learn-business-intelligence-with-phoebe / Leader session 5 of 6
Learn Business Intelligence with Phoebe · Leader track · Session 5 of 6

Self-service BI without chaos

Every leader wants both: teams that answer their own questions, and one version of the truth. Most orgs get one or the other. This session gives you the operating model that delivers both - who builds what, with which guardrails - simple enough to draw on a whiteboard, real enough to survive contact with your actual org chart.

🟡 Leader track Leaders: execs · managers · non-technical No code · 45 minutes
0-3 · Welcome 3-16 · Operating models 16-42 · Guardrails + demos 42-45 · Q&A
Part 0

The tension this session resolves

Session a4 taught you to commission one dashboard well. But you will not commission every dashboard - at some point marketing, ops, and finance will want to build their own. Say yes with no plan and you get forty versions of revenue. Say no and you become the bottleneck everyone routes around anyway. The answer is an operating model: an explicit deal about who builds what, and which guardrails keep the numbers trustworthy.

Live - presented in session Self-study - read after class ▶ Mini-BI - interactive playground Official sources covered
★ What you walk out with today An operating model you can draw on a whiteboard: the three ways to organize BI and why hub-and-spoke usually wins, the trust-tier ladder (ad-hoc, promoted, certified), what row-level security really is (a leadership decision, not an IT detail), and the culture moves that make any of it stick.
Part 1 · covers Tableau Blueprint role paths, Google BI org framing

The three operating models 8 min live

There are only three ways to run BI in a company, and every org is somewhere on this line. Central BI team: every dashboard comes from one team - quality is high and consistent, but the queue is long and the business routes around it with spreadsheets. Full self-serve: anyone builds anything - gloriously fast, until the CFO and the CMO bring different revenue numbers to the same board meeting. Hub-and-spoke: a small central team owns the governed core, and trained builders inside each domain build on top of it. That third one is the mature answer, and the rest of this session is how to run it.

Central BI team One team builds it all Quality: high, consistent Queue: long, weeks not days Business routes around it Full self-serve Anyone builds anything Speed: instant, no queue Forty versions of revenue Trust erodes quietly Hub-and-spoke Governed core + builders Hub owns definitions Spokes ship fast on top The mature default Most orgs drift into full self-serve, feel the chaos, then land on hub-and-spoke. You can skip the pain.
🔍 Click to zoom - three ways to organize BI, and the trade each one makes
LiveHub-and-spoke in practice4 min

The deal, spelled out so both sides know what they signed:

  • The hub (central team) owns the semantic model and certified content: the definitions of revenue, active customer, and churn live in one place, plus the handful of dashboards the whole company steers by. Small team, high leverage - they build the road, not every car.
  • The spokes (domain builders) build on top: a trained analyst inside marketing, ops, or finance builds their team's dashboards using the hub's certified measures. They get speed and domain context; they do not get to redefine revenue.
  • The boundary is the semantic layer: from a3 - definitions encoded once, so every spoke chart agrees with every hub chart. Break the boundary and you are back to full self-serve chaos with extra steps.
The whiteboard version One circle (hub: definitions + certified core), four squares (spokes: domain builders), lines between them. If you cannot name who sits in the circle and who sits in the squares at your company, that is this week's homework.
Self-studyTableau Blueprint's role map - who you need to resource4 min read

Tableau's official Blueprint methodology defines 12 role-based learning paths in 3 groups. You do not need Tableau to use this map - it is the best public checklist of the roles a real BI program needs, and leaders are the ones who resource them:

GroupRolesYour job as a leader
Enable a Data CultureExecutive Sponsor · Community Leader · Data StewardFill these first - one is probably you. No sponsor, no program.
Provide InsightsConsumer · Author · Designer · Analyst · Data Scientist · DeveloperMap your people onto the ladder. Most staff are Consumers; each spoke needs at least one Author or Analyst.
Deploy and ManageSite Admin · Server Admin · Server ArchitectUsually IT. Confirm someone actually owns this before dashboards go company-wide.

Notice what the grouping implies: a full third of the map is culture, not tooling. Tableau ships software for a living and still says the sponsor and steward roles come first.

Part 2 · covers PL-300 "Manage and secure Power BI" - the leader view

Guardrails that make self-serve safe 10 min live

Hub-and-spoke only works if viewers can tell governed content from a Friday-afternoon experiment. Four guardrails do that job, and each one maps to a feature your BI platform already has: trust tiers (certified vs promoted vs ad-hoc content), workspaces as team boundaries, row-level security for who sees which rows, and sensitivity labels for what may leave the building. These are exactly the topics in the PL-300 exam's "Manage and secure Power BI" domain - your builders learn the buttons in b8; you decide the policy here.

Ad-hoc Anyone can publish Promises nothing yet Promoted Team lead endorses it "Worth a look" signal Not independently audited Certified Definitions checked vs core Refresh monitored Named owner on the hook The org-wide truth tier Viewers must see the tier at a glance - a badge on the dashboard. Trust is a label, not a vibe.
🔍 Click to zoom - the trust-tier ladder every self-serve org needs
LiveThe certification ritual - who signs off, and on what4 min

Certification is a ritual, not a checkbox. Before anything wears the certified badge, a named reviewer (usually the hub's data steward) checks three things:

  • Definition: every measure on the dashboard resolves to the semantic model's definition - its "revenue" is the revenue from a3, not a local remix.
  • Refresh: the data updates on a stated schedule, someone is alerted when refresh fails, and the last-refreshed time is visible to viewers.
  • Owner: a named human answers for it - questions, fixes, and the eventual decision to retire it. No owner, no badge.

Promoted is the lighter tier: a team lead vouches for it inside their team, no central audit. Ad-hoc is everything else - allowed to exist, labeled as such. Three tiers, three levels of promise; the ladder only works if the badge is visible.

Self-studySecurity questions leaders must answer - RLS and labels4 min read

Row-level security (RLS) means one dashboard, where each viewer sees only their slice of the rows: the Singapore city manager opens the sales dashboard and sees Singapore; the exec opens the identical dashboard and sees everything. Nobody maintains five copies. The technology is a builder task (b8) - but the matrix of who sees what is a leadership decision, and someone has to write it down. For Daybreak it looks like this:

Viewer roleSees rows forWhy
City managerTheir own city onlyRuns one market; other cities are noise and a leak risk
Channel managerTheir channel, all citiesOwns web or wholesale end to end
Finance analystAll rows, no customer namesNeeds totals, not personal data
ExecutiveEverythingAccountable for the whole

Sensitivity labels answer the other question: what may leave the building? Marking content Confidential or Internal travels with the data when someone exports it to Excel or PDF. Decide the label policy once; the platform enforces it everywhere.

Part 3 · covers Google BI cert org-impact themes, Tableau Blueprint culture group

Data culture - the multiplier 6 min live

Here is the uncomfortable part: you can buy the tool, design the perfect operating model, and still fail. Tools do not create adoption - rituals, champions, and training do. Remember the 9am test from the builder track: if a question gets asked every Monday at 9am, it deserves a dashboard. The org-level version: if your Monday meeting still opens with a spreadsheet screenshot, your BI program has not landed, whatever the license count says.

LiveThe champion network4 min

The highest-leverage culture move costs almost nothing: name one champion per team - the person who already answers everyone's data questions anyway - and make it official.

  • Give them first access and first training: champions see new certified content before anyone else and get the builder-track skills (point them at b1).
  • Give them a channel: a monthly champions call where the hub previews changes and champions surface what confuses their teams. This is where definition drift gets caught early.
  • Give them credit: put the champion role in performance reviews. Unpaid, unrecognized champion networks dissolve within two quarters.
  • Rituals beat mandates: open your own Monday meeting from the certified dashboard, every week, visibly. Teams copy what leaders do, not what they announce.
Real world

The 200-orphan cleanup. A retail company rolled out self-serve BI with enthusiasm and no trust tiers. Eighteen months later an audit found roughly 200 dashboards nobody could explain: no owner, unknown refresh state, three competing definitions of margin. Viewers had learned to trust none of them - adoption was falling while dashboard count grew. The fix was not a new tool. They introduced certification, badged 15 dashboards as the governed core, archived anything unowned after a 30-day claim window, and adoption recovered within two quarters. The lesson: an uncertified pile does not converge on truth by itself - somebody has to hold the ladder.

Demo 1 of 2

Design Daybreak's operating model ★ 12 min · whiteboard exercise

Daybreak has grown to 200 people: marketing, ops, finance, and a two-person data team. Design its BI operating model on one whiteboard - the same four moves you would make at your own company.

Pick the model. 200 people, four departments wanting dashboards, two data people. Central team? They become the bottleneck in a month. Full self-serve? Forty revenues. Hub-and-spoke: the two data people are the hub; one trained builder per department is the spoke.

Name the certified core. Which metrics get the badge on day one? Keep it brutal: revenue, orders, active subscribers, average order value, churn. Five metrics, certified, owned. Everything else can be promoted or ad-hoc until it earns its way up.

Draw the RLS matrix. Two rows to start: the channel manager sees their channel across all cities; the exec sees everything. Write it as a table with names in it - the moment it has names, it is a policy instead of an intention.

Assign Blueprint roles. Who is Executive Sponsor (you), who is Data Steward (hub), who are the Authors (spokes), and who runs the platform (IT)? If a Blueprint role has no name next to it, you have found your first hiring or training gap.

The test of a good operating model A new marketing hire should be able to answer three questions in their first week: where do I find the numbers I can trust (certified core), who builds new views for my team (their spoke builder), and what am I not allowed to see (the RLS matrix). If any answer is "ask around", the model is not done.
Demo 2 of 2

Stress-test with the playground ★ 8 min · think like a spoke

Below is Daybreak revenue by channel in the same mini-BI your builders use. Imagine you have just handed this data to self-serve channel managers - then stress-test your guardrails against what they will actually do with it.

Spot the drift risk. A channel manager rebuilds this chart but quietly nets out refunds, because "that reflects my real performance". Their revenue no longer matches finance's. Which guardrail catches it? Certification - their version can exist ad-hoc, but it cannot wear the badge, and the Monday meeting only ever shows badged numbers.

Spot the leak risk. The wholesale manager screenshots the full chart - including the web channel's numbers - into a partner deck. Which guardrails? RLS should have limited what they saw in the first place; a Confidential sensitivity label makes the export policy explicit.

Now press Show SQL. The generated query is the semantic layer doing its job: every spoke asking for "revenue by channel" gets this same SQL. That is why the hub guards the definitions - one translation, no drift at the source.

Homework

Try it yourself - this week ◐ 20-30 min total

Source material

Official sources covered

The leader track distills the governance and org-design material from the official curricula, minus the button-clicking. This page covers:

PL-300 · Manage and secure Power BI - workspaces, endorsement, RLS, sensitivity labelsPart 2 · the leader view; your builders get the hands-on depth in b8
Tableau Blueprint · 12 role-based learning paths in 3 groupsPart 1 · the role map leaders resource, tool-agnostic reading
Google BI cert · organizational impact and data-driven culture threadsPart 3 · culture as the multiplier; Google's course spreads this across modules
Check yourself

Three questions before you go 🎯 ◐ 90 seconds

1 · What does hub-and-spoke give you that the other two models do not?

Central teams give truth without speed; full self-serve gives speed without truth. Hub-and-spoke splits the work: the hub owns definitions and certified content, the spokes ship fast on top of them.

2 · A dashboard carries the "certified" badge. What exactly is being promised?

Certification is a checked promise: definition, refresh, owner. Who built it and how popular it is are beside the point - plenty of well-meant, popular dashboards fail the audit.

3 · What does row-level security (RLS) actually do?

RLS filters rows per viewer on a single shared dashboard - which is exactly why it replaces the five-copies-per-region mess. And deciding who sees what is a leadership call; the implementation is b8's problem.

Leader session 5 cheat sheet · pin this

Three modelsCentral (truth, slow) · full self-serve (fast, forty revenues) · hub-and-spoke (both). Know where your org sits.
Hub-and-spoke dealHub owns the semantic model + certified core; trained domain builders ship on top. The boundary is the definitions.
Trust tiersAd-hoc (no promise) → promoted (team lead vouches) → certified (audited). The badge must be visible to viewers.
Certification ritualThree checks before the badge: definition matches the model, refresh monitored, named owner. No owner, no badge.
WorkspacesTeam boundaries for content: who can publish where. The org chart of your BI platform.
RLSOne dashboard, per-viewer rows. The who-sees-what matrix is a leadership decision - write it down with names.
Sensitivity labelsConfidential/Internal marks that travel with exports. Decide the policy once, the platform enforces it.
Culture multiplierChampions per team + leader rituals beat mandates. If Monday still opens with a spreadsheet, BI has not landed.