LogoLogo
  • Welcome to e6data
  • Introduction to e6data
    • Concepts
    • Architecture
      • e6data in VPC Deployment Model
      • Connect to e6data serverless compute
  • Get Started
  • Sign Up
  • Setup
    • AWS Setup
      • In VPC Deployment (AWS)
        • Prerequisite Infrastructure
        • Infrastructure & Permissions for e6data
        • Setup Kubernetes Components
        • Setup using Terraform in AWS
          • Update a AWS Terraform for your Workspace
        • AWS PrivateLink and e6data
        • VPC Peering | e6data on AWS
      • Connect to e6data serverless compute (AWS)
        • Workspace Creation
        • Catalog Creation
          • Glue Metastore
          • Hive Metastore
          • Unity Catalog
        • Cluster Creation
    • GCP Setup
      • In VPC Deployment (GCP)
        • Prerequisite Infrastructure
        • Infrastructure & Permissions for e6data
        • Setup Kubernetes Components
        • Setup using Terraform in GCP
        • Update a GCP Terraform for your Workspace
      • Connect to e6data serverless compute (GCP)
    • Azure Setup
      • Prerequisite Infrastructure
      • Infrastructure & Permissions for e6data
      • Setup Kubernetes Components
      • Setup using Terraform in AZURE
        • Update a AZURE Terraform for your Workspace
  • Workspaces
    • Create Workspaces
    • Enable/Disable Workspaces
    • Update a Workspace
    • Delete a Workspace
  • Catalogs
    • Create Catalogs
      • Hive Metastore
        • Connect to a Hive Metastore
        • Edit a Hive Metastore Connection
        • Delete a Hive Metastore Connection
      • Glue Metastore
        • Connect to a Glue Metastore
        • Edit a Glue Metastore Connection
        • Delete a Glue Metastore Connection
      • Unity Catalog
        • Connect to Unity Catalog
        • Edit Unity Catalog
        • Delete Unity Catalog
      • Cross-account Catalog Access
        • Configure Cross-account Catalog to Access AWS Hive Metastore
        • Configure Cross-account Catalog to Access Unity Catalog
        • Configure Cross-account Catalog to Access AWS Glue
        • Configure Cross-account Catalog to Access GCP Hive Metastore
    • Manage Catalogs
    • Privileges
      • Access Control
      • Column Masking
      • Row Filter
  • Clusters
    • Edit & Delete Clusters
    • Suspend & Resume Clusters
    • Cluster Size
    • Load Based Sizing
    • Auto Suspension
    • Query Timeout
    • Monitoring
    • Connection Info
  • Pools
    • Delete Pools
  • Query Editor
    • Editor Pane
    • Results Pane
    • Schema Explorer
    • Data Preview
  • Notebook
    • Editor Pane
    • Results Pane
    • Schema Explorer
    • Data Preview
  • Query History
    • Query Count API
  • Connectivity
    • IP Sets
    • Endpoints
    • Cloud Resources
    • Network Firewall
  • Access Control
    • Users
    • Groups
    • Roles
      • Permissions
      • Policies
    • Single Sign-On (SSO)
      • AWS SSO
      • Okta
      • Microsoft My Apps-SSO
      • Icons for IdP
    • Service Accounts
    • Multi-Factor Authentication (Beta)
  • Usage and Cost Management
  • Audit Log
  • User Settings
    • Profile
    • Personal Access Tokens (PAT)
  • Advanced Features
    • Cross-Catalog & Cross-Schema Querying
  • Supported Data Types
  • SQL Command Reference
    • Query Syntax
      • General functions
    • Aggregate Functions
    • Mathematical Functions & Operators
      • Arithematic Operators
      • Rounding and Truncation Functions
      • Exponential and Root Functions
      • Trigonometric Functions
      • Logarithmic Functions
    • String Functions
    • Date-Time Functions
      • Constant Functions
      • Conversion Functions
      • Date Truncate Function
      • Addition and Subtraction Functions
      • Extraction Functions
      • Format Functions
      • Timezone Functions
    • Conditional Expressions
    • Conversion Functions
    • Window Functions
    • Comparison Operators & Functions
    • Logical Operators
    • Statistical Functions
    • Bitwise Functions
    • Array Functions
    • Regular Expression Functions
    • Generate Functions
    • Cardinality Estimation Functions
    • JSON Functions
    • Checksum Functions
    • Unload Function (Copy into)
    • Struct Functions
  • Equivalent Functions & Operators
  • Connectors & Drivers
    • DBeaver
    • DbVisualiser
    • Apache Superset
    • Jupyter Notebook
    • Tableau Cloud
    • Tableau Desktop
    • Power BI
    • Metabase
    • Zeppelin
    • Python Connector
      • Code Samples
    • JDBC Driver
      • Code Samples
      • API Support
    • Configure Cluster Ingress
      • ALB Ingress in Kubernetes
      • GCE Ingress in Kubernetes
      • Ingress-Nginx in Kubernetes
  • Security & Trust
    • Best Practices
      • AWS Best Practices
    • Features & Responsibilities Matrix
    • Data Protection Addendum(DPA)
  • Tutorials and Best Practices
    • How to configure HIVE metastore if you don't have one?
    • How-To Videos
  • Known Limitations
    • SQL Limitations
    • Other Limitations
    • Restart Triggers
    • Cloud Provider Limitations
  • Error Codes
    • General Errors
    • User Account Errors
    • Workspace Errors
    • Catalog Errors
    • Cluster Errors
    • Data Governance Errors
    • Query History Errors
    • Query Editor Errors
    • Pool Errors
    • Connectivity Errors
  • Terms & Condition
  • Privacy Policy
    • Cookie Policy
  • FAQs
    • Workspace Setup
    • Security
    • Catalog Privileges
  • Services Utilised for e6data Deployment
    • AWS supported regions
    • GCP supported regions
    • AZURE supported regions
  • Release Notes & Updates
    • 6th Sept 2024
    • 6th June 2024
    • 18th April 2024
    • 9th April 2024
    • 30th March 2024
    • 16th March 2024
    • 14th March 2024
    • 12th March 2024
    • 2nd March 2024
    • 10th February 2024
    • 3rd February 2024
    • 17th January 2024
    • 9th January 2024
    • 3rd January 2024
    • 18th December 2023
    • 12th December 2023
    • 9th December 2023
    • 4th December 2023
    • 27th November 2023
    • 8th September 2023
    • 4th September 2023
    • 26th August 2023
    • 21st August 2023
    • 19th July 2023
    • 23rd May 2023
    • 5th May 2023
    • 28th April 2023
    • 19th April 2023
    • 15th April 2023
    • 10th April 2023
    • 30th March 2023
Powered by GitBook
On this page
  • Connectivity
  • Query History
  • Query Editor
  • Clusters
  • Catalogs
  • Workspaces
  • Identity and Access Management (IAM)
  1. Access Control
  2. Roles

Policies

Define and enforce access control rules.

This document lists all the policies available on e6data and their associated permissions:

Connectivity

Policy Name
Permissions
Description

ConnectivityFullAccess

ep:Create

Permission to create an endpoint

ep:Update

Permission to update an endpoint

ep:Delete

Permission to delete an endpoint

ep:Get

Permission to view information about Endpoints.

ep:List

Permission to view the list of assigned Endpoints.

ips:Create

Permission to create an IP Set

ips:Update

Permission to update an IP Set

ips:Delete

Permission to delete an IP Set

ips:Get

Permission to view information about IP Sets.

ips:List

Permission to view the list of assigned IP Sets.

ConnectivityViewAccess

ep:Get

Permission to view information about Endpoints.

ep:List

Permission to view the list of assigned Endpoints.

ips:Get

Permission to view information about IP Sets.

ips:List

Permission to view the list of assigned IP Sets.

Query History

Policy Name
Permissions
Description

QueryHistoryFullAccess

qh:DownloadHistory

Permission to download query history.

qh:ViewAllHistory

Permission to view the query history of all the users.

Query Editor

Policy Name
Permissions
Description

QueryEditorFullAccess

qe:Enable

Permission to access the Query Editor and run queries.

qe:Download

Permission to download query results

QueryEditorManagerAccess

qe:Enable

Permission to access the Query Editor and run queries.

Clusters

Policy Name
Permissions
Description

ClusterFullAccess

cl:*

Includes all the permissions listed below.

ClusterManagerAccess

cl:List

Permission to view the list of assigned clusters.

cl:Get

Permission to view information about assigned clusters.

cl:Update

Permission to update assigned clusters.

cl:Associate

Permission to attach an assigned catalog to an assigned cluster.

cl:Disassociate

Permission to detach an assigned catalog that is already attached to a cluster.

cl:Suspend

Permission to suspend assigned clusters.

cl:Resume

Permission to resume assigned clusters.

ct:List

Permission to view the list of assigned catalogs.

ClusterRunAccess

cl:List

Permission to view the list of assigned clusters.

cl:Get

Permission to view information about assigned clusters.

cl:Suspend

Permission to suspend assigned clusters.

cl:Resume

Permission to resume assigned clusters.

ClusterReadAccess

cl:List

Permission to view the list of assigned clusters.

cl:Get

Permission to view information about assigned clusters.

Catalogs

Policy Name
Permissions
Description

CatalogFullAccess

ct:*

Includes all the permissions listed below.

CatalogManagerAccess

ct:Get

Permission to view information about catalogs.

ct:List

Permission to view the list of assigned catalogs.

ct:Update

Permission to update assigned catalogs.

ct:Refresh

Permission to refresh assigned catalogs.

CatalogReadAccess

ct:Get

Permission to view information about catalogs.

ct:List

Permission to view the list of assigned catalogs.

Workspaces

Policy Name
Permissions
Description

WorkspaceFullAccess

ws:*

Includes all the permissions listed below.

WorkspaceManagerAccess

ws:Update

Permission to update an assigned workspace.

ws:Get

Permission to to view information about assigned workspaces.

ws:List

Permission to view the list of assigned workspaces.

Identity and Access Management (IAM)

Policy Name
Permissions
Description

IAMFullAccess

iam:*

Includes all the permissions listed below.

IAMReadAccess

iam:ListUsers

Permission to view the list of existing users.

iam:ListGroups

Permission to view the list of existing groups.

iam:ListPolicies

Permission to view all existing policies.

iam:ListOperations

Permission to view basic operations.

IAMManagerAccess

iam:UpdateUsers

Permission to update the privileges of any existing user.

iam:UpdateGroups

Permission to update the privileges of any existing group.

PreviousPermissionsNextSingle Sign-On (SSO)

Last updated 9 months ago