Skip to main content

Data authorization

Last updated 10/05/2026

Overview​

Data warehouse processing produces many intermediate tables that aren't suitable for business use, and exposing all of them makes it harder for the business side to choose tables. Many projects also need fine-grained control over data permissions (at the database and table level).

With the data authorization capability of the DataOps Platform, data developers can authorize assets in a space, such as space databases, tables, and views, for use by the project domain or other space domains. Authorized projects can use these resources in BI dashboards and Model Mapping Assets Configuration, and authorized spaces can use the authorized assets for further development in their own space domain.

  • Project Authorization is the prerequisite
  • Data Authorization is application-layer control
  • Role Permissions control the feature permissions that correspond to account roles
DefinitionAuthorizing partyAuthorized EntityPermission categoryDescription
Space - Project Authorization

Space

Project

  • Allow supply and use
  • Allow use
  • No authorization
  • "Supply": Assets processed in the workspace can be supplied to the selected project for use
  • "Use": The workspace can use assets in the selected project for processing
Data Authorization

Space A

Project

Space B

  • Data query
  • Resource meta query
  • Sub-level list query
  • Data assets in Space A, such as databases, tables, and views, can be authorized to a project for use
  • Databases, tables, views, and other assets in Space A can be authorized to Space B, so they are visible in the IDE of Space B and can be queried & used
Role PermissionsRole ARole B
  • View
  • Edit
  • Feature usage
  • Role Permissions define the roles related to workspaces and the feature permissions of each role
  • Permission control over specific roles' use of features on specific assets will be refined later

Core concepts & entities​

The basic model of data authorization is granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".

DefinitionDescription

Resource Group

The scope of authorizable resources is the online assets of a space, and a resource group definition must declare its resource scope.

  • Tables
  • Assets
Auth space
  • An auth space is an independent space where content groups and their permission rules are configured
  • When the data permission service processes an auth request, it first confirms which space the auth request belongs to, and then checks permissions
Authorized Entity

In permission management and system design, an Authorized Entity (Authorization Subject) is the entity that is granted access permissions. It can be either active or passive, depending on the context and system design.

Here, it is the authorized project or another workspace.

(Authorized) entityProject, workspace
Permission type

Workspace - Authorization only involves:

  • Metadata query meta
  • List query list
  • Read Query
Auth StrategyAn instance of an authorization action

Resource groups​

What is a workspace resource group​

  • The scope of authorizable resources is the online assets of a space, and a resource group definition must declare its resource scope.
  • The resource scope includes these entities: database (db), table, Link View
WarehouseCatalogDatabasedb

Built-in ETL Warehouse

HiveProduction environment database (online)hive.ws_xxxx_product
IDE databasehive.ws_xxxx_ide

Note ⚠️: Dev environment databases can't be authorized externally

Workspace resource group types​

  • Each space has built-in resource groups, and you can also create custom resource groups
Resource group typeDefinitiondb
Built-in resource group

All in space

hive.ws_xxxx_product

hive.ws_xxxx_ide

Production tableshive.ws_xxxx_product
IDE tableshive.ws_xxxx_ide
Custom resource group

Two definition methods

  • Table enumeration
  • Table name regex condition

Create a resource group​

Click + Resource Group in the upper-right corner to open the resource group creation page

Definition methodMethodDescription
Specify tableDirectly select a set of individual tables
  • Database type options: Task Database, IDE Database, All
  • Tables include all space tables and view tables under the database
  • Supports Refresh and Search table name
RegEx

Write a regular expression to match the space tables that meet the rule

  • Supports inserting "Task Databases" and "IDE Databases" to write regex rules
  • Lookup shows all matched tables
  • You can configure multiple Conditions on separate lines
Specify table
RegEx

After a resource group is saved, a quick link takes you to the Authorization page

Edit a resource group​

Click the edit icon in the resource group management list to open the resource group edit page

Resource group categoryEditable itemsNon-editable items
Built-in resource group/
  • Nothing is editable
Custom resource group
  • Resource group name
  • Specified databases and tables
  • Resource group code (built-in)

Delete a resource group​

Deletion methodResource group categoryDeletion action
Active deletionBuilt-in resource groupCan't be deleted
Custom resource groupDeleting a resource group also deletes its auth strategies; remind the user
Passive deletion/When a space is deleted, its resource groups are deleted and can't be recovered

Auth Strategy​

note

Granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".

Grant "XXX project" the query permission on "production tables and IDE tables"

Create Resource Group and Authorization are two consecutive, independent actions.

Auth types​

By default, every Authorized Entity granted permissions by a space has meta, list, query permissions.

Permission typeIncluded permissionsDefault strategy

Metadata query

meta

  • desc
  • show create xxx

Allowed

Sub-level list query

list

  • show xxx
Allowed

Read

query

  • select
Allowed

Scope of authorized entities​

A space can set authorization separately for each project. There are three permission levels:

PermissionsDescription
Allow supply and use
  • "Supply": Assets processed in the workspace can be supplied to the selected project for use
  • "Use": The workspace can use assets in the selected project for processing
Allow use
  • "Use only": The workspace can only use assets in the project for processing
No authorizationAssets processed in the workspace are not yet authorized for use by the project

Therefore, a workspace can grant data permissions to a project only if the project has the "supply" permission.

Add authorization​

Method 1: Configure on a resource group​

Authorization configured on a Resource Group has a stable structure and belongs exclusively to the current resource group.

Open the Configure Authorization details page, where only Auth Method = Authorize the resource group is available. When you save, a dialog asks you to confirm Adding X new auth strategies

Method 2: Configure from the public navigation​

Click Authorization in the upper-right corner

Open the Configure Authorization details page, where you can configure authorization from two perspectives: Grant authority to entity and Authorize the resource group.

Edit auth strategies​

note
  • A resource group can be authorized to multiple different entities, producing multiple auth strategies
  • For enabled strategies, the definition of the associated resource group can still be changed
  • If the authorization configuration of a strategy's associated resource group changes, strategies are added or deleted accordingly
ActionTrigger methodDescription
Add strategy

Manual addition

Auth strategies added by manually adding an Authorization
Editing the authorization of a Resource Group grants authorization to some new authorized entities

Delete strategy

Active deletion

Manually delete a strategy in the Action column, or batch delete strategies

  • After deletion, the Authorized Entity associated with the resource group changes accordingly
Passive deletion

Editing the authorization of a Resource Group revokes authorization from some authorized entities

  • Strategies related to those authorized entities are deleted at the same time

Project deleted: The authorized entity (project) is deleted from the system

  • Strategies related to the authorized entity are deleted at the same time

Space deleted: All assets in the space are deleted

Enable/disable strategyActive enablingA strategy is Enabled by default once it's created successfully
Active disablingManually disable a strategy in the Action column

Passive disabling

Project's "supply" permission revoked: The strategy is Disabled

Project deleted: The authorized entity (project) is deleted from the system, and the strategy is disabled and deleted

Auth strategy management list​

Auth Tool​

The Data Authorization module provides a quick auth tool to help you identify the permission scope of assets.

note

Query:

  1. Which resource groups is the currently selected Resource in?
  2. Does the currently selected Resource have permission in a given space/project?
Was this page helpful?