---
title: Set up Access Group or Policy (Authorization)
slug: set-up-access-group-or-policy-authorization
docTags: 
createdAt: 2026-09-01T03:31:17.671Z
---

## Overview

To query data from the Data Query layer, the requesting user must have the appropriate authorization. Authorization is managed through domain-specific access groups in ARMS and determines which users can access data tables within a domain.

Each domain has a dedicated access group that grants read access to all tables registered under that domain. Membership in the required access group is mandatory, regardless of whether the data pipeline is running or the table is registered in the Data Catalog. Queries issued without the necessary authorization return a permission error.

Use the procedures in this section to request access to the appropriate domain access group and verify that the required permissions have been assigned.

- **Execution Platform:** ARMS
- **Request process:** Access Request (request access to the domain-specific access group using ARMS)
- **Responsible:** Data Engineer

### Access Group Naming Convention

Access groups follow the naming convention:

:::BlockQuote
*data-domain-\<domain\_name>*
:::

**Example:&#x20;**&#x44;omain\:Service Maintenance > Access Group\:data-domain-service\_maintenance

### Request Access to an Access Group

ARMS supports access group requests through two organizational unit (OU) types:

- Account level
- Compute Zone level

:::hint{type="info"}
* Compute Zone-level access groups are being deprecated. Account-level access groups are becoming the primary authorization method supported by the Data Query layer.
* Account-level access is currently available in the staging environment and is undergoing validation. Use the Account-level process for new requests. If issues occur, use the Compute Zone-level process until the rollout is complete.
:::

## Account-Level OU Access (Recommended)

Use the Account-level OU access model to request authorization for domain-specific data access groups. This model is the preferred authorization mechanism for the Data Query layer and is intended to replace Compute Zone-level access groups. After approval, users can query all tables registered under the authorized domain.

**Status:** Available in the staging environment and currently under validation before general availability.

**Asset location:** images/getting\_started/arms-account-level-access/

:::hint{type="info"}
Account-level access is currently available in the staging environment and is undergoing validation before general availability. If issues are encountered during the rollout, use the Compute Zone-level access process as a temporary alternative.
:::

Perform the following steps to request access at the Account-level:&#x20;

1. Open the [ARMS Portal](https://eu1sr1lnarms-dev.bats.kyndryl.net/arms2).&#x20;
2. Navigate to **User > AIOPS Requests > Request Access Groups**.
3. Select **OU Type&#x20;**&#x61;&#x73;**&#x20;Account**.
4. Use **Filter** to narrow the list by Unit Tag or POD.
5. Select the required account or organizational unit, such as:
   - Kaiser Permanente1 – Dev
   - ServiceNow – Dev
   - ServiceNow - Staging
6. Click **Next**.
7. Review the **Standard Access** groups displayed for the selected accounts.
8. Select **Advanced Form** because domain-specific access groups (data-domain-\*) are not included in Standard Access.
9. Under **Data Lake Service**, search for and select the access group for the required domain. Example: data-domain-service\_maintenance
10. Click **Next**.
11. Enter a business justification.
12. Click **Submit**.
13. The request is routed to the designated approver.
14. After approval, access is granted to query all tables registered under the selected domain.

::::hint{type="info"}
:::Paragraph{indent="1"}
Request access only to the domains required for job responsibilities to simplify approval and access management.
:::
::::

## Compute Zone-Level OU Access (Deprecated)

Use the Compute Zone-level OU access model to request authorization for domain-specific access groups when Account-level access is unavailable or cannot be used. This access model continues to provide access to domain data; however, it is being phased out in favor of the Account-level authorization model.

:::hint{type="info"}
- Compute Zone-level access groups are being phased out and will be replaced by Account-level access groups. Use the Account-level process whenever possible.
- Until Account-level access is fully validated and generally available, Compute Zone-level access remains available as a fallback option.
:::

### Request Compute Zone-Level Access

Perform the following steps to request access at the Compute zone-level:

1. Open the [ARMS Portal](https://eu1sr1lnarms-dev.bats.kyndryl.net/arms2).
2. Navigate to **User > AIOPS Requests > Request Access Groups**.
3. Select **OU Type** as Compute Zone.
4. Select the appropriate compute zone, such as:
   - dev\_was1
   - staging\_was1
5. Select **Advanced Form**.
6. Under Data Lake Service, search for and select the access group associated with the required domain.

:::Paragraph{indent="1"}
**Example:** data-domain-service\_maintenance
:::

7. Click **Next**.
8. Enter a business justification.
9. Click **Submit**.
10. The request is routed to the designated approver for review and approval.
11. After approval, access is granted to query all tables registered under the selected domain.

### Verify Access Assignments

After the request is approved, the assigned access group appears in ARMS under: **User > AIOPS Assignments**.

### ARMS Access Group Assignments

Use the AIOPS Assignments page to review the access groups assigned to the user account and verify that the required domain access has been granted.

:::hint{type="info"}
If the domain associated with a target table is unknown, use the [Data Catalog Controller APIs](https://kyndryl.gitbook.io/kyndryl-cto/kyndryl-platform-techdocs/convergence-of-software/datafoundations/overview/getting_started#discovering-domains-and-data-tables-prerequisites-for-querying) to identify available domains and registered tables before submitting an access request.
:::

