Catalog authorization
Overview
Before V5.0, data permissions in the data development environment had two major pain points:
- First, although the IDE module and ETL data warehouse of each data development workspace were allocated independently, the range of data source catalogs they could query was exactly the same, with no visibility isolation mechanism;
- Second, because workspaces and projects share the same ETL data warehouse, when customers mounted their own data sources to query engines such as Trino/StarRocks, fine-grained data permission control for different business scenarios or user roles wasn't possible. This blurred data security boundaries and made it difficult to meet enterprises' needs for tiered, segregated management of sensitive data.
To address this, we provide system-level data visibility control: Through system-level, platform-based configuration, admins can flexibly control the range of data sources that each workspace or project can access via direct connection, achieving precise authorization and secure isolation of data visibility while keeping data sharing efficient.
Core concepts & entities
The basic model of data authorization is granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".
| Definition | Description |
|---|---|
Resource Group | The authorizable resource scope of Warehouse Management - Catalog is all database and table assets under the selected warehouse (including all catalogs), and a resource group definition must declare its resource scope. |
| Auth space |
|
| (Authorized) entity | In permission management and system design, an Authorized Entity (Authorization Subject) is the entity that is granted access permissions. It can be either active or passive, depending on the context and system design. In Warehouse Management, the authorized entities are: workspaces and projects (in progress) |
| Permission type |
|
| Auth Strategy | An instance of an authorization action |
How-to guide
In System Settings > Warehouse Management > Catalog Authorization, you can batch-authorize the data catalogs (Catalog) that different data development workspaces or projects can access, achieving system-level isolation of data sources.
Authorize by catalog
Catalog Authorization offers two views. The first is Authorize By Catalog, whose primary view is the catalogs under the warehouse.
When you select the name of the catalog you want to authorize, you can see the full list of entities that can be granted permissions on that catalog.
Then click the edit ✍️ pencil in the action column of the entity to authorize to grant that entity the corresponding permissions on all DBs under the catalog.
Permission type
| Definition | (Authorized) entity | Permission category | Description | Reference |
|---|---|---|---|---|
Warehouse Management - Catalog Authorization |
| Merges the basic permission types into four
| These four permissions are cumulative, i.e.
| System Settings - Data Authority - Catalog Authorization |
Catalog authorization scope
| Authorization scope | Description |
|---|---|
| Full Catalog |
|
| Specified DB |
|
| No authorization |
|
| Default |
|
Authorize by entity
The second authorization method is Authorize By Entity, whose primary view is the authorized entity.
Click an entity name to expand the names of all catalogs under the warehouse that can be granted permissions. You can customize the permission scope that each Catalog grants to that entity.
Batch edit authorization relationships
To batch add, delete, or modify the relationships between catalogs and authorized entities, click Authorization in the upper-right corner of the page.
For example, select Authorize By Catalog. On the edit page, switch to Add by Database on the right side of the catalog, and you can batch-authorize the two databases a and b under catalog hive to the two spaces default and demo.
After you save, the updated authorization policy takes effect. Note: Saving without selecting any permissions resets or deletes this authorization relationship (the page prompts No permissions are currently configured. Saving will reset/delete this authorization relationship).

