Skip to main content

Catalog authorization

Last updated 10/03/2026

Overview​

Before V5.0, data permissions in the data development environment had two major pain points:

  • First, although the IDE module and ETL data warehouse of each data development workspace were allocated independently, the range of data source catalogs they could query was exactly the same, with no visibility isolation mechanism;
  • Second, because workspaces and projects share the same ETL data warehouse, when customers mounted their own data sources to query engines such as Trino/StarRocks, fine-grained data permission control for different business scenarios or user roles wasn't possible. This blurred data security boundaries and made it difficult to meet enterprises' needs for tiered, segregated management of sensitive data.

To address this, we provide system-level data visibility control: Through system-level, platform-based configuration, admins can flexibly control the range of data sources that each workspace or project can access via direct connection, achieving precise authorization and secure isolation of data visibility while keeping data sharing efficient.

Core concepts & entities​

The basic model of data authorization is granting "related permissions" on "content resources" to "authorization targets" in "a given scenario".

DefinitionDescription

Resource Group

The authorizable resource scope of Warehouse Management - Catalog is all database and table assets under the selected warehouse (including all catalogs), and a resource group definition must declare its resource scope.
Auth space
  • An auth space is an independent space where content groups and their permission rules are configured
  • When the data permission service processes an auth request, it first confirms which space the auth request belongs to, and then checks permissions
  • Currently, the auth spaces in the DataOps Platform are projects and workspaces.
(Authorized) entity

In permission management and system design, an Authorized Entity (Authorization Subject) is the entity that is granted access permissions. It can be either active or passive, depending on the context and system design.

In Warehouse Management, the authorized entities are: workspaces and projects (in progress)

Permission type
  • Metadata query meta,
  • List query list,
  • Management DDL,
  • Read Query,
  • Write DML,
  • Delete Drop
Auth StrategyAn instance of an authorization action

How-to guide​

In System Settings > Warehouse Management > Catalog Authorization, you can batch-authorize the data catalogs (Catalog) that different data development workspaces or projects can access, achieving system-level isolation of data sources.

Authorize by catalog​

Catalog Authorization offers two views. The first is Authorize By Catalog, whose primary view is the catalogs under the warehouse.

When you select the name of the catalog you want to authorize, you can see the full list of entities that can be granted permissions on that catalog.

Then click the edit ✍️ pencil in the action column of the entity to authorize to grant that entity the corresponding permissions on all DBs under the catalog.

Permission type​

Definition(Authorized) entityPermission categoryDescriptionReference

Warehouse Management - Catalog Authorization

  • Workspace
  • Project (future)

Merges the basic permission types into four

  • Read (Meta, Query, list)
  • Write (DML)
  • Create/Alter (DDL)
  • Delete (Drop)

These four permissions are cumulative, i.e.

  • Having Write permission always includes Read permission
  • Having Create/Alter permission always includes Read and Write permissions
  • Having Delete permission always includes all permissions
System Settings - Data Authority - Catalog Authorization

Catalog authorization scope​

Authorization scopeDescription
Full Catalog
  • Authorizes the catalog, its child DBs, and their child tables
Specified DB
  • Requires you to further select DBs; authorizes the selected DBs and their child tables
No authorization
  • Doesn't authorize the catalog, its child DBs, or their child tables
  • When the default policy for the permission type of the auth space is deny, data can't be queried without authorization; when the default policy is allow, data can be queried without authorization
Default
  • For the "AE System" catalog, the features corresponding to its child resources already have authorizations, which are handled by the system by default and can't be changed in the UI. For example, under the hive catalog, authorization for space DBs is handled by the system.

Authorize by entity​

The second authorization method is Authorize By Entity, whose primary view is the authorized entity.

Click an entity name to expand the names of all catalogs under the warehouse that can be granted permissions. You can customize the permission scope that each Catalog grants to that entity.

Batch edit authorization relationships​

To batch add, delete, or modify the relationships between catalogs and authorized entities, click Authorization in the upper-right corner of the page.

For example, select Authorize By Catalog. On the edit page, switch to Add by Database on the right side of the catalog, and you can batch-authorize the two databases a and b under catalog hive to the two spaces default and demo.

After you save, the updated authorization policy takes effect. Note: Saving without selecting any permissions resets or deletes this authorization relationship (the page prompts No permissions are currently configured. Saving will reset/delete this authorization relationship).

Was this page helpful?