Data authorization
Overview
Data warehouse processing produces many intermediate tables that aren't suitable for business use, and exposing all of them makes it harder for the business side to choose tables. Many projects also need fine-grained control over data permissions (at the database and table level).
With the data authorization capability of the DataOps Platform, data developers can authorize assets in a space, such as space databases, tables, and views, for use by the project domain or other space domains. Authorized projects can use these resources in BI dashboards and Model Mapping Assets Configuration, and authorized spaces can use the authorized assets for further development in their own space domain.
Permission-related definitions
- Project Authorization is the prerequisite
- Data Authorization is application-layer control
- Role Permissions control the feature permissions that correspond to account roles
| Definition | Authorizing party | Authorized Entity | Permission category | Description |
|---|---|---|---|---|
| Space - Project Authorization | Space | Project |
|
|
| Data Authorization | Space A | Project Space B |
|
|
| Role Permissions | Role A | Role B |
|
|
Core concepts & entities
The basic model of data authorization is granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".
| Definition | Description |
|---|---|
Resource Group | The scope of authorizable resources is the online assets of a space, and a resource group definition must declare its resource scope.
|
| Auth space |
|
| Authorized Entity | In permission management and system design, an Authorized Entity (Authorization Subject) is the entity that is granted access permissions. It can be either active or passive, depending on the context and system design. Here, it is the authorized project or another workspace. |
| (Authorized) entity | Project, workspace |
| Permission type | Workspace - Authorization only involves:
|
| Auth Strategy | An instance of an authorization action |
Resource groups
What is a workspace resource group
- The scope of authorizable resources is the online assets of a space, and a resource group definition must declare its resource scope.
- The resource scope includes these entities: database (db), table, Link View
| Warehouse | Catalog | Database | db |
|---|---|---|---|
Built-in ETL Warehouse | Hive | Production environment database (online) | hive.ws_xxxx_product |
| IDE database | hive.ws_xxxx_ide |
Note ⚠️: Dev environment databases can't be authorized externally
Workspace resource group types
- Each space has built-in resource groups, and you can also create custom resource groups
| Resource group type | Definition | db |
|---|---|---|
| Built-in resource group | All in space |
|
| Production tables | hive.ws_xxxx_product | |
| IDE tables | hive.ws_xxxx_ide | |
| Custom resource group | Two definition methods
|
Create a resource group
Click + Resource Group in the upper-right corner to open the resource group creation page
| Definition method | Method | Description |
|---|---|---|
| Specify table | Directly select a set of individual tables |
|
| RegEx | Write a regular expression to match the space tables that meet the rule |
|
After a resource group is saved, a quick link takes you to the Authorization page
Edit a resource group
Click the edit icon in the resource group management list to open the resource group edit page
| Resource group category | Editable items | Non-editable items |
|---|---|---|
| Built-in resource group | / |
|
| Custom resource group |
|
|
Delete a resource group
| Deletion method | Resource group category | Deletion action |
|---|---|---|
| Active deletion | Built-in resource group | Can't be deleted |
| Custom resource group | Deleting a resource group also deletes its auth strategies; remind the user | |
| Passive deletion | / | When a space is deleted, its resource groups are deleted and can't be recovered |
Auth Strategy
Granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".
Grant "XXX project" the query permission on "production tables and IDE tables"
Create Resource Group and Authorization are two consecutive, independent actions.
Auth types
By default, every Authorized Entity granted permissions by a space has meta, list, query permissions.
| Permission type | Included permissions | Default strategy |
Metadata query meta |
| Allowed |
Sub-level list query list |
| Allowed |
Read query |
| Allowed |
Scope of authorized entities
A space can set authorization separately for each project. There are three permission levels:
| Permissions | Description |
|---|---|
| Allow supply and use |
|
| Allow use |
|
| No authorization | Assets processed in the workspace are not yet authorized for use by the project |
Therefore, a workspace can grant data permissions to a project only if the project has the "supply" permission.
Add authorization
Method 1: Configure on a resource group
Authorization configured on a Resource Group has a stable structure and belongs exclusively to the current resource group.
Open the Configure Authorization details page, where only Auth Method = Authorize the resource group is available. When you save, a dialog asks you to confirm Adding X new auth strategies
Method 2: Configure from the public navigation
Click Authorization in the upper-right corner
Open the Configure Authorization details page, where you can configure authorization from two perspectives: Grant authority to entity and Authorize the resource group.
Edit auth strategies
- A resource group can be authorized to multiple different entities, producing multiple auth strategies
- For enabled strategies, the definition of the associated resource group can still be changed
- If the authorization configuration of a strategy's associated resource group changes, strategies are added or deleted accordingly
| Action | Trigger method | Description |
|---|---|---|
| Add strategy | Manual addition | Auth strategies added by manually adding an Authorization |
| Editing the authorization of a Resource Group grants authorization to some new authorized entities | ||
Delete strategy | Active deletion | Manually delete a strategy in the Action column, or batch delete strategies
|
| Passive deletion | Editing the authorization of a Resource Group revokes authorization from some authorized entities
| |
Project deleted: The authorized entity (project) is deleted from the system
Space deleted: All assets in the space are deleted | ||
| Enable/disable strategy | Active enabling | A strategy is Enabled by default once it's created successfully |
| Active disabling | Manually disable a strategy in the Action column | |
Passive disabling | Project's "supply" permission revoked: The strategy is Disabled Project deleted: The authorized entity (project) is deleted from the system, and the strategy is disabled and deleted |
Auth strategy management list
Auth Tool
The Data Authorization module provides a quick auth tool to help you identify the permission scope of assets.
Query:
- Which resource groups is the currently selected Resource in?
- Does the currently selected Resource have permission in a given space/project?

