Skip to main content
Self-ServeOpen the app

Data platform self-service, governed

Data platform access, without the ticket queue

Self-Serve turns access requests into governed, automated provisioning. Your teams ask, approvers click, and Snowflake, dbt Cloud, and the rest of your stack are configured automatically — with every step on the audit trail.

Provisions and governs the tools your teams already use

Snowflakedbt CloudSigmaCollateAstronomer AirflowAWS MarketplaceMicrosoft Entra ID
0
tickets raised

Access is requested, approved, and provisioned in-product.

100%
of actions audited

Every request, approval, and grant lands on the trail.

5+
services out of the box

Snowflake, dbt Cloud, Sigma, Collate, Astronomer.

6
built-in roles

From admin to user, with delegated approvals between.

The platform

One front door to your entire data stack

Stop brokering access by hand. Self-Serve puts requesting, approving, provisioning, and paying for your data platform in one governed product.

  • Self-service provisioning

    Teams request access to Snowflake, dbt Cloud, Sigma, and more. A workflow engine executes the provisioning automatically — users, roles, grants, licences — the moment it's approved.

  • Governed by design

    Role-based access control, named or role-based approvers, delegation, and a complete audit trail. Governance isn't bolted on afterwards — it's the path every request takes.

  • Cost under control

    Budgets per business area, workload and warehouse monitoring, configurable thresholds, and alerts the moment spend drifts. FinOps signal without the spreadsheet archaeology.

Governance

Approvals that move fast — and leave a trail

Every request routes to the right people automatically: named approvers or role-based rules, with delegation for when they're away and auto-approval where you decide it's safe.

  • Six built-in roles, enforced server-side on every single call
  • Delegated approvals and auto-approval rules you control
  • A complete, attributed audit history on every entity

FinOps

Know what your platform costs — before the invoice does

Budgets per business area, monitoring for expensive and untagged workloads, warehouse-configuration checks, and per-user alert thresholds. When spend drifts, the right people hear about it immediately — not at month end.

  • Budgets and alerts per business area, not one blunt total
  • Large and untagged Snowflake workloads surfaced automatically
  • Configurable thresholds per user and per role

And the rest

A whole platform team, in product form

The unglamorous work that keeps a data platform running — built in, so nobody has to build it around you.

  • Bring your own data

    Upload CSV or Excel and land it in Snowflake — schema inferred, validated, and governed.

  • Reference data management

    Steward-authored datasets in from CSV, a table, or a URL — out to Snowflake, Postgres, SQL Server, or S3.

  • Licence management

    A per-organisation licence catalogue for dbt Cloud, Collate, Sigma, and anything else you licence out.

  • Support ticketing

    Built-in tickets with assignment, tracking, and resolution — platform support without leaving the platform.

  • Notifications that land

    In-app and email notifications for approvals, alerts, and request progress — with delivery tracking.

  • User lifecycle

    Invite with email verification, change roles and business areas, and remove with a clean cascade — start to finish.

How it works

From "can I get access?" to access. Automatically.

  1. 1

    Request

    A user picks a service, workspace, and role — a guided form, not a free-text ticket.

  2. 2

    Approve

    Named approvers or role-based rules decide, with delegates and auto-approval where you allow it.

  3. 3

    Provision

    The workflow engine executes every task — users, grants, warehouses, licences — automatically.

  4. 4

    Audit

    Each step is recorded as it happens. The full history of every request, forever answerable.

Security

Built like the control plane it is

  • Single sign-on

    Microsoft Entra ID (OIDC) sign-in, mapped to your organisation's claimed email domains.

  • Role-based access control

    Six roles enforced on every function call, server-side — the UI never decides who may act.

  • Tenant isolation

    Every record is scoped to your organisation, enforced at runtime, type, and lint layers.

  • Complete audit trail

    Every request, approval, grant, and change is attributed and timestamped.

Ready to retire the ticket queue?

Give every team the data platform — and keep every control you care about.