In data governance, how do the roles of data owner, data steward and data custodian differ?
answer
- accountable, careful, operating
- owner decides and answers for it
- steward keeps meaning and quality
- custodian runs systems and controls
basics
~20 sThe data owner is accountable for a dataset and decides its use and access; the data steward maintains its definitions, quality and metadata day to day; the data custodian operates the systems and technical controls that store and protect it.
solid answer
~40 sThese are commonly used governance roles with different kinds of responsibility. The **data owner** — usually a business leader for the domain — is **accountable**: they decide who may use the data and for what, approve definitions and retention, and answer for misuse. The **data steward** handles the **day-to-day care** of meaning and quality: maintaining definitions and glossary terms, resolving data-quality issues, keeping catalog metadata accurate, and advising users. The **data custodian** — typically an engineering or platform team — **operates** the systems: storage, backups, access controls as configured, security patches and pipeline operation. Custodians implement what owners decide; they should not decide access themselves. Organisations name these roles differently, but separating **accountability, care and operation** is the point.
go deeper
Be ready to say who is accountable, who maintains meaning and quality, and who operates the systems.
Walk through an access request or a quality issue and show which role does what.
Explain how you would assign and keep these roles current across many datasets, and the failures to avoid.
Decide how roles are mapped to the organisation's structure, including in a domain-oriented model, and how they are resourced.
## Why separate the roles Governance questions land on different people. "May the marketing team use this data?" is a business decision. "What does this column mean, and why is it wrong this week?" is a matter of domain knowledge. "Is the table backed up and are the grants applied?" is operational. Mixing these produces predictable failures: engineers deciding access they cannot judge, or business owners expected to fix pipelines. Governance frameworks and common industry practice therefore distinguish three roles. ## The three roles | Role | Kind of responsibility | Typical holder | Examples of duties | |---|---|---|---| | **Data owner** | accountability and decisions | a business leader for the domain | approves access and purposes, sets retention with legal input, approves definitions, answers for misuse | | **Data steward** | day-to-day care of meaning and quality | a domain expert or analyst with a governance role | maintains definitions and glossary terms, resolves quality issues, keeps catalog metadata accurate, advises users | | **Data custodian** | technical operation and protection | an engineering or platform team | runs storage and pipelines, applies access controls as decided, handles backups, patching and monitoring | ## How they interact 1. A consumer requests access; the **owner** decides, the **custodian** implements the grant. 2. A dashboard shows an implausible value; the **steward** investigates the definition and quality, the **custodian** fixes the pipeline if it failed. 3. A retention period is set; the **owner** approves it, the **custodian** configures the automated deletion, the **steward** checks the catalog reflects it. ## In a data mesh Data mesh places these roles **inside domains**: the domain's data product owner takes on accountability, domain members steward meaning and quality, and a **platform team** provides much of the custodian capability as self-serve infrastructure. The separation still holds; what changes is where the people sit. ## Common failures - **Owner by default**: the platform team is listed as owner of everything because it runs the storage, so nobody with business judgement decides access. - **Individuals instead of roles**: an owner leaves and the field goes stale; assigning the role to a team or position avoids it. - **Stewardship without time**: stewards are named but given no time, so definitions and quality issues pile up. ## Why interviewers ask it It is basic governance vocabulary, asked of analysts and engineers alike. A good answer distinguishes **accountability, care and operation**, gives examples, and knows why custodians should not decide access.
- Why should the platform team not be the owner of every dataset it stores?Because ownership means deciding who may use the data and for what, which needs business knowledge of the data and its obligations. The platform team can operate storage and controls well, but cannot judge purpose or need.
- How do you keep ownership current when people change jobs?Assign ownership to a team or a named position rather than an individual, resolve current contacts from the organisation directory, and report datasets whose owner cannot be resolved so they are reassigned quickly.
saying these in an interview costs you the question
- Letting the team that stores the data decide who may access it
- Using owner, steward and custodian as interchangeable terms
- Assigning ownership to individuals with no plan for when they leave
- Naming stewards without giving them time for the role