Data source-specific permissions

To run data quality on a data source, the Edge connection must have the minimum permissions described in the table below.

Note The Edge connection may be shared with other capabilities, such as Structural Metadata Ingestion, or may be specific to Data Quality & Observability.

Data source Structural Metadata ingestion permissions Data Quality Pushdown permissions
Amazon Athena N/A
  • Read access on your Glue catalog and S3 buckets
  • Write access on your S3 output location
Amazon Redshift USAGE
  • GRANT USAGE ON SCHEMA
  • GRANT SELECT ON ALL TABLES
Databricks CAN ATTACH TO CAN ATTACH TO
Google BigQuery
  • bigquery.datasets.get
  • bigquery.jobs.create
  • bigquery.tables.get
  • bigquery.tables.getData
  • bigquery.tables.list
  • resourcemanager.projects.get
  • roles/bigquery.dataViewer
  • roles/bigquery.jobUser
  • roles/bigquery.readSessionUser
  • roles/bigquery.dataOwner permissions on the temporary dataset
Microsoft SQL Server
  • CONNECT SQL on the system
  • VIEW DEFINITION on the database
  • GRANT on the login and database
  • GRANT SELECT on schemas, tables, and views
Oracle OCI N/A

GRANT SELECT on schemas, tables, and views

SAP HANA
  • MONITORING role
  • PUBLIC role
SELECT on each schema that you want to profile
Snowflake
  • USAGE on the database and schema
  • REFERENCES on each table that you want to ingest
  • USAGE on the warehouse, database, and schema
  • GRANT SELECT on tables and views
Starburst N/A read-only role on the catalog, schemas, tables, views, and columns