Data access is arranged through systems you own. We use named users, time-limited access and the least privilege that still lets us extract what the pack needs. We do not copy the ledger to a machine we keep. Working files live in your tenancy or in a shared space you control. When a spreadsheet is still the right tool, it is built so a refresh is a sequence of steps, not a feat of memory.
Model structure is agreed before the first large sheet is locked: entities, currencies, the chart mapping, and the cuts the commercial views will need. Review cycles are short. Your finance lead sees a working file early enough to object to a definition while it is still cheap to change. We run at least one live month through the new pack or forecast and reconcile it to the ledger before we treat the build as complete.
If the data cannot support a view you wanted, we say so in the review and we cut the view rather than invent a figure. That conversation is easier in week three than in week ten.