Kindly fill up the following to try out our sandbox experience. We will get back to you at the earliest.
Data Governance for the Modern Data Stack: 4 Breaking Points
Governance breaks in four places once data spans a warehouse, dbt, BI and AI agents: ownership, policy reach, lineage gaps and uncataloged tables.

Key Takeaways
- Governance in a modern data stack is a coordination problem. The rules are not the hard part. Holding the same answer about a table in a warehouse, a lakehouse, a transformation project, a BI tool and now an agent is the hard part.
- It breaks in exactly four places. Ownership that every tool records differently, policy that cannot follow the data out of the tool that set it, lineage that stops at each tool boundary, and agents reading tables nobody cataloged.
- The centralized model does not transfer. A single database had a single place to set a rule, and the rule was a property of the database. Separating storage from compute removed that place and nothing replaced it.
- The limits are documented, not theoretical. dbt does not push column descriptions to the warehouse unless you turn it on, and never for sources. Databricks does not preserve lineage across a rename. Power BI does not guarantee lineage when a connection was hand written.
- Retention is the number most teams get wrong. Snowflake ACCESS_HISTORY covers the last 365 days on Enterprise Edition. If your auditor asks for two years of column access, the warehouse alone cannot answer.
- What holds it together sits above every tool. A governance layer with read access into each system, holding the owner record, the classification, the assembled lineage graph and the access record in one place.
Data governance in a modern data stack is the practice of holding a single answer to four questions about a table when that table is touched by five or six separate systems: who owns it, what class of data is in it, where it came from, and who read it. The questions are the same ones a bank asked of a mainframe in 1995. What changed is that no system in the stack can answer any of them on its own.
This page is about that gap, not about governance in general. If you need the definition, the pillars and why governance matters at all, what data governance is and the pillars it rests on covers it. What follows assumes you already run a modern stack and want to know where it leaks.
What a modern data stack actually looks like now
A modern data stack is usually five layers. Ingestion moves records in. A cloud warehouse or lakehouse holds them and runs the compute. A transformation layer, most often dbt, turns raw tables into modelled ones. A BI layer serves dashboards and extracts. Since 2025 there is a fifth layer that did not exist when most governance programs were designed: agents and assistants that query the same tables through an API rather than through a dashboard.
Every one of those layers keeps its own metadata. The warehouse knows the object owner. The transformation project knows the model owner written in a YAML file. The BI tool knows a workspace role. The catalog knows a data steward. None of them is wrong, and none of them is authoritative.
Why the centralized governance model does not transfer
The centralized model worked because governance was a property of the database. There was a single engine, a single administrator and a single GRANT statement, so a rule set once applied everywhere the data could be read. Three changes in the modern stack take that away.
- Storage separated from compute. The same files are read by several engines, and a permission granted in one engine says nothing about the others.
- The record of truth became ambiguous. A column description can live in the warehouse comment, the dbt YAML, the BI semantic model and the catalog at the same time, with four different values.
- The rate of change went up. A transformation project ships new models daily. A governance forum meets monthly. Any process that depends on a human approving each new asset falls behind in the first week.
| Governance concern | Single database era | Modern data stack |
|---|---|---|
| Where a rule is set | Once, in the database | Separately in each tool that touches the data |
| Who owns an asset | The schema owner | Four owner fields that do not agree |
| How lineage is known | Read from the one engine | Assembled from every layer, with gaps |
| Who read a column | The database audit log | Several logs with different retention windows |
| Speed of change | Release cycles | Daily model deploys and ad hoc agent queries |
The 4 places governance breaks in a modern data stack
Across the stacks we see, the same four failures come up. They are not vague risks. Each one has a check that finds it in an afternoon.
| Breaking point | What it looks like | The check that finds it |
|---|---|---|
| 1. Ownership | Every tool has its own owner field and none of them agree | Count assets with an empty or stale owner in every tool, not only the catalog |
| 2. Policy reach | A rule set in one tool does not follow the data out of it | Take one classified column and follow it into a BI extract |
| 3. Lineage | The graph stops where each tool stops instrumenting | Rename a table, then reopen the lineage graph |
| 4. Agents | An assistant reads tables nobody cataloged | Ask the assistant for a table you know is undocumented |
1. Ownership: five tools, five owner fields, no agreement
Ownership is the failure that looks solved and is not. Every tool in the stack has a place to record an owner, so every tool reports high coverage, and the four sets of owners disagree the moment anyone checks them side by side. Worse, most of those fields hold a team name or a service account rather than a person.
Tool boundaries make this concrete rather than philosophical. In Databricks Unity Catalog, detailed information about workspace objects such as notebooks, jobs and dashboards is visible only in the workspace where they were created, and appears masked to a user working from another workspace. Two teams can each believe they know who owns a pipeline while looking at different halves of it.
The working test: an asset has an owner only when the owner is a named person who can be contacted, recorded in a single system, and resolvable from any tool in the stack. A field filled with a team alias is a field, not an owner. Count your assets against that definition rather than against whichever tool gives the flattering number.
2. Policy: a rule set in one tool does not follow the data out of it
A classification is only worth what it reaches. In a modern stack, most classifications are written where it is convenient rather than where the data is read, and the gap between those two places is where policy quietly stops.
Take dbt. You can write a description and a classification against a column in the model YAML, and it will sit in the dbt project and go no further, because the persist_docs setting that pushes descriptions into the warehouse as column and relation comments is disabled by default. dbt Labs also documents that persist_docs is not implemented for sources at all, so the raw tables closest to your regulated data are the ones least likely to carry their description into the warehouse. On Databricks, column level comments additionally require a delta file format. Keeping those descriptions and classifications aligned across tools is the work covered in our guide to metadata governance.
Now take Snowflake. Tag based masking policies let you set a policy on a tag and have every column of a matching data type protected automatically, which is a real answer to scale. Two boundaries come with it. It is an Enterprise Edition feature, so a Standard Edition account does not have it. And the policy is evaluated when the column is queried inside Snowflake: an authorized role sees the raw value, and anything that role writes out to a CSV, a BI extract or a notebook carries the raw value with no policy attached to it.
The working rule: treat every export as the edge of a policy. Write the classification where the data is read rather than only where it is defined, and know the list of places your data leaves the tool that protects it.
3. Lineage: the graph stops at each tool boundary
Lineage is the most oversold part of the modern stack because every vendor ships a lineage view and every lineage view is honest about a smaller area than buyers assume. The limits are published. They are just published in the documentation nobody reads during a demo.
- Renames break the chain. Databricks documents that lineage is not preserved for renamed catalogs, schemas, tables, views or columns. The rename that tidied up your warehouse also cut the graph.
- History has a start date. Unity Catalog lineage captured before 1 September 2024 is not available at all, and the lineage system tables keep a rolling one year window while the Catalog Explorer view retains indefinitely from that date. Two views of the same lineage, two different answers.
- Some writes are never captured. Databricks column lineage excludes events with no source, so a column populated with explicit values does not appear.
- The BI layer depends on how the connection was made. Microsoft documents that correct semantic model to dataflow lineage in Power BI is guaranteed only when the connection was set up through the Get Data user interface with the Dataflows connector, and is not guaranteed when a Mashup query was written by hand.
- Not everyone can see it. The Power BI lineage view requires an Admin, Member or Contributor role in the workspace. A user with the Viewer role cannot open it, which usually means the analyst who needs it most cannot.
The working assumption: your lineage is complete only for objects that were never renamed, connected through the vendor user interface, and touched inside the retention window. Everything else needs a graph assembled outside the tools. How that graph is built, and what column level lineage adds over table level, is covered in data lineage tracking, its types and techniques.
Retention is where this becomes a compliance question rather than a convenience one. The windows are short and they differ by layer.
| Layer | What it retains | Documented limit |
|---|---|---|
| Snowflake Time Travel | Historical row state for queries, clones and undrop | 1 day by default, up to 90 days for permanent objects on Enterprise Edition |
| Snowflake ACCESS_HISTORY | Which user read which object and column | Last 365 days, Enterprise Edition or higher |
| Databricks lineage system tables | Table and column lineage events | Rolling 1 year window, older events removed |
| Databricks Catalog Explorer lineage | The lineage graph | Retained indefinitely, but only from 1 September 2024 onward |
| Power BI lineage view | Dataset, dataflow and report links | Scoped to one workspace, Viewer role cannot open it |
Read that table against your own retention obligation. If an auditor asks who read a customer column two years ago, a Snowflake account cannot answer from ACCESS_HISTORY, because the view covers the last 365 days. The record has to be landed somewhere with a longer window before the question is asked, not after.
4. Agents: assistants read the tables nobody cataloged
The newest breaking point is the one no governance program was designed for. An agent connected to your warehouse does not browse a catalog and pick the certified table. It runs a query. If an uncataloged copy of the customer table is sitting in a scratch schema with the same columns and no classification, the agent will find it, use it and answer confidently.
The failure mode is worth stating precisely, because it is not the one people expect. The risk is not that the agent invents an answer. The risk is that the agent is correct about a table that should never have been in scope, and nobody can tell from the answer which table it used. That turns every uncataloged asset into an access problem rather than a documentation problem.
Two numbers make the size of it visible in any stack. Count the tables an agent credential can reach. Then count the ones with an owner and a classification. The distance between those two numbers is your actual exposure, and in most stacks nobody has ever measured it.
The demo below shows what closing that distance looks like in practice. Claude is connected to live Decube context through an MCP server and works through a governance team, one after another: how asset recovery is calculated from query logs, how many assets have no owner, which dashboards a table change would break, and, in the part that matters here, finding a Databricks table holding customer email that has not yet been classified as PII. It also writes back, enriching descriptions and creating monitors, with access controls refusing users who are not authorized.
The governance controls an agent needs are the ones you already owe an auditor, applied to a non human reader. Our guide to governing AI agents that read your data works through the access model in detail.
What actually holds governance together across a modern stack
Four things, matching the four failures. None of them can live inside a single tool, which is the whole point.
- A single owner record, held outside the tools. A named person, recorded once, resolvable from any layer. The test is whether you can name the owner of an asset in a system you have not connected yet.
- A classification applied at the column and applied again at every export. The tag in the warehouse is the start. The list of places the data leaves that warehouse is what the classification actually has to cover.
- A lineage graph assembled from every layer. Including the BI layer and the agent layer, rather than read from whichever tool happens to have the best viewer.
- An access record kept longer than the shortest window in your stack. If the warehouse keeps 365 days and your obligation is two years, the record has to be landed somewhere else before the gap matters.
That set is what a data governance tool for a modern stack has to deliver: not a policy library, but a place where those four answers stay consistent while the tools underneath them change.
How Decube handles governance across a modern data stack
The rest of this page is the worked example. It is the Decube governance module, and it is organized around exactly the four problems above rather than around a feature list.
One place for every governance policy
Traditionally, governance policies are stored in disparate locations: spreadsheets, email threads and documents that live outside the systems holding the data. Decube provides a central location for all of your data governance policies and links them to the actual data assets in the Catalog. That link is what turns a written policy into something you can check, because it gives you a complete view of how a given asset is governed rather than a folder of documents nobody opens.
Create custom data classification
Every organization classifies differently, so classifications are yours to define. Add a custom policy in the Classification Policies tab and start classifying data against your own criteria. This matters most for teams early in a governance program: start with a basic set of classifications and add more as the program grows, rather than waiting to design the full taxonomy before anything is classified.
Automatic classification of sensitive data
The sensitive content pattern rule is a classification workflow inside each policy detail. It lets you set rules against connected data sources that automatically tag columns matching a keyword or a regular expression. For example, a rule can classify every column containing the phrase social security number as PII, which is how you close the distance between the tables an agent can reach and the tables that carry a classification. On a large stack this is the only version of the job that finishes.
Upload policy documents to our platform
Policy documents can be uploaded as attachments directly against the policy they belong to, so the governance documentation and the assets it governs sit in the same place. When an auditor asks for the written policy and the list of assets covered by it, both answers come from one screen.
Discover all assets classified under the policy
For each policy you get the list of assets managed under it, so every asset tagged as PII, for instance, appears in a single view. The list exports as a CSV, either to send to another team or to hand over for an audit. You can see the same governance features running end to end in the Decube product tour.
How to check your own stack this week
Four checks, one for each breaking point. None of them needs a project.
Whatever those four checks return is your governance position in a modern data stack, and it will be more specific than any maturity score. If you want to see the four answers assembled in one place across your own connected sources, book a Decube walkthrough and bring the numbers with you.
Frequently Asked Questions
What is data governance in a modern data stack?
Data governance in a modern data stack is the practice of holding a single answer to four questions about a table when the table is touched by five or six separate systems: who owns it, what class of data is in it, where it came from, and who read it. The definition of governance has not changed since the single database era. What changed is that no one system in the stack can answer any of the four questions on its own, so the answers have to be assembled in a layer that sits above the warehouse, the lakehouse, the transformation project, the BI tool and the agents.
What is the difference between AI governance and data governance?
Data governance controls the data: who owns a table, how it is classified, where it came from and who read it. AI governance controls the models and agents that act on that data: which models are in use, what they are allowed to touch, how they are tested and how their outputs are audited. They meet at one point. An AI system can only be governed as well as the data underneath it is governed, because an agent that reads an uncataloged table with no owner and no classification produces an answer nobody can trace. In practice a company needs both, and the data governance work has to be in place first.
What data quality and governance do you need before deploying AI agents on your data?
Four things, and they are the same four an auditor would ask for. First, every table the agent can reach has a named owner who can be paged, not an empty owner field. Second, every column holding personal or regulated data carries a classification that the agent's access path respects, not just the warehouse console. Third, lineage that reaches the tables the agent actually queries, so you can say what a wrong answer was built from. Fourth, an access record showing which agent read which column, retained for at least as long as your auditor asks for. If any of the four is missing, the agent will still work, and that is the problem: it will be confidently right about a table that should never have been in scope.
Which data governance platform is best for a healthcare company?
For healthcare the deciding factors are not feature counts, they are where the data sits and what the platform can prove. Ask three things. Does the platform read metadata without copying the underlying records out of your environment, so protected health information never leaves your boundary? Does it hold the compliance attestations your security review will ask for? Does it keep an access record long enough for your retention obligation, rather than the shortest window your warehouse happens to offer? Decube is built for the first point, keeping customer data inside the customer environment, and publishes SOC 2, ISO 27001, HIPAA and GDPR compliance along with TLS in motion and AES-256 at rest. Weigh any vendor on those three questions before comparing feature grids.
Who are Collibra's main competitors for data governance?
The platforms most often shortlisted against Collibra are Decube, Alation, Atlan, Informatica and Microsoft Purview. They split into two groups. The older enterprise suites sell a governance program: workflow, stewardship and policy management, usually bought by a chief data officer. The newer platforms sell governance attached to the working stack: catalog, column level lineage, classification and quality monitoring that a data engineering team runs day to day. The right shortlist depends on which of those two problems you actually have.
What is the difference between Alation and Atlan for data governance?
Both are catalog first platforms, so the difference that matters in an evaluation is rarely the feature list. Compare them on three axes instead. How much of the metadata arrives automatically from your connectors versus how much a steward has to type. Whether lineage reaches column level and survives a rename in the source system. And how the platform is deployed relative to your data, because that decides your security review more than any other answer. Run the same three questions across every vendor on your list, Decube included, and the shortlist usually reduces itself.
Where should the governance layer sit when data lives across a warehouse, a lakehouse and a BI tool?
Outside all of them, with read access into each. A governance layer that lives inside the warehouse cannot see the BI extract, and one that lives inside the BI tool cannot see the raw files. Three tests separate a real governance layer from a viewer built into one tool. Can it name an owner for an asset in a system you have not connected yet? Does its lineage survive a rename in the source? Can it answer who read a given column without you logging into the warehouse console?














.webp)