User Entitlements for AI Data Access
Giving data teams granular control over which schemas, tables, and columns each user can access.
Give AI access without giving everyone access
Agentic analytics makes it dramatically easier for employees to explore company data.
That freedom is powerful, but without the right controls, it can also increase the surface area of data that employees are able to access.
Supper User Entitlements gives data teams precise control over what each user can see, while preserving the freedom and power of agentic analytics.
Admins can define allow and deny permissions across schemas, tables, and columns, creating an access surface that is appropriate for each user.
The result: companies can make more data available for analytics without assuming that every employee should be able to access all of it.
What are Supper User Entitlements?
Supper User Entitlements are the permissions layer that governs which parts of a company's data each user can access through Supper.
The system supports granular allow and deny permissions that can apply broadly across data or narrowly to individual:
- Schemas
- Tables
- Columns
Supper's entitlement structure is modeled after the flexibility of AWS IAM. Administrators can create broad permissions using wildcard-style rules or define highly specific access boundaries for individual users.
That means a company can give employees powerful natural-language analytics while ensuring that each person remains inside the appropriate scope of data.
Why does AI-powered analytics need a permissions layer?
Traditional data access already requires governance. Agentic analytics makes that requirement even more important because it removes much of the friction involved in querying data.
Without an entitlement layer, an MCP connection or other open-ended warehouse connection can expose a broad range of schemas and tables to users.
That creates two problems.
First, administrators have less confidence that employees are staying within the data boundaries appropriate for their roles.
Second, data teams can become reluctant to make additional data available. Every new table added to the warehouse can increase the surface area of information potentially accessible through AI.
Supper is designed to remove that tradeoff.
More data should make an analytics system more useful, not make administrators more nervous about who can see it.
More data, not more risk
The purpose of Supper's entitlement layer is not simply to restrict access.
It is to make broader access possible.
When data teams know that each user's data surface is explicitly controlled, they can feel more comfortable connecting additional schemas and tables to Supper.
Employees still get the ability to ask questions in natural language and work with company data through agentic analytics.
Data teams and executives retain control over where those capabilities begin and end.
Enterprise-grade permissions, even for small teams
Supper deliberately chose a sophisticated permissions model rather than reducing access control to a handful of simple roles.
Even small companies can have sensitive financial, customer, operational, personnel, or executive data. Company size does not eliminate the need for strong data governance.
Supper therefore supports enterprise-grade entitlement rules with granular allow and deny controls.
Administrators can manage permissions directly through the entitlement structure or use Supper's permission-management interface to make configuration easier.
Permissions can also be cloned or copied when administrators need to apply similar access patterns across users.
Roles and data permissions are separate
Supper controls access along two dimensions.
Product roles determine what someone can do inside Supper.
Admins can manage higher-level capabilities such as the semantic model and other configuration controls. Regular users can ask questions and see answers without receiving those administrative capabilities.
Data entitlements determine what data someone can access.
A user may be allowed or denied access to particular schemas, tables, or columns independently of their general product role.
Together, these controls let organizations govern both what users can do in Supper and what company data they can do it with.
Granular access from schema to column
Supper's entitlement model can cover a wide range of access patterns.
An administrator could give a user broad access across a large data surface, restrict them to a particular schema, narrow access to specific tables, or control access at the individual-column level.
Allow and deny permissions give administrators the flexibility to create combinations appropriate to their organization.
The objective is simple:
Every employee should be able to access exactly the data that is appropriate for them, and no more.
Built for data teams
The hero of the Supper entitlement model is the data team.
Instead of choosing between tightly restricting AI or exposing a warehouse too broadly, data administrators can give colleagues a powerful analytics experience with explicit boundaries.
That also gives executive teams confidence that employees can take advantage of agentic AI while the organization maintains control over sensitive company data.
Agentic analytics, with boundaries
The promise of AI-powered analytics should not depend on giving every employee unrestricted access to company data.
Supper combines powerful agentic analytics with a granular entitlement layer so organizations can give people more freedom to explore data while maintaining control over what each person is allowed to see.
More data. More analytical freedom. The right boundaries for every user.
FAQ
What are user entitlements in Supper?
User entitlements are Supper's data-access permissions. They determine which schemas, tables, and columns an individual user is allowed or denied access to when using Supper.
Can Supper restrict access to individual tables?
Yes. Supper permissions can be defined at the schema, table, and column level.
Can Supper restrict access to individual columns?
Yes. Supper's entitlement model supports column-level permissions, allowing administrators to define more granular access when necessary.
Does Supper support both allow and deny permissions?
Yes. Supper uses an entitlement structure with both allow and deny rules.
How is Supper's permission model designed?
Supper's entitlement model takes inspiration from AWS IAM and uses a flexible permission structure that can range from broad wildcard-style access to specific schemas, tables, and columns.
What is the difference between a Supper admin and a regular user?
Admins have access to higher-level product controls, including management of the semantic model. Regular users can use Supper to ask questions and view answers without receiving those administrative capabilities.
Why are user entitlements important for AI analytics?
Natural-language and agentic analytics make it easier for employees to query company data. Entitlements ensure that this increase in analytical power does not automatically become an increase in unrestricted data access.
How does Supper make AI access to a data warehouse safer?
Supper adds an access layer that controls the data surface available to each user. Instead of assuming that anyone using an AI interface can reach everything exposed through a warehouse connection, administrators can define explicit user-level boundaries.
Are Supper User Entitlements only for large enterprises?
No. Supper's position is that even small companies deserve enterprise-grade data permissions. Sensitive data and access-control requirements can exist at organizations of any size.
Can administrators reuse permission configurations?
Yes. Supper provides controls for copying and cloning permissions to make sophisticated access structures easier to manage.