Permissions overview

Deephaven enables fine-grained access control to data, queries, and reports. This is accomplished through the individual authorization of users and groups, access control lists (ACLs), and account information.

Authentication vs. authorization

There are two aspects to access control in Deephaven:

AspectDescriptionManaged by
AuthenticationVerification of a user's identityInternal (passwords, keys) or external (LDAP, SAML)
AuthorizationVerification of what permissions the user hasEnforced internally by Deephaven; entitlement data can be sourced from an external system (e.g., DACS)

Authentication

Authentication can be handled:

  • Internally: Deephaven's own ACL store handles authentication directly:
  • Externally: Integrating with an external identity provider:
    • LDAP for Active Directory or OpenLDAP
    • SAML for identity providers such as Okta

If external authentication is in use, a new user must generally be configured both in the external system and in Deephaven before they can log in. The exception is when SAML or LDAP/Active Directory group synchronization is enabled: Deephaven then creates the user's ACL record automatically on their first successful login.

Authorization

Authorization decisions are enforced within Deephaven. Data access rights and system privileges can be granted to individual users or groups, though the entitlement data behind a permission can itself come from an external system, as with the DACS integration.

Groups in Deephaven are internal to the product. External group memberships (e.g., from Active Directory) are not automatically used. When using group-based permissions, add users to appropriate Deephaven groups manually, or configure group synchronization for automatic group membership: SAML group synchronization or LDAP/Active Directory group synchronization.

What can be controlled

ResourceControl levelDocumentation
Table dataRow and column filteringTable ACLs
Persistent QueriesView, edit, start/stop accessPersistent Query ACLs
System featuresConsole access, query creationSpecial groups
ACL managementWho can edit permissionsiris-acleditors group

Common tasks

TaskDocumentation
Create a new userWeb ACL editor or CLI
Create an admin userAdmin user
Grant table accessTable ACLs
Share query resultsPersistent Query ACLs
Set up key-based loginAuthentication keys
Verify user permissionsCheck permissions

Note

If you are using a Legacy worker, please refer to the Legacy ACLs documentation.

This section covers