Set up Access Group or Policy (Authorization)
Overview
To query data from the Data Query layer, the requesting user must have the appropriate authorization. Authorization is managed through domain-specific access groups in ARMS and determines which users can access data tables within a domain.
Each domain has a dedicated access group that grants read access to all tables registered under that domain. Membership in the required access group is mandatory, regardless of whether the data pipeline is running or the table is registered in the Data Catalog. Queries issued without the necessary authorization return a permission error.
Use the procedures in this section to request access to the appropriate domain access group and verify that the required permissions have been assigned.
- Execution Platform: ARMS
- Request process: Access Request (request access to the domain-specific access group using ARMS)
- Responsible: Data Engineer
Access Group Naming Convention
Access groups follow the naming convention:
Example: Domain:Service Maintenance > Access Group:data-domain-service_maintenance
Request Access to an Access Group
ARMS supports access group requests through two organizational unit (OU) types:
- Account level
- Compute Zone level
- Compute Zone-level access groups are being deprecated. Account-level access groups are becoming the primary authorization method supported by the Data Query layer.
- Account-level access is currently available in the staging environment and is undergoing validation. Use the Account-level process for new requests. If issues occur, use the Compute Zone-level process until the rollout is complete.
Account-Level OU Access (Recommended)
Use the Account-level OU access model to request authorization for domain-specific data access groups. This model is the preferred authorization mechanism for the Data Query layer and is intended to replace Compute Zone-level access groups. After approval, users can query all tables registered under the authorized domain.
Status: Available in the staging environment and currently under validation before general availability.
Asset location: images/getting_started/arms-account-level-access/
Account-level access is currently available in the staging environment and is undergoing validation before general availability. If issues are encountered during the rollout, use the Compute Zone-level access process as a temporary alternative.
Perform the following steps to request access at the Account-level:
- Open the ARMS Portal.
- Navigate to User > AIOPS Requests > Request Access Groups.
- Select OU Type as Account.
- Use Filter to narrow the list by Unit Tag or POD.
- Select the required account or organizational unit, such as:
- Kaiser Permanente1 – Dev
- ServiceNow – Dev
- ServiceNow - Staging
- Click Next.
- Review the Standard Access groups displayed for the selected accounts.
- Select Advanced Form because domain-specific access groups (data-domain-*) are not included in Standard Access.
- Under Data Lake Service, search for and select the access group for the required domain. Example: data-domain-service_maintenance
- Click Next.
- Enter a business justification.
- Click Submit.
- The request is routed to the designated approver.
- After approval, access is granted to query all tables registered under the selected domain.
Request access only to the domains required for job responsibilities to simplify approval and access management.
Compute Zone-Level OU Access (Deprecated)
Use the Compute Zone-level OU access model to request authorization for domain-specific access groups when Account-level access is unavailable or cannot be used. This access model continues to provide access to domain data; however, it is being phased out in favor of the Account-level authorization model.
- Compute Zone-level access groups are being phased out and will be replaced by Account-level access groups. Use the Account-level process whenever possible.
- Until Account-level access is fully validated and generally available, Compute Zone-level access remains available as a fallback option.
Request Compute Zone-Level Access
Perform the following steps to request access at the Compute zone-level:
- Open the ARMS Portal.
- Navigate to User > AIOPS Requests > Request Access Groups.
- Select OU Type as Compute Zone.
- Select the appropriate compute zone, such as:
- dev_was1
- staging_was1
- Select Advanced Form.
- Under Data Lake Service, search for and select the access group associated with the required domain.
Example: data-domain-service_maintenance
- Click Next.
- Enter a business justification.
- Click Submit.
- The request is routed to the designated approver for review and approval.
- After approval, access is granted to query all tables registered under the selected domain.
Verify Access Assignments
After the request is approved, the assigned access group appears in ARMS under: User > AIOPS Assignments.
ARMS Access Group Assignments
Use the AIOPS Assignments page to review the access groups assigned to the user account and verify that the required domain access has been granted.
If the domain associated with a target table is unknown, use the Data Catalog Controller APIs to identify available domains and registered tables before submitting an access request.