For the complete documentation index, see llms.txt. This page is also available as Markdown.

Author a Restricted Subscription Policy

Build a subscription policy that applies only to data sources you own

Data owners who are not governors can write restricted subscription policies and data policies, which allow them to enforce policies on multiple data sources simultaneously, eliminating the need to write redundant local policies.

Unlike global policies, the application of these policies is restricted to the data sources owned by the users or groups specified in the policy and will change as users' ownerships change.

Permission

CREATE_DATA_SOURCE Immuta permission or own the data source

Write access policy requirements

Private preview: Write policies are available to select accounts. Contact your Immuta representative to enable this feature.

Enable write access policies

Once support for this feature has been enabled in your Immuta tenant,

  1. Navigate to the App Settings page.

  2. Scroll to the Preview Features section.

  3. Click the Enable Write Policies checkbox and Save your changes.

Build the policy

  1. Click the Policies icon in the navigation menu and select Subscription Policies.

  2. Click New subscription policy and complete the Policy name field.

  3. Select the type of subscription policy:

    1. Grant policy: Subscribe users to the data source if they meet the conditions of the policy.

    2. Guardrail policy: Prevent users from subscribing unless they meet the conditions of the policy. Some subscription levels listed below are unavailable for this policy type.

  4. Select the access type you want to control:

    • Read Access: Control who can view the data source.

    • Write Access: Control who can view and modify data in the data source.

  5. Select the subscription level you would like to apply:

    • Allow users with specific groups/attributes:

      1. Choose the condition that will drive the policy: when user is a member of a group or possesses attribute. Note: To build more complex policies than the builder allows, follow the Advanced rules DSL policy guide.

      2. Use the subsequent dropdown to choose the group or attribute for your condition. You can add more than one condition by selecting + Add Another Condition. The dropdown menu in the subscription policy builder contains conjunctions for your policy. If you select or, only one of your conditions must apply to a user for them to see the data. If you select and, all of the conditions must apply.

      3. Check the Require Manual Subscription checkbox to turn off automatic subscription. Enabling this feature will require users to manually subscribe to the data source if they meet the policy.

      4. If you would like to make your data source visible in the list of all data sources in the UI to all users, click the Allow Data Source Discovery checkbox. Otherwise, this data source will not be discoverable by users who do not meet the criteria established in the policy.

      5. If you would like users to have the ability to request approval to the data source, even if they do not have the required attributes or traits, check the Request Approval to Access checkbox. This will require an approver with permissions to be set.

    • Allow individually selected users

  6. From the Where should this policy be applied dropdown menu, select When selected by data owners, On all data sources, or On data sources. If you selected On data sources, finish the condition in one of the following ways:

    • tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with columns tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with column names spelled like: Select this option, and then enter a regex and choose a modifier in the subsequent fields.

    • in server: Select this option and then choose a server from the subsequent dropdown menu to apply the policy to data sources that share this connection string.

    • created between: Select this option and then choose a start date and an end date in the subsequent dropdown menus.

  7. Beneath Whose Data Sources should this policy be restricted to, add users or groups to the policy restriction by typing in the text fields and selecting from the dropdown menus that appear.

  8. Opt to complete the Enter Rationale for Policy (Optional) field.

  9. Click Activate Policy or Stage Policy.

Last updated

Was this helpful?