Security policies are rules that you define for selected data assets, user groups, and users. Use them to create and assign roles to users and groups.
- Default security policies: Default security policies are created in the workspace and assigned predefined user groups and roles. You cannot delete these policies, but you can enable or disable them.
- Custom security policies: Custom security policies are created by users. Create them by selecting assets, user groups, and associated roles.
Go to . The Policies page displays the following details for each policy:
- Status: Whether the security policy is enabled or disabled.
- Security Policy: The name of the security policy.
- Type: Whether it is a default or custom policy.
- User Groups: The number of user groups associated with the policy.
- Users: The number of users assigned to the policy.
- Roles: The number of roles assigned to the policy.
- Last Updated: When the security policy was last updated.
- Last Updated By: The user who last updated the security policy.
Use the context menu next to the policy name to perform the following actions.
- To enable a security policy, select Enable and confirm in the Enable Security Policy dialog.
- To disable a security policy, select Disable and confirm in the Disable Security Policy dialog. Disabling pauses permissions for all assigned users and user groups.
-
To edit a security policy, select Edit. On the Edit Security Policy page, update assigned roles, users, user groups, or targeted assets.
- Click Assign Roles to add new roles to the policy.
- To edit assigned roles and associated user groups, click the ellipsis next to the role and select Edit.
- In the Edit Role Assignment window, modify the assigned roles.
- Click Save to apply changes to the roles.
- In the Target assets section, change or modify existing conditions.
- Click Save.
Note: Changing the criteria to select target assets resets all previously defined conditions. - To delete a security policy, select Delete and confirm in the Delete Security Policy dialog.
- To duplicate a security policy, click the ellipsis next to
the policy name and select Duplicate.
- For a default policy, confirm in the Duplicate Security Policy dialog.
- For a custom policy, update details on the Create Security Policy page and click Create.
View default security policies
The following table lists each default policy, its description, associated user groups, and assigned roles.
| Policy | Description | User Group | Role |
|---|---|---|---|
| Catalog Management | Configure catalog and governance settings. | Catalog Managers |
Data Steward |
| Connection Management | Manage connections to external resources, such as data sources and LLMs. | Connection Managers |
Agent Manager |
| Agent Managers | Agent Manager | ||
| Datasource Managers | Datasource Manager | ||
| Designers | Create, edit, and delete configurations across all resource types. | Designers |
Business Owner |
| Replication Designers | Replication Designer | ||
| Observability Designers | Quality Designer | ||
| Quality Designers | Quality Designer | ||
| Operators | Start and stop quality and replication pipelines. | Operators |
Quality Designer |
| Quality Operators | Quality Operator | ||
| Replication Operators | Replication Operator | ||
| Observability Viewers | Catalog Viewer | ||
| Workspace Management | Manage workspace settings including security policies, users, data sources, governance, and the catalog. | Workspace Managers and Workspace Owners |
Workspace Manager |
| Workspace Admin | Workspace Manager | ||
| Workspace Owner | Workspace Manager |
Configure custom security policy
To create a custom security policy:
- Click Create Security Policy.
- Enter the policy name and any other required information. The Description field is optional.
- In the assignment pane, select Assign Roles, then select a role from the drop-down list.
- Select the users or user groups to associate with the policy.
- Use the arrows to move selected users or groups to the Selected Groups and Users pane.
- In the selected items table, select a user or group to view its assigned roles, groups, and users.
- Verify the entries in the table. Groups are tagged; individual users appear without a tag.
- Select Assign to add the selected users and user groups to the policy.
- Define the asset targeting settings. You can apply the policy to All assets or target Assets by condition.
- Select Preview to review the assets targeted by the policy.
- Select the Propagate to all descendants checkbox to apply the security policy to all assets and their child assets. For example, if the policy is applied to the host datasource, it is also inherited by the underlying database and schema.
- Select Create to save the policy.
Conditions to select assets in security policies
- The condition builder updates each row based on earlier selections, making it easier to create precise targeting rules and add multiple condition groups when needed.
- The system populates each additional condition row based on earlier conditions, helping you build more precise targeting logic.
- You can review the policy in the preview step before you create it.
The initial filter includes the following values:
- Asset class: A core category that groups similar assets in Data Integrity Suite. It organizes assets for easier management, search, and governance.
- Asset type: A template that defines how assets are categorized and managed in Data Integrity Suite. It determines what information is captured, how it is organized, and which rules apply.
- Domain: A logical grouping of related data assets that represents a business capability. It organizes business and technical assets into a manageable structure.
- Owner Group: A group of users collectively responsible for managing data domains and related assets.
- Owner User: A user assigned workspace owner permissions.