impact analysis shows the number of workspaces, reports and dashboards that might be affected by a change, plus the total views and unique visitors for those downstream items. That helps prioritise investigation: a change affecting a report with 20,000 unique viewers warrants more scrutiny than one with three viewers. The feature also provides a way to notify the relevant people.

Run a review people can finish

Review access when a person changes role, a dataset gains sensitive detail or a report reaches a new audience. For stable grants, choose an interval appropriate to the risk. Have owners confirm each grant against a current task, then check that the implemented permission matches the decision. Include model-building and export rights as well as report visibility.

A useful starting set of records is a dataset register, an audience and permission list, a metric change record and a route for exceptions. Apply it to one important reporting flow, then extend it where the records help owners make decisions.

APP 11 requires an APP entity to take reasonable steps to protect personal information it holds from misuse, interference and loss, and from unauthorised access, modification or disclosure. Reasonable steps include technical and organisational measures.

When personal information is no longer needed for any purpose permitted under the APPs, the entity must take reasonable steps to destroy it or ensure it is de-identified. This requirement does not apply if the information is part of a Commonwealth record, or if retention is required by or under an Australian law or a court or tribunal order.

In this guide

  1. Applying row-level access to sensitive business dataDefine and check row-level BI access using business entitlements, representative users and the right platform roles.
  2. Separating personal data from management reportingDesign management reports around useful measures while keeping identifying records in a separately controlled data path.
  3. Keeping a record of metric definition changesRecord metric versions, effective dates, history treatment and affected reports so changes in BI figures remain explainable.
  4. Reviewing who can export detailed datasetsReview detailed BI exports by purpose, permission route and effective access, then verify revoked or expired grants.

More from Data Governance

Data Governance

Data quality checks

Data quality checks turn a vague concern about “bad data” into a small set of assertions that a reporting team can run and act on.