Access Control

Overview

Sifflet offers an access management system that lets you customize the level at which you control access to your resources.

Role-Based Access Control

Sifflet relies on role-based access control to ensure that only authorized individuals can access specific resources or perform specific actions. You can assign roles to both users and tokens.

User roles vary based on the domain, resulting in differing permissions for resources across various domains and platform configurations. Sifflet classifies resources into two distinct types:

  1. Domain resources: These include items such as catalog and lineage assets, monitors, incidents, and their related dashboards. Typically, domain resources are grouped into domains to mirror a specific business area (such as Finance, Operations, etc.) or team (Data Engineering, Data Stewards, etc.). For more details, see Domains.
  2. System resources: These resources, not tied to any specific domain, are used for platform administration. They include Users, Authentication Settings, Tags, Data Sources management, Domains management, and Glossary.

Every Sifflet user receives a system role and one or more domain roles based on the number of domains they are associated with.

📘

Domain "All"

In case there are no domains defined on the platform, all users default to the "All" domain. Sifflet enforces the domain role across all the data assets connected to the platform.

System Role

System roles define the type of access the user has to a given setting resource. Typically, these roles provide the user the right to create, edit, and delete a resource.

By default, Sifflet offers three system roles: Admin, System Editor and System Viewer.

System ResourceActionsAdminSystem EditorSystem Viewer
Integrations
Integrations managementread, create, edit, delete, trigger run✅✅❌
Credentialsread name and description, use in source✅✅❌
Credentialscreate, edit, delete✅❌❌
Glossary
Termsread✅✅✅
Termscreate, edit, delete✅✅❌
Settings
Tagsread✅✅✅
Tagscreate, edit, delete✅✅❌
Domainsread, create, edit, delete✅❌❌
Usersread, create, edit, delete✅❌❌
Access Tokensread, create, delete✅❌❌
Single Sign-On (SSO)read, create, edit, delete✅❌❌
Collaboration Tools connectionscreate, edit, delete✅❌❌
Collaboration tools configurations (templates, webhooks, channels, etc.)read, create, edit, delete✅✅❌
Tenant Preferencesread, create, edit, delete✅❌❌
Teamsread, create, edit, delete✅❌❌
Workspaceread, create, edit, delete✅❌❌
Custom Metadataread, create, edit, delete✅❌❌
AI settingsactivate, deactivate✅❌❌
Notification rulesread, create, edit, delete✅❌❌

Domain Role

Domain roles define the type of access the user has to a given domain resource. By default, Sifflet offers four domain roles: Domain Editor, Monitor Responder, Catalog Editor, and Domain Viewer.

Domain resourceActionDomain EditorMonitor ResponderCatalog EditorDomain Viewer
Data Catalog
Data assetssearch through the catalog✅✅✅✅
Data assetsread✅✅✅✅
Data assetscreate metadata, edit metadata, delete metadata, generate metadata✅❌✅❌
Data assetspreview data✅❌✅❌
Monitors
Monitorsread (overview, runs details, parameters details)✅✅✅✅
Monitorscreate, edit, delete, run✅❌❌❌
Monitorsshow failing rows✅✅❌❌
Monitorsqualify runs for machine learning (ML) model feedback✅✅❌❌
Incidents
Incidentsassign, status update, close✅✅❌❌
Notifications
Notification rulescreate, edit, delete✅❌❌❌
Notification rulesread✅✅✅✅
Data products
Data productscreate, edit, delete✅❌❌❌
Data productsread✅✅✅✅
📘

Multiple Domain Access

You can associate a user with multiple domains: for example, a user can be a Domain Viewer in Domain A and a Domain Editor in Domain B.

Token Roles

Access Tokens allow you to programmatically interact with Sifflet objects through the API, CLI and Airflow Operator.

By default, Sifflet offers three token roles: Admin, Editor, Viewer:

ResourceActionAdminEditorViewer
Data Catalog
Data assetssearch through the catalog✅✅✅
Data assetsread✅✅✅
Data assetsdata preview✅✅❌
Data assetsmetadata edit (manual or through AI suggestions)✅✅❌
Monitors
Monitorread (overview, runs details, parameters details)✅✅❌
Monitorcreate, edit, delete, run✅✅❌
Monitorshow failing rows✅✅❌
Monitorqualify runs for machine learning (ML) model feedback✅✅❌
Incidents
Incidentsassign, status update, close✅✅❌
Glossary
Termsread✅✅✅
Termscreate, edit, delete✅✅❌
Integrations
Secrets managementread, create, edit, delete✅❌❌
Integrations managementcreate, edit, delete, trigger run✅✅❌
Integrations managementSubmit dbt metadata files and trigger the related data source refresh✅✅❌
Integrations managementCreate declarative pipeline & edge lineage✅❌❌
Settings
Tagsread✅✅✅
Tagscreate, edit, delete✅✅❌
Domainsread, create, edit, delete✅❌❌
Usersread, create, edit, delete✅❌❌
Access Tokensread, create, delete✅❌❌
Single Sign-On (SSO)read, create, edit, delete✅❌❌
Collaboration Toolsread, create, edit, delete✅❌❌
Account Preferencesread, create, edit, delete✅❌❌
Teamsread, create, edit, delete✅❌❌
Workspaceread, create, edit, delete✅❌❌
Custom Metadataread, create, edit, delete✅❌❌

📘

You can also assign roles to the domains you want this token to apply to, using the same roles described in Domain Role.


Did this page help you?