Back

Data Governance Portal

GOV.UK UKHSA — 2026

UKHSA Data Governance Portal landing page with sign-in and employee-code registration

Role

Lead Developer & System Engineer

Team

Najaf Arash Dastnaei

Nassim El-Hallaoui

Emma Grantham

Badriyah Almutairy

Timeline

10 Weeks

Overview

The UKHSA Data Governance Portal was a university group project focused on creating a centralised system for managing and reviewing data governance information. Designed around the needs of an organisation handling large amounts of data, the portal provides a structured way to manage data assets, governance records, and related information. The project aimed to make data governance more organised, accessible, and easier to manage while giving users a clear interface for working with the information they need.

Highlights

We turned a slow, fragmented access process into a single system designed to make data access faster, clearer, and easier to manage.

User dashboard showing a Request Access panel alongside a list of current dataset access grants

0.1Requesting access alongside a live view of current grants.

Image
Dataset picker open, listing datasets with SENSITIVE and NON_SENSITIVE tags

0.2Every dataset labelled by sensitivity before you request it.

Image
Admin employee directory with filters by role, status, and training expiry

0.3Employee directory with role, status, and training expiry.

Image
Audit log listing access grants, revocations, and approvals with filters by user, dataset, and date

0.4A filterable audit trail of every access decision.

Image

The Problem

A simple access request was becoming a slow, manual process.

UKHSA wanted to replace multiple disconnected steps with one system.

The existing process for granting access to the main database relied on several systems and manual steps. Users submitted their requests through a web survey, the requests were collected into a CSV once a day, and the file then had to be manually uploaded to the data platform before a script could process each request. Non-sensitive datasets could be approved automatically, while sensitive datasets required a human approver. This created several problems: requests could be delayed by the daily processing cycle, manual uploads introduced opportunities for errors, and administrators had no single place to see who had access to which datasets or track requests. Changes to datasets and approval rules also required manual script changes, while different naming conventions between the front-end and database added further complexity. UKHSA's goal was therefore to replace this fragmented workflow with a single web application that could manage the entire process, from submitting an access request through to approval, database updates, and eventual access revocation.

Process

We worked closely with UKHSA to turn their existing workflow into a more streamlined system.

Regular feedback shaped the design and helped us stay aligned with the client's requirements.

We began by understanding the existing access process and the issues UKHSA wanted the new system to solve. We mapped out the journey from submitting an access request through to approval and database updates, then used this to define the core features and workflow of the portal. Throughout development, we held weekly Zoom meetings with the UKHSA clients to demonstrate progress, discuss requirements, gather feedback, and make changes based on their priorities. We iterated on both the user interface and underlying workflow, particularly around automatic approval for non-sensitive datasets and a dedicated dashboard for sensitive requests requiring human approval. This regular collaboration helped us build the solution around the client's actual process rather than making assumptions about how the system should work.

Flight Departures dataset table with 150 rows of granted data
Flight Departures dataset table with a destination cell tooltip open

Solution

A single system that takes a data access request from submission to decision.

We combined a streamlined workflow with an accessible, familiar interface.

The full access process now runs through one web application. Users log in, submit requests, select datasets and access types, confirm their training, and track request status, with no separate surveys or manual CSV uploads required. A rules engine handles non-sensitive datasets automatically, while sensitive requests are routed to an approver dashboard where they can be reviewed, approved, or rejected with a reason. The system then updates the relevant database records as part of the workflow. Alongside the functionality, we focused on making the portal straightforward to use and appropriate for a government-facing environment. We introduced dark and light themes, used a colour palette influenced by the GOV.UK design language, and built consistent CSS components across forms, dashboards, tables, and approval screens. The result was a solution that addressed both the underlying process problems and the usability of the people interacting with it.

Antenatal Screening dataset table showing status, sensitivity, row count, and add/save row controls

Outcome

We delivered the complete solution and demonstrated it directly to the UKHSA team.

The final product met the requested specification and extended beyond the original requirements.

We completed the portal and demonstrated the finished product to the UKHSA clients, walking them through the full access request and approval workflow. The system met all of the specifications provided to us, including automated handling of non-sensitive requests, approval workflows for sensitive datasets, and centralised management of access. We also went beyond the initial requirements by implementing additional security features such as email and phone number verification. The clients were happy with the final result, and the project gave us practical experience of working with a real client, responding to feedback, and delivering against a detailed set of requirements.