Back to Help Center
Guide

Governance and security

This guide sets out practical principles of governance and security in Centriu: who accesses what, how to protect sensitive data, how to record responsibilities, and how to review access over time.

Basic governance principles in Centriu

A single source of truth

For the monitored indicators, Centriu should be treated as the official source.

Least privilege access

Each person sees only what they need to do their job well.

Clear owners

There should always be an owner for each module, dashboard, or critical metric.

Continuous review

Governance is not a project; it is a process (monthly and quarterly reviews).

Role and permission structure (example)

Adapt to the actual roles in Centriu:

Global Admin

  • Manages users, permissions, integrations, and general settings.
  • Full access; should be restricted to a few people.

Area Admin / Manager

  • Configures dashboards, targets, and alerts for their area.
  • Does not touch global integrations or security.

Operator

  • Uses operational screens (support, tickets, records).
  • Limited access to the necessary data.

Viewer

  • Only reads dashboards and reports.
  • Ideal for executives and the board.

Rule of thumb

If you wouldn't trust someone to press a button that deletes everything, that person should not be a Global Admin.

Handling sensitive data

1. Classify the data

  • Internal public: any employee can view it (e.g., total number of customers).
  • Restricted: only a few areas (e.g., values per customer).
  • Confidential: highly controlled access (e.g., sensitive personal data).

2. Protect what is restricted/confidential

  • Limit access by roles and groups.
  • Avoid exposing sensitive data in broadly shared dashboards.
  • Use anonymization or aggregation when needed (ranges, totals).
  • Record in an internal document which fields are sensitive and who can view them.

Operational security

Login best practices

  • Always use a corporate email address.
  • Enable two-factor authentication (when available).
  • Avoid generic accounts without a clear owner.

Sessions and devices

  • Close sessions of inactive users whenever possible.
  • In more critical scenarios, restrict access via VPN or corporate IP (if the product allows it).

Access review cycle

Implement a simple cycle:

  • Monthly: review the user list, adjust roles, and reduce unnecessary access.
  • When employees leave: revoke access immediately and transfer ownership of dashboards and integrations.
  • When creating new squads/projects: define which data will be used, which roles will have access, and whether there is any sensitive data.

Record of responsibilities

Create a simple record (a document or a governance tab in Centriu) with:

  • Owner of each critical metric.
  • Owner of each important dashboard.
  • Owner of the main integrations.

This reduces the chance of a “no man's land” when something breaks.

Incidents and response

Define a basic flow:

  • How to report data issues (a wrong dashboard, an odd number).
  • Whom to report to (channel and owners).
  • Criticality (low, medium, high).
  • How to record root cause and corrective action.

Even without a dedicated module, use a dedicated channel (e.g., “Centriu – incidents”).

Active governance and security checklist

  • There are at least 2 global admins (and no more than 5).
  • Each module has a clear owner.
  • Sensitive data has been mapped and protected.
  • The user list has been reviewed within the last 30 days.
  • There is a clear flow for onboarding and offboarding employees.
  • There is an official channel for data questions and incidents.

Next steps