Data access governance for decentralized data science teams
Centralizing governance over data access across decentralized teams closes the gap between fast-moving analytics work and the audit trail regulated banks must produce for every model in production.

Himadri Banerjee
Product Owner, Data Science & Analytics
Zürcher Kantonalbank
What you'll take away from this session
Platform ownership must sit outside delivery teams
Delivery pressure always wins when the same team owns both use case delivery and platform maintenance. Separate, dedicated ownership is the only durable model.
Centralized platforms compound in value
Every connector, base image, and onboarding process built once lowers the cost of the next use case. New teams inherit a governed environment instead of building one from scratch.
Three-tier identity model separates access risk
Named human accounts, development service identities, and production service identities each carry distinct data access rights. This separation lets one installation serve live banking data safely.
Vulnerability management runs on a weekly cadence
Open-source components create a large, constantly changing attack surface. Every high or critical finding gets reviewed weekly, then remediated or documented as a reasoned exception.
Data virtualization avoids replicating governed data
A virtualization layer enforces governance controls at the source boundary instead of copying data into the platform. This keeps data residency and access rights exactly where they belong.
Cloud migration requires re-engineering every connection
Every source system connection needs re-engineering before a bank can decommission its old environment. Public cloud migration does not just relocate workloads; authentication and authorization must be rebuilt for each connection.
Zürcher Kantonalbank runs one Domino installation across eight decentralized teams spanning analytics, compliance, risk, audit, and fraud, supporting more than 70 data scientists with a platform team of six. Himadri Banerjee, Product Owner for Data Science and Analytics, built that setup over six years, moving from a fragmented, team-by-team approach to a single governed enterprise data platform with clear separation between where data science happens and where infrastructure is managed.
Four groups pull on the platform at once: cloud infrastructure, security and compliance, data governance, and use case teams racing to reach production. Banerjee argues that data access governance at this scale cannot survive as a side task inside a delivery team; it requires dedicated ownership with its own mandate. Without that mandate, every control the bank puts in place eventually loses to deadline pressure. The platform team's payoff shows up in what the analytics teams never have to touch: security negotiations, upgrade timing, and data connectivity get resolved before those teams ever encounter them.
FAQ
What organizational model supports data science at scale in a regulated bank?
How do banks connect a cloud AI platform to on-premises data sources?
What does vulnerability management look like for an open-source data science platform at a bank?
Transform the work that matters most
See how Domino helps the world’s most regulated enterprises build, scale, and govern AI-powered applications.