Permissions overview
Deephaven enables fine-grained access control to data, queries, and reports. This is accomplished through the individual authorization of users and groups, access control lists (ACLs), and account information.
Authentication vs. authorization
There are two aspects to access control in Deephaven:
| Aspect | Description | Managed by |
|---|---|---|
| Authentication | Verification of a user's identity | Internal (passwords, keys) or external (LDAP, SAML) |
| Authorization | Verification of what permissions the user has | Enforced internally by Deephaven; entitlement data can be sourced from an external system (e.g., DACS) |
Authentication
Authentication can be handled:
- Internally: Deephaven's own ACL store handles authentication directly:
- Storing a password validation hash in the ACL store
- Key-based authentication using key pairs registered in the ACL store
- Externally: Integrating with an external identity provider:
If external authentication is in use, a new user must generally be configured both in the external system and in Deephaven before they can log in. The exception is when SAML or LDAP/Active Directory group synchronization is enabled: Deephaven then creates the user's ACL record automatically on their first successful login.
Authorization
Authorization decisions are enforced within Deephaven. Data access rights and system privileges can be granted to individual users or groups, though the entitlement data behind a permission can itself come from an external system, as with the DACS integration.
Groups in Deephaven are internal to the product. External group memberships (e.g., from Active Directory) are not automatically used. When using group-based permissions, add users to appropriate Deephaven groups manually, or configure group synchronization for automatic group membership: SAML group synchronization or LDAP/Active Directory group synchronization.
What can be controlled
| Resource | Control level | Documentation |
|---|---|---|
| Table data | Row and column filtering | Table ACLs |
| Persistent Queries | View, edit, start/stop access | Persistent Query ACLs |
| System features | Console access, query creation | Special groups |
| ACL management | Who can edit permissions | iris-acleditors group |
Common tasks
| Task | Documentation |
|---|---|
| Create a new user | Web ACL editor or CLI |
| Create an admin user | Admin user |
| Grant table access | Table ACLs |
| Share query results | Persistent Query ACLs |
| Set up key-based login | Authentication keys |
| Verify user permissions | Check permissions |
Note
If you are using a Legacy worker, please refer to the Legacy ACLs documentation.
This section covers
- ACL storage - Storage options for ACL data
- Admin user - Creating administrative users
- Authentication keys - Key-based authentication setup
- CLI ACL editor - Command-line ACL management
- Web ACL editor - Web-based ACL management interface
- Table ACLs - Row and column level access control
- Persistent Query ACLs - Access control for query results
- Auth server ACL plugins - Custom authentication hooks
- Plugin ACLs - How table ACLs apply based on execution context in
deephaven.uiand Deephaven Express plugins - DACS integration - Thomson Reuters DACS entitlements