Security Center
This topic answers frequently asked questions (FAQs) about Security Center in DataWorks.
What permissions can I request in Security Center?
On the Security Center page, you can request table permissions within a DataWorks workspace, including permissions for both the development environment and the production environment.
Relationship between Data Management and Security Center
Security Center is the upgraded replacement for the permission and security features in Data Management. Permissions that were previously requested in the Data Management module or granted by using the odpscmd grant command are still visible on the page.
To submit new permission requests or handle approvals through the UI, go to Security Center. The Data Management module no longer supports these operations.
Field selection in permission requests
If LabelSecurity is enabled for the workspace, you can select specific fields when submitting a request. Otherwise, you can only request permissions for the entire table.
Who approves requests?
A workspace administrator or the table owner must approve the request. The approval process is complete as soon as one of them approves or rejects the request.
Why one submission creates two requests
This occurs because the tables in your request have different table owners. Security Center automatically splits the request into separate requests based on the table owner.
Why temporary permissions become permanent
This indicates that the security level of the field is 0 or is lower than or equal to the security level of your account.
Why I have unrequested permissions
This can happen for one of the following reasons:
-
An administrator granted you the permission by running commands in the console, outside of Security Center.
-
You automatically have permissions for fields with a security level of 0 or a level lower than or equal to your account's.
Why requests disappear from the approval queue
This happens because another workspace administrator or the table owner has already processed the request. Once a request is approved or rejected, it is considered complete and is removed from your Requests To Be Processed queue.
Handling "MaxCompute project exception" errors
Send the error message and the error code from the dialog box to your workspace administrator, who can investigate and resolve the issue.
Why can't I return or revoke permissions?
You can only return or revoke permissions for fields that have a security level higher than your account's security level. You cannot return or revoke permissions for fields where the security level is 0 or is lower than or equal to your account's security level.
Why Alibaba Cloud accounts cannot request permissions
An Alibaba Cloud account has all permissions by default and does not need to request them. Therefore, the option to request permissions is not available to Alibaba Cloud accounts. This does not affect the normal use of the account.
Viewing Data Management records in Security Center
No. The request and approval records in Security Center and Data Management are not linked. To view historical records from Data Management, you must navigate to the Data Management page.
Revoking permissions using request records
Currently, Security Center is not the only authorization channel. To best support permission revocation, Authorizations lists all user ACL permissions, regardless of the authorization channel. You can revoke permissions based on the current permission status, without needing to use the application records.
Resubmitting pending requests from Data Management
Yes. The request and approval records in Security Center and Data Management are not linked, so you must submit a new request in Security Center.
Configuring LabelSecurity for a field
You must go to Data Map to configure LabelSecurity for the field.