For the complete documentation index, see llms.txt. This page is also available as Markdown.

Author a Restricted Data Policy

Build a data policy that only applies to data sources you own

Data owners who are not governors can write restricted subscription and data policies, which allow them to enforce policies on multiple data sources simultaneously, eliminating the need to write redundant local policies.

Unlike global policies, the application of these policies is restricted to the data sources owned by the users or groups specified in the policy and will change as users' ownerships change.

Permissions

CREATE_DATA_SOURCE Immuta permission or own the data source

Build the policy

  1. Click the Policies icon in the navigation menu and select Data Policies.

  2. Click New data policy and complete the Policy name field.

  3. Select Protect or Reveal as the data policy type.

  4. AI-powered feature: Click Explain this policy to open the AI assistant side sheet. The AI assistant will generate a textual summary and explanation of the policy behavior on various users using mock data.

  5. Opt to complete the Enter Rationale for Policy (Optional) field, and then click Add.

  6. From the Where should this policy be applied dropdown menu, select When selected by data owners, On all data sources, or On data sources. If you selected On data sources, finish the condition in one of the following ways:

    • tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with columns tagged: Select this option and then search for tags in the subsequent dropdown menu.

    • with column names spelled like: Select this option, and then enter a regex and choose a modifier in the subsequent fields.

    • in server: Select this option and then choose a server from the subsequent dropdown menu to apply the policy to data sources that share this connection string.

    • created between: Select this option and then choose a start date and an end date in the subsequent dropdown menus.

  7. Beneath Whose Data Sources should this policy be restricted to, add users or groups to the policy restriction by typing in the text fields and selecting from the dropdown menus that appear.

  8. To limit this policy to data sources within specific domains, enter the domains the policy should be restricted to in the Select Domains field.

  9. Click Activate Policy or Stage Policy.

Last updated

Was this helpful?