Set up Access Group or Policy (Authorization)
overview to query data from the data query layer, the requesting user must have the appropriate authorization authorization is managed through domain specific access groups in arms and determines which users can access data tables within a domain each domain has a dedicated access group that grants read access to all tables registered under that domain membership in the required access group is mandatory, regardless of whether the data pipeline is running or the table is registered in the data catalog queries issued without the necessary authorization return a permission error use the procedures in this section to request access to the appropriate domain access group and verify that the required permissions have been assigned execution platform arms request process access request (request access to the domain specific access group using arms) responsible data engineer access group naming convention access groups follow the naming convention data domain \<domain name> example domain\ service maintenance > access group\ data domain service maintenance request access to an access group arms supports access group requests through two organizational unit (ou) types account level compute zone level compute zone level access groups are being deprecated account level access groups are becoming the primary authorization method supported by the data query layer account level access is currently available in the staging environment and is undergoing validation use the account level process for new requests if issues occur, use the compute zone level process until the rollout is complete account level ou access (recommended) use the account level ou access model to request authorization for domain specific data access groups this model is the preferred authorization mechanism for the data query layer and is intended to replace compute zone level access groups after approval, users can query all tables registered under the authorized domain status available in the staging environment and currently under validation before general availability asset location images/getting started/arms account level access/ account level access is currently available in the staging environment and is undergoing validation before general availability if issues are encountered during the rollout, use the compute zone level access process as a temporary alternative perform the following steps to request access at the account level open the arms portal https //eu1sr1lnarms dev bats kyndryl net/arms2 navigate to user > aiops requests > request access groups select ou type as account use filter to narrow the list by unit tag or pod select the required account or organizational unit, such as kaiser permanente1 – dev servicenow – dev servicenow staging click next review the standard access groups displayed for the selected accounts select advanced form because domain specific access groups (data domain ) are not included in standard access under data lake service , search for and select the access group for the required domain example data domain service maintenance click next enter a business justification click submit the request is routed to the designated approver after approval, access is granted to query all tables registered under the selected domain request access only to the domains required for job responsibilities to simplify approval and access management compute zone level ou access (deprecated) use the compute zone level ou access model to request authorization for domain specific access groups when account level access is unavailable or cannot be used this access model continues to provide access to domain data; however, it is being phased out in favor of the account level authorization model compute zone level access groups are being phased out and will be replaced by account level access groups use the account level process whenever possible until account level access is fully validated and generally available, compute zone level access remains available as a fallback option request compute zone level access perform the following steps to request access at the compute zone level open the arms portal https //eu1sr1lnarms dev bats kyndryl net/arms2 navigate to user > aiops requests > request access groups select ou type as compute zone select the appropriate compute zone, such as dev was1 staging was1 select advanced form under data lake service, search for and select the access group associated with the required domain example data domain service maintenance click next enter a business justification click submit the request is routed to the designated approver for review and approval after approval, access is granted to query all tables registered under the selected domain verify access assignments after the request is approved, the assigned access group appears in arms under user > aiops assignments arms access group assignments use the aiops assignments page to review the access groups assigned to the user account and verify that the required domain access has been granted if the domain associated with a target table is unknown, use the data catalog controller apis https //kyndryl gitbook io/kyndryl cto/kyndryl platform techdocs/convergence of software/datafoundations/overview/getting started#discovering domains and data tables prerequisites for querying to identify available domains and registered tables before submitting an access request