Create data access rule

A data access rule creates an additional layer of protection by managing access and enhancing protection for specific usages.

When creating a data access rule, you can do one of the following:

Prerequisites

Steps

  1. OpenProtect.
  2. Click the Data Access Rules tab.
  3. Click Create Data Access Rule.
    The Data Access Rule dialog box appears.
  4. Enter the required information.
    FieldDescription
    NameEnter a name to identify the rule.
    Optional: DescriptionEnter a description for the rule.
    GroupsSelect the groups for the rule.
    Assets

    Select the data assets that the rule is protecting.

    Tip 
    • This field contains Business Process, Data Category, and Data Set assets, in addition to assets of custom asset types.
    • For more information, go to Prescriptive paths.
    Optional: Mask Data
    1. Click Add Masking, and then, in the Masking Option field, select the masking level that you want to apply to a data category or data classification.
    2. Click Data Category or Data Classification, and then select the data category or data classification for the selected masking level.
    Tip 
    • You can add more data categories and data classifications by using Add Another Masking.
    • If the association between the data classification and a column is not yet accepted, the rule ignores the column.

    Optional: Filter Data

    1. Click Add Filter, and then, in the Filter Action field, select the row filter that you want to apply to a data classification with a specific code set and code value.
      Tip The following steps are applicable only if you selected Show Some or Hide Some.
    2. In the Data Classification field, select the data classification that you want to show or hide.
    3. In the Code Set field, select the code set for the selected data classification.
    4. In the Code Value field, select the code value for the selected code set.
    Tip You can add more data classifications for row-filtering by using Add Another Filter.
    The Summary section shows a summary of the rule.
    Tip The Grant Access to Data Linked to Selected Assets checkbox is applicable to only certain data sources. For more information, go to Grant access to linked data.

    Image of the Data Access Rule dialog box

  5. To preview the rule, in the Summary section, click Generate Preview.
    Tip The preview shows only the first 1,000 affected columns. The drop-down list box below the Generate Preview button is used to switch between the assets that you selected in the rule. Each asset has its own preview table.
  6. Click Create Draft or Publish.