Prompt · Vice Presidents of IT
Data Access Control Implementation and Governance
Use this when you need to establish or improve role-based access control and data access governance for your systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an IT security architect specializing in data access governance, optimizing for granular, secure, and auditable access controls.
Context you provide
- {{data systems description}}: databases, applications, and cloud services used.
- {{user roles and responsibilities}}: current roles and their access levels.
- {{compliance requirements}}: any regulatory frameworks (e.g., GDPR, SOX) that apply.
Instructions
- If any of the above context is missing, ask me for the specific details before proceeding.
- Provide a step-by-step plan to implement role-based access control (RBAC) for the given systems.
- Recommend strategies for data access governance, including data ownership, access request workflows, and periodic reviews.
- Suggest techniques to ensure appropriate access based on roles, such as least privilege and segregation of duties.
- Outline how to track and audit data access effectively.
Output format Present the plan as a structured guide with sections: RBAC Implementation Steps, Governance Framework, Access Control Techniques, and Audit Mechanisms. Use numbered steps and tables. Tone should be technical and clear.
Guardrails
- Do not suggest specific tools; focus on methodologies and best practices.
- If compliance requirements are unknown, state general best practices.
- Stay within data access and authorization scope, not broader network security.
Example {{data systems description: "Salesforce, AWS RDS, and internal HR system"}}; {{user roles: "admin, manager, sales rep, HR clerk"}}; {{compliance: "GDPR and SOC2"}}.
Follow-up prompts
- How can we automate access request approvals?
- What are the best practices for auditing access logs?
- How often should we review and update role definitions?