Use the Security tab to assign users to roles and manage permissions, ensuring that only authorized users can perform specific actions.
The Security tab is a centralized interface for managing users, user groups, security policies, and roles. It ensures that users are assigned to the appropriate roles and have only the permissions required to perform their actions. Best practices:
- Define clear roles and responsibilities: Create roles based on the tasks users perform, ensuring users only have access to resources necessary for their role.
- Use Role-Based Access Control (RBAC): Assign roles with predefined permissions to users rather than assigning permissions directly to individual users. This simplifies management and ensures consistency.
- Create logical user groups: Group users based on their roles and responsibilities. This simplifies permission management and policy application.
- Implement strong authentication methods: Require strong, complex passwords and enforce regular password changes.
- Conduct regular audits and reviews: Audit user access, roles, and security policies to ensure compliance and identify potential security gaps.
Note:
- You must have View permission to access the relevant tabs in Security. To modify details, you must have Manage permission or other required write permissions.
- Policy-based role assignment: For custom user groups, roles are assigned through security policies. Assigning user groups and users to custom roles is also managed through security policies.
- Apply least-privilege access: Grant only the minimum permissions required for each role.
- View is read-only and does not allow modifications.
- Manage allows configuration changes but may still be restricted by separate permissions.
- For Technical Assets and Business Assets, Delete is explicitly separate from Manage and must be granted independently.
- Operate is intended for runtime operational tasks and should be assigned only to users responsible for operational workloads.
- Use group-based role assignment through security policies to improve consistency and reduce direct per-user permission drift.
- Review role assignments regularly to remove stale or excessive access.
The following table lists feature-level permissions and supported actions:
| Feature | Permission | Actions |
|---|---|---|
| Agent | View | View agent details. |
| Manage | Create new agent; edit agent details; delete agent. | |
| Business Asset | View | View assets and assignments. |
| Manage | Create and edit assets; create and manage assignments. | |
| Delete | Delete assets. | |
| Catalog | View | View details of cataloged fields and datasets; view technical asset details; view cataloged jobs. |
| Profile | View profiling details associated with datasets and fields. | |
| Metrics | View scores and measurements about your data. | |
| Catalog Meta Model | View | View assets cataloged in the workspace. |
| Manage | Edit details of cataloged assets. | |
| Data Profile | View | View data profiles and associated details. |
| Manage | Create new data profiles; edit existing profiles; modify profile details. | |
| Operate | Run profile manually; stop a data profile run. | |
| Data Sample | View | View generated data samples in pipelines and rules. |
| Manage | Delete generated samples; regenerate samples. | |
| Datasource | View | View details of datasources added to the workspace. |
| Manage | Edit datasource details; delete datasource from workspace. | |
| Observer | View | View details of created observers. |
| Manage | Create new observers; edit existing observer details. | |
| Quality Pipeline | View | View details of created quality pipelines. |
| Manage | Create new pipelines; delete pipelines; rename pipelines; duplicate pipelines. | |
| Operate | Add transformation steps; create pipeline engine; create run configuration; run the pipeline. | |
| Relationships | View | View existing relationships. |
| Manage | Create relationship type; edit existing relationships; delete existing relationships. | |
| Replication Pipeline | View | View details of created replication pipelines. |
| Manage | Add new projects to replication pipeline; edit replication pipelines; delete replication pipelines. | |
| Operate | Add new projects to replication pipeline; edit replication pipelines; delete replication pipelines; apply configurations to pipeline. | |
| Role | View | View existing roles and permissions. |
| Manage | Edit existing roles by adding or removing users; create custom roles; modify/delete custom rules. | |
| Rules and Scores | View | View default and custom rules; view generated data quality scores. |
| Manage | Create, edit, delete, or duplicate rules; enable and disable scheduled rule runs. | |
| Operate | Manually trigger rule runs. | |
| Runtime Engine | View | View pipeline engines created in the workspace. |
| Manage | Create new pipeline engines; edit existing pipeline engines; delete existing pipeline engines. | |
| Security Policy | View | View security policies created in the application. |
| Manage | Create custom security policies; technical assets permission; edit and duplicate default security policies by assigning users or user groups; enable or disable security policy; delete security policy. | |
| Technical Asset | View | View assets and assignments. |
| Manage | Create and edit assets; create and manage assignments. | |
| Delete | Delete assets. | |
| User | View | View user details. |
| Manage | Edit user details; remove user. | |
| Invite | Invite a new user to the workspace. | |
| User Group | View | View user groups created in the application. |
| Manage | Edit user group; duplicate user group; create custom user group. | |
| Workflow | View | View details of workflows created in the application. |
| Manage | Create new workflows; create assignments and requests; delete existing workflows. | |
| Workspace | Manage | Access and modify profile information; view subscription details; access usage details; generate and manage API keys; view and access instructions to download supported data products. |