DataSquares for the enterprise
Governed analytics for the whole company.
Connect the systems you already run, define each metric once, and give every team dashboards, stories, reports and AI answers. Sign-in, access, audit and AI spend are managed in one place.
One governed path from source to decision.
Every stage shares one sign-in, one permission model and one set of metric definitions, so governance is set up once rather than tool by tool.
Integrate
Bring data in
Connect databases, warehouses, files and business apps from a catalog of 143 connectors, 74 of them generally available, with read-only access. Pipelines move and reshape data on a schedule.
Store
Keep it where it works
Query your databases and warehouses where they are, or import tables into the managed Warehouse, where each workspace has its own isolated database.
Model and govern
Define it once
Data models hold relationships, measures and row-level security. Governed metrics define each KPI once, and certification, quality checks and lineage show which numbers to trust.
Analyze, share and ask
Use it everywhere
Dashboards, stories, reports, embeds and AI answers read the same definitions, under the same access rules.
Governance that holds at company scale.
Certify the numbers people should use, keep sensitive data in the right hands, and stop bad data before it is published.
- Certified metrics
- Define a KPI once, with its grain and an accountable owner. KPI cards, digests, alerts and AI answers use that one definition, and certified metrics come first in search.How it works: Certified metrics
- Row-level security
- Policies on the data model decide which rows each person sees, beneath every chart, export and drill-down, and in embeds through the viewer’s token.How it works: Row-level security
- Field masking
- Fields with a sensitivity label show as *** to everyone but workspace admins, on every surface that queries the model, AI answers included.How it works: Field masking
- Quality gates
- A failing critical check holds publication while the last good version keeps serving. An override needs a written reason, and the audit log keeps it.How it works: Quality gates
- Lineage and impact
- See what feeds any asset and what would break if it changed, before you rename a field or retire a model.How it works: Lineage and impact
- Business glossary
- Write down what your terms mean. AI answers use your definition of “active customer”, and field tooltips show it where people build.How it works: Business glossary
Administration in one place.
Identity, roles, billing and AI spend are run from one Administration area, and parts of it can be handed to the teams that own them.
- Single sign-on and SCIM
- Connect your identity provider over OpenID Connect or SAML 2.0, and let SCIM 2.0 create, suspend and remove members and push groups.How it works: Single sign-on and SCIM
- Sign-in policy
- Require two-factor authentication for every member, and choose which faster sign-in methods, such as passkeys, your people may use.How it works: Sign-in policy
- Workspaces and groups
- Give each team or environment its own workspace, with its own members, dashboards and data sources, and share with whole groups at once.How it works: Workspaces and groups
- Roles and delegated admins
- Built-in and custom roles set view, create, update and delete rights per area. Pages such as the audit log and usage can be granted without the rest of Administration.How it works: Roles and delegated admins
- Billing access for finance
- Each billing page is its own permission and people can hold a billing role, so finance can work with invoices and AI credits without the rest of Administration.How it works: Billing access for finance
- AI spend you can see and cap
- Every AI feature spends one credit balance, with usage by feature and a ledger of every debit. Auto-recharge buys credits only within a monthly cap you set.How it works: AI spend you can see and cap
- Audit log and query records
- A tamper-evident audit log and a record of every query, exportable as CSV for a reviewer or as a feed for your SIEM.How it works: Audit log and query records
- API keys bound to their owner
- Personal API keys carry scopes, always expire, and never do more than their owner’s role allows.How it works: API keys bound to their owner
How teams roll it out.
A sensible order for bringing DataSquares to a whole company, with the guide for each step.
- 1
Connect your identity provider
Turn on single sign-on, connect SCIM so joiners and leavers follow your directory, and require two-factor.
SSO, SCIM and MFA guide - 2
Set up workspaces and roles
Create a workspace per team or environment, add groups, and delegate the Administration pages each team needs.
Users and roles guide - 3
Connect data and govern it
Connect sources with read-only users, build models with row-level security, and certify the first metrics people should use.
Data models guide - 4
Share where people work
Publish dashboards, write stories for business reviews, schedule reports, embed in your portals and answer metric questions in Slack.
Use cases
Ways teams share what they find
Reach people where they already work: in a review document, their inbox, your own portal, Slack or their phone.
- Stories for business reviews
- Start from a business review, board pack, incident review or weekly KPI update template, and ask reviewers to approve before anything is published.How it works: Stories for business reviews
- Scheduled and data-driven reports
- Email reports and dashboards on a schedule as PDF, Excel, PowerPoint or CSV, or send each regional manager only their own region.How it works: Scheduled and data-driven reports
- Embedded analytics
- Embed dashboards and reports in your portals, with each viewer’s rows scoped by a token your server mints. Embeds carry your logo and theme with a small Powered by DataSquares credit.How it works: Embedded analytics
- Promotion between workspaces
- Export dashboards, models and metrics as definitions with no data or credentials, import them into production, and see a field-level diff before you promote.How it works: Promotion between workspaces
- Answers in Slack
- A slash command answers governed-metric questions in a Slack channel, and stories can be shared to Slack without their numbers.How it works: Answers in Slack
- A phone app for readersEarly access
- People read dashboards, metrics, alerts and stories on Android with their own access; building stays on the web.How it works: A phone app for readers
Ready for your security review.
Every control is documented, and the security page links each one to the page that explains how it works.
- Single sign-on over OIDC or SAML 2.0, SCIM 2.0 provisioning, and two-factor you can require for everyone
- Row-level security and masking applied where the query runs, so they hold on every surface
- AI that reads only what the asker may read and asks before it changes anything
- A tamper-evident audit log and a record of every query
- Source credentials encrypted with AES-256, and only read queries against your sources
- API keys that expire and never do more than their owner’s role allows
How is DataSquares delivered?
Does our data have to move into DataSquares?
Can we use our own identity provider?
How do we keep AI usage under control?
Can we embed DataSquares in our own products?
How do we move work from development to production?
Which products are in early access?
Plan your rollout with our team.
Book a walkthrough on your own requirements, or start a free trial and try it on your own data.