Access Control
Overview
Sifflet offers an access management system that lets you customize the level at which you control access to your resources.
Role-Based Access Control
Sifflet relies on role-based access control to ensure that only authorized individuals can access specific resources or perform specific actions. You can assign roles to both users and tokens.
User roles vary based on the domain, resulting in differing permissions for resources across various domains and platform configurations. Sifflet classifies resources into two distinct types:
- Domain resources: These include items such as catalog and lineage assets, monitors, incidents, and their related dashboards. Typically, domain resources are grouped into domains to mirror a specific business area (such as Finance, Operations, etc.) or team (Data Engineering, Data Stewards, etc.). For more details, see Domains.
- System resources: These resources, not tied to any specific domain, are used for platform administration. They include Users, Authentication Settings, Tags, Data Sources management, Domains management, and Glossary.
Every Sifflet user receives a system role and one or more domain roles based on the number of domains they are associated with.
Domain "All"In case there are no domains defined on the platform, all users default to the "All" domain. Sifflet enforces the domain role across all the data assets connected to the platform.
System Role
System roles define the type of access the user has to a given setting resource. Typically, these roles provide the user the right to create, edit, and delete a resource.
By default, Sifflet offers three system roles: Admin, System Editor and System Viewer.
| System Resource | Actions | Admin | System Editor | System Viewer |
|---|---|---|---|---|
| Integrations | ||||
| Integrations management | read, create, edit, delete, trigger run | ✅ | ✅ | ❌ |
| Credentials | read name and description, use in source | ✅ | ✅ | ❌ |
| Credentials | create, edit, delete | ✅ | ❌ | ❌ |
| Glossary | ||||
| Terms | read | ✅ | ✅ | ✅ |
| Terms | create, edit, delete | ✅ | ✅ | ❌ |
| Settings | ||||
| Tags | read | ✅ | ✅ | ✅ |
| Tags | create, edit, delete | ✅ | ✅ | ❌ |
| Domains | read, create, edit, delete | ✅ | ❌ | ❌ |
| Users | read, create, edit, delete | ✅ | ❌ | ❌ |
| Access Tokens | read, create, delete | ✅ | ❌ | ❌ |
| Single Sign-On (SSO) | read, create, edit, delete | ✅ | ❌ | ❌ |
| Collaboration Tools connections | create, edit, delete | ✅ | ❌ | ❌ |
| Collaboration tools configurations (templates, webhooks, channels, etc.) | read, create, edit, delete | ✅ | ✅ | ❌ |
| Tenant Preferences | read, create, edit, delete | ✅ | ❌ | ❌ |
| Teams | read, create, edit, delete | ✅ | ❌ | ❌ |
| Workspace | read, create, edit, delete | ✅ | ❌ | ❌ |
| Custom Metadata | read, create, edit, delete | ✅ | ❌ | ❌ |
| AI settings | activate, deactivate | ✅ | ❌ | ❌ |
| Notification rules | read, create, edit, delete | ✅ | ❌ | ❌ |
Domain Role
Domain roles define the type of access the user has to a given domain resource. By default, Sifflet offers four domain roles: Domain Editor, Monitor Responder, Catalog Editor, and Domain Viewer.
| Domain resource | Action | Domain Editor | Monitor Responder | Catalog Editor | Domain Viewer |
|---|---|---|---|---|---|
| Data Catalog | |||||
| Data assets | search through the catalog | ✅ | ✅ | ✅ | ✅ |
| Data assets | read | ✅ | ✅ | ✅ | ✅ |
| Data assets | create metadata, edit metadata, delete metadata, generate metadata | ✅ | ❌ | ✅ | ❌ |
| Data assets | preview data | ✅ | ❌ | ✅ | ❌ |
| Monitors | |||||
| Monitors | read (overview, runs details, parameters details) | ✅ | ✅ | ✅ | ✅ |
| Monitors | create, edit, delete, run | ✅ | ❌ | ❌ | ❌ |
| Monitors | show failing rows | ✅ | ✅ | ❌ | ❌ |
| Monitors | qualify runs for machine learning (ML) model feedback | ✅ | ✅ | ❌ | ❌ |
| Incidents | |||||
| Incidents | assign, status update, close | ✅ | ✅ | ❌ | ❌ |
| Notifications | |||||
| Notification rules | create, edit, delete | ✅ | ❌ | ❌ | ❌ |
| Notification rules | read | ✅ | ✅ | ✅ | ✅ |
| Data products | |||||
| Data products | create, edit, delete | ✅ | ❌ | ❌ | ❌ |
| Data products | read | ✅ | ✅ | ✅ | ✅ |
Multiple Domain AccessYou can associate a user with multiple domains: for example, a user can be a Domain Viewer in Domain A and a Domain Editor in Domain B.
Token Roles
Access Tokens allow you to programmatically interact with Sifflet objects through the API, CLI and Airflow Operator.
By default, Sifflet offers three token roles: Admin, Editor, Viewer:
| Resource | Action | Admin | Editor | Viewer |
|---|---|---|---|---|
| Data Catalog | ||||
| Data assets | search through the catalog | ✅ | ✅ | ✅ |
| Data assets | read | ✅ | ✅ | ✅ |
| Data assets | data preview | ✅ | ✅ | ❌ |
| Data assets | metadata edit (manual or through AI suggestions) | ✅ | ✅ | ❌ |
| Monitors | ||||
| Monitor | read (overview, runs details, parameters details) | ✅ | ✅ | ❌ |
| Monitor | create, edit, delete, run | ✅ | ✅ | ❌ |
| Monitor | show failing rows | ✅ | ✅ | ❌ |
| Monitor | qualify runs for machine learning (ML) model feedback | ✅ | ✅ | ❌ |
| Incidents | ||||
| Incidents | assign, status update, close | ✅ | ✅ | ❌ |
| Glossary | ||||
| Terms | read | ✅ | ✅ | ✅ |
| Terms | create, edit, delete | ✅ | ✅ | ❌ |
| Integrations | ||||
| Secrets management | read, create, edit, delete | ✅ | ❌ | ❌ |
| Integrations management | create, edit, delete, trigger run | ✅ | ✅ | ❌ |
| Integrations management | Submit dbt metadata files and trigger the related data source refresh | ✅ | ✅ | ❌ |
| Integrations management | Create declarative pipeline & edge lineage | ✅ | ❌ | ❌ |
| Settings | ||||
| Tags | read | ✅ | ✅ | ✅ |
| Tags | create, edit, delete | ✅ | ✅ | ❌ |
| Domains | read, create, edit, delete | ✅ | ❌ | ❌ |
| Users | read, create, edit, delete | ✅ | ❌ | ❌ |
| Access Tokens | read, create, delete | ✅ | ❌ | ❌ |
| Single Sign-On (SSO) | read, create, edit, delete | ✅ | ❌ | ❌ |
| Collaboration Tools | read, create, edit, delete | ✅ | ❌ | ❌ |
| Account Preferences | read, create, edit, delete | ✅ | ❌ | ❌ |
| Teams | read, create, edit, delete | ✅ | ❌ | ❌ |
| Workspace | read, create, edit, delete | ✅ | ❌ | ❌ |
| Custom Metadata | read, create, edit, delete | ✅ | ❌ | ❌ |
You can also assign roles to the domains you want this token to apply to, using the same roles described in Domain Role.
Updated 5 days ago

