The data and governance features already existed, but users had to navigate separate technical services to use them. CLOUDSUFI built a business-facing interface that brings context and next steps into one journey, while the client retains control of permissions and approvals.
The underlying Google Cloud services were already in place. The required data and governance features also existed. However, users had to work across separate technical services. They had to navigate project structures and metadata, and permissions, lineage, and quality data appeared in different places.
CLOUDSUFI designed and built the business-user interface. The UI sits above the existing platform, bringing discovery, context, governance, and access together, and guiding users toward relevant next steps. Users can now work through one product experience instead of learning each service first.
CLOUDSUFI did not replace the platform. It did not change the data or governance model. The client still controls its data and metadata, along with roles, policies, approvals, and decision rights. CLOUDSUFI built the experience layer through which people use these features.
Enterprise data was spread across many projects and services, covering many domains and asset types. Users needed to understand the platform’s design before they could find and assess the right resource. One task could involve several steps: a user might search in one service and inspect metadata in another, then need to rebuild lineage details, check quality data elsewhere, find the asset owner, and still need access guidance.
This journey relied on specialist knowledge, and it was fragmented for both business and technical users. Key challenges included: search required knowledge of projects and services; users had to know resource types and technical names; business terms and technical metadata appeared separately; lineage, quality, and policies were hard to assess together; publishing data products required manual setup; sharing involved uneven handoffs between teams; access limits were visible, but next steps were unclear; and separate copies could create duplicate or stale data, increasing governance work.

CLOUDSUFI owned the full business-user interface, covering both product design and interaction design. The work also included frontend development and the integration layer between existing services. The team designed governance and access workflows, created role-aware states and actions, and built reusable components that support the full application.
The UI provides a new starting point: users can begin with a question and don’t need a project or resource ID. CLOUDSUFI redesigned the journey around what users want to do, not around the platform’s technical structure, turning common questions into guided paths: what data exists, what does it mean, can I trust it, who owns it, do I have access, and what can I do next.
Five capabilities carry that journey. Discover lets users search with natural language or keywords and filter by products, assets, aspects, and projects, with results in grid or table views. Understand lets users review the resource overview and schema, view documents and business terms, and see ownership, lineage, quality signals, and generated insights in the same journey. Govern lets users view aspects and classifications, review policies, access groups, and contracts, with business glossaries providing added context. Request supports permission-aware requests with visible status, an auditable approval path, and final approval remaining under client control. Use lets users open approved data in BigQuery or Looker, provided their existing permissions allow it.


Knowledge Catalog makes access easier to understand and easier to request. However, the UI does not gain approval authority, and CLOUDSUFI does not gain that authority either. The client still defines roles and permission groups, along with policies, owners, and approvers. These controls remain inside the client’s environment.
The UI shows the right status and next step, so users can see when access is not available, provide context for a request, and then track its status. Users can proceed after the client approves access, following the client’s existing approval process: discover a governed asset or data product, evaluate its meaning, owner, quality, and lineage, request the relevant group and provide context, have the client owner apply existing governance rules to approve, and use approved data in an analysis environment.
CLOUDSUFI built the UI as a product layer designed to be maintained over time. The UI supports large catalogs, and its components can be reused across many workflows. The product responds to existing roles and permissions and stays aligned with the client’s environment. It does not duplicate the client’s data, and it does not create a separate governance authority.
Four design principles carried the build. A unified integration layer brings catalog, asset, lineage, and quality data into one interaction model, along with project and sharing details, so users do not need separate service-by-service workflows. Role-aware behavior reflects the client’s current access model, including authentication and permissions, and applies to restricted assets and access actions. Automated metadata synchronization keeps the UI aligned with the metadata and governance details stored in the underlying environment. Responsive catalog navigation is designed to work across large catalogs, using virtualized result browsing so it does not load the full result set at once.
The product architecture is modular: reusable components support a consistent product experience, and structured modules support versioned releases. The UI supports light and dark themes, and its design allows continued growth. In-place data consumption lets approved subscribers use publisher-controlled data through linked access — helping preserve fresh data and avoiding needless copies and data movement.

The impact comes from the UI that CLOUDSUFI built. Business and technical users now have one direct path to find and interpret enterprise data. They can also review governance details and request access when needed.
The UI presents context around each task and asset. Users previously needed knowledge of several technical services to find these details. The underlying platform remains intact, and its features remain under client control — what changed is how people use those features. The reusable UI can support new data domains, services, policies, and workflows. Users do not need to relearn each service; the UI handles the technical structure beneath each journey.
Simplified discovery lets users search by intent, then refine results with governed context. Unified understanding lets users review business and technical signals around one asset. Guided access lets users view requests and status within existing controls. Client control means the client retains control of data and policies, and its roles and approvals remain authoritative.
CLOUDSUFI designed and built the business-user interface as an open-source implementation. The source is in the GoogleCloudPlatform repository, which includes setup and deployment guidance, published under the Apache License 2.0.
Let's build what's next.
Talk to us about your data and AI challenges — and how CLOUDSUFI can help solve them.
Talk to us →