Skip to main content

Granting access to a service account

Grant data to a service account using the same governance rules applied to users and groups.

When to use this​

  • Use it after creating the service account.
  • Use it when an automation needs to query specific tables.
  • Use it when the account's current access does not cover a new routine.

Before you start​

  • Confirm the automation's purpose.
  • Have the service account's name.
  • List the catalog, schema, and tables needed.

Step by step​

  1. Open Data Governance.
  2. Create a new data rule.
  3. Choose the service account as the recipient.
  4. Select the catalog, schema, and tables needed.
  5. Configure expiry, masks, or filters where applicable.
  6. Simulate and review the summary.
  7. Save the rule.

What happens next​

  • The account can query only the data covered by the rule.
  • The change goes through propagation.
  • Queries made by the account are traceable in the audit trail.

Common errors​

  • Granting data to the wrong account.
  • Granting a whole schema when the automation uses a few tables.
  • Not reviewing access when the routine changes.

Good practice​

  • Use specific rules for each automation purpose.
  • Bring the account owner and the data owner together in the approval.
  • Review service accounts more often than ordinary users.

Next steps​