Skip to main content
Adrià García

Architecture guide

Seeing data does not permit every use

An agency prepares a campaign for a group brand. It needs limited access, a permitted data use and applicable messaging preferences. These are different controls.

Sources checked:

None replaces the others

  1. Access · who

    1. User and role
    2. Authorised resource

    May the agency inspect this field or work with this audience? Review permissions, resources and access policies.

  2. DULE · what for

    1. Labelled data
    2. Evaluated use

    Does the contract permit advertising use? An enabled policy connects the restriction to a marketing action.

  3. Consent · whose preference

    1. Person's preference
    2. Channel enforcement

    Which preference applies to this brand, purpose and channel? The check depends on the message and configured controls.

A profile's brand attribute is not a security boundary. An audience filter does not prove the team cannot access other data.

What Adobe documents

ABAC connects roles, labels and resources

AEP can restrict resources such as fields and audiences through access policies. Dataset label-based access requires its policy to be active. Labelling a field does not automatically label an audience using it.

Adobe: Attribute-based access control

DULE evaluates uses, not roles

A usage policy connects labels to marketing actions. Resource access does not override that policy. Usage policies are disabled by default, including the predefined ones.

Adobe: Data governance

Message type matters

AJO distinguishes marketing and transactional messages in its consent controls. A marketing opt-out is not a universal ban on email. Nor should transactional classification be used to bypass it.

Adobe: Marketing and transactional email

How I would review it

  • Test with an agency user and an internal user. List the objects and data each can read or change.
  • If brands require isolation, design that boundary explicitly. Do not infer person-level isolation from a label or a brandId field.
  • Also review technical identities, exports and APIs. A permission working in the interface does not prove every integration behaves correctly.

This guide compares architectural controls. It does not certify isolation or legal compliance. Validate the access model against enabled capabilities and organisational requirements.

Explore through examples

Related services