Linking Data Access to Data Catalog

To fully integrate your data governance landscape, you can link a data source in Data Access to an existing System asset in Data Catalog. This is applicable only to data sources that contain data objects, not to identity stores.

Why link a data source to a System asset

After adding a data source to Data Access, you can link it to a corresponding System asset in Catalog. This allows Data Access to automatically map the data objects in the data source (such as databases, schemas, tables, and columns) to the corresponding data assets in Catalog.

Such mapping between Data Access and Catalog allows you to create a new Data Access role directly from your asset, with Data Access automatically populating the role's data objects. For example, if you create a role from a Data Product Port asset that contains three tables, Data Access populates the new role with those three tables.

Such mapping between Data Access and Catalog unlocks the following capabilities:

Note To be able to create a role from an asset, access requests need to be configured for the asset type with one or more relation types. These relation types define the paths that Data Access follows to find related data assets.

How mapping works

The mapping between a data source in Data Access and a System asset in Catalog relies on matching names.

Data Access matches each database, schema, table, and column in the data source to the correspondingly named Database, Schema, Table, and Column asset nested under the System asset in Catalog. For the mapping to work, ensure that the System asset's name and the names of its nested assets exactly match the names that are used in the data source.

Example: Creating a role from a Data Product Port asset

This example shows how a new role that is created from a Data Product Port asset is automatically populated with data.

Suppose that you want to enable self-service access requests for a Data Product Port asset named SALES_PORT, which is related to three Table assets: CUSTOMERS, ORDERS, and PRODUCTS. Instead of creating a role in Data Access from scratch and then manually adding data objects to it, you can choose to create a role from the asset.

Prerequisites

An administrator has configured access requests for the Data Product Port asset type with the relation type "Data Product Port is implemented as Data Product Port Asset" (an out-of-the-box explicit relation type). This relation type links a data product port to the tables that it exposes. (By default, Table is part of the Data Product Port Asset asset type group.)

How it works

  1. When you create a role from the SALES_PORT asset, Data Access follows the "Data Product Port is implemented as Data Product Port Asset" relation type to locate the related tables: CUSTOMERS, ORDERS, and PRODUCTS.
  2. Data Access resolves each table to its corresponding data object in Data Access. To do this, it uses the System asset that is linked to the data source.
    • The Table asset CUSTOMERS is resolved to the data object SNOWFLAKE_PROD.SALES_SCHEMA.CUSTOMERS.
    • The Table asset ORDERS is resolved to the data object SNOWFLAKE_PROD.SALES_SCHEMA.ORDERS.
    • The Table asset PRODUCTS is resolved to the data object SNOWFLAKE_PROD.SALES_SCHEMA.PRODUCTS.
  3. Data Access populates the new role with the following data objects:
    • SNOWFLAKE_PROD.SALES_SCHEMA.CUSTOMERS
    • SNOWFLAKE_PROD.SALES_SCHEMA.ORDERS
    • SNOWFLAKE_PROD.SALES_SCHEMA.PRODUCTS

You can review the permissions before proceeding to create the role. Data Access then creates the role and links it to the SALES_PORT data product port.

In this way, instead of manually searching across schemas for the correct data objects, you create a role that is scoped to your asset's underlying data.

Example: Creating a role from a Data Set asset

This example shows how a new role that is created from a Data Set asset is automatically populated with data. It is similar to the previous example, but the logic that is used to populate the new role is slightly different because it involves columns.

Suppose that you want to enable self-service access requests for a Data Set asset named CUSTOMER, which is related to two Column assets: CREDIT_CARD_NUMBER and EMAIL_ADDRESS.

Prerequisites

An administrator has configured access requests for the Data Set asset type with the "Data Set contains Column" relation type (a custom derived relation type).

How it works

  1. When you create a role from the CUSTOMER data set, Data Access follows the "Data Set contains Column" relation type to locate the related columns: CREDIT_CARD_NUMBER and EMAIL_ADDRESS.
  2. Data Access resolves each column to its corresponding data object in Data Access. To do this, it uses the System asset that is linked to the data source.
    Note Data Access grants permissions only at the level of data objects that a data source can apply access to. In practice, this includes any data object type except columns, for example, tables, views, or schemas. When a related asset resolves to a data object that cannot carry permissions on its own (such as a column), Data Access automatically resolves it to the nearest ancestor data object that can hold permissions. For example, a Column asset typically resolves to its parent table. As a result, creating a role from an asset may populate data objects at a broader level than the starting asset.

    Accordingly, both Column assets, CUSTOMERS and EMAIL_ADDRESS, are resolved to the same data object, SNOWFLAKE_PROD.SALES_SCHEMA.CUSTOMER.

  3. Data Access populates the new role with the SNOWFLAKE_PROD.SALES_SCHEMA.CUSTOMER data object.

You can review the permissions before proceeding to create the role. Data Access then creates the role and links it to the CUSTOMER data set.

Importing metadata from Catalog for dynamic rules

Linking a data source allows Data Access to import metadata from Catalog as object tags (key-value pairs) attached to data objects in Data Access.

For example, if a Column asset in Catalog has a relation to a PII Data Category asset, Data Access can import that relation as an object tag (for example, Category:PII). You can then create a column mask with a dynamic rule that automatically masks all columns tagged Category:PII across your data sources, eliminating the need to manually select individual tables or columns.

Synchronizing asset ownership

Linking a data source enables Data Access to map asset responsibilities (ownership) in Catalog directly to data object ownership in Data Access. For example, if a user is assigned as an owner of a Table asset in Catalog (such as the Customer Orders table), Data Access designates that user as the owner of the corresponding table in Data Access.

This enables the table owners in Catalog to directly review access requests and manage permissions for their data objects in Data Access, without requiring manual administrative setup or separate security assignments.

Related topics

Configure access requests