> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Module 7 · Track B: Validate & Govern

> Row-level rules in .tql only bind queries that go through the ontology. To make them the only path, ask your admin to mark the connection TQL-only — plain SQL is then refused on… (~20 min)

## 7.1 · Validate with golden datasets

```text Prompt theme={null}
Use these golden datasets and validation cases to check the metrics. Where a metric is ambiguous, reconcile it to the governed definition and add a golden-query test that pins the expected value.
```

<Check>
  **You'll see:** accuracy checked against known-correct outputs — and a pinned test that will alert on drift.
</Check>

## 7.2 · Govern with access policies

```text Prompt theme={null}
Apply these access policies to the ontology: restrict sensitive surfaces to the right roles (fail closed), apply row-level filters by scope, and limit restricted data to authorized roles. Show the access logic in the .tql.
```

<Check>
  **You'll see:** governance expressed *in the model* — fail-closed access rules, reviewable like any other file. (Module 9 takes this further with full personas.)
</Check>

<Note>
  **Make it enforceable, not advisory** — Row-level rules in .tql only bind queries that go *through* the ontology. To make them the **only** path, ask your admin to mark the connection **TQL-only** — plain SQL is then refused on that connection in every surface, and admins can also revoke the raw-sql role permission or disable raw SQL org-wide (see [**Admin & Governance**](/workshops/admin-governance/overview), Module 3.4b). **The order matters: the work you just did in this workshop is the prerequisite.** TQL-only removes the ungoverned path without creating a governed one — locking a connection whose ontology doesn't yet cover users' real questions strands them (and locking one with *no* query files makes it unqueryable). Build first — the modules you've completed — verify coverage ([**Ontology Operations**](/workshops/ontology-operations/overview) §2.5), then lock. The full security build lives in the [**Row-Level Security & Identity-Aware Access**](/workshops/row-level-security/overview) workshop.
</Note>

### ✅ Checkpoint

* [ ] At least one metric has a golden-query test pinning its expected value
* [ ] Sensitive surfaces fail closed, and you can point to the access logic in the .tql


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.