Configure user groups

Updated at:

The user group feature in DataWorks helps you efficiently manage data access permissions by grouping accounts that require the same permissions. When you configure data masking, you can add a user group to an allowlist. This allows accounts in the user group to access raw data instead of masked data. This topic describes how to create and manage user groups.

Limitation

This feature is available only in DataWorks Professional Edition or later.

Go to the Data Security Guard page

  1. Log on to the DataWorks console. In the target region, click Data Governance > Security Center in the left-side navigation pane. On the page that appears, click Go to Security Center.

  2. In the left-side navigation pane, click Data Security > Sensitive Data Management and then click Try Now to access Data Security Guard.

    Note
    • If your Alibaba Cloud account is already authorized, you are directed to the Data Security Guard homepage.

    • If your Alibaba Cloud account is not authorized, you are redirected to the Data Security Guard authorization page. To use Data Security Guard features for the first time, go to Data Security > Sensitive Data Management, select Data Security Guard in the pop-up dialog, and then complete the authorization.

Create a user group

Create a user group on the Data Security Guard page.

  1. In the left-side navigation pane, choose Rule Setting > User Group Management to go to the User Group Management page.

  2. Create a user group.

    1. Click Create User Group. In the New User Group dialog box, enter a User Group Name and add the desired accounts to the user group.

    2. You can add accounts to the user group based on their source type.

      Account source type

      Method

      Text

      Add accounts by clicking Upload File. This method lets you batch-add accounts by uploading a text file and is ideal for adding many accounts.

      Note

      DataWorks supports only UTF-8 encoded .txt files. Each account must be on a separate line. You can upload a maximum of 1,000 accounts.

      Select existing accounts

      This method allows you to directly select the accounts to add, including Alibaba Cloud account (including main accounts and RAM users), RAM role, and MaxCompute role accounts. This method is ideal for adding a small number of accounts.

      1. Select the account type as needed.

      2. In the Available Accounts section, select the desired accounts and click the image icon to move them to the Selected Accounts section.

      Note

      For MaxCompute roles, you can only create a user group from multiple roles within the same MaxCompute project.

    3. Click Confirm to complete the user group creation.

Use user groups

After you create a user group, you can use the Data Masking Management feature to configure an allowlist for a masking rule and add the user group to the allowlist. Data masked by the target masking rule will still be displayed as raw data for accounts in the user group. For more information about configuring a masking rule allowlist, see Configure data masking.

Manage user groups

On the User Group Management page, you can manage the user groups that you have created.

View user groups

You can view basic information about all created user groups, including User Group Name, Commission Time, and the associated masking allowlist information for the user group.

  • Search for user groups: You can search for a user group by User Group Name or Head. Fuzzy matching is supported. After you enter a keyword, all user groups whose names or owners contain the keyword are displayed.

  • Sort user groups: You can sort all user groups in ascending or descending order of Commission Time to find the desired user group by time.

  • View Associated Masking Allowlist: If a user group has been added to a masking allowlist, click the image icon in the Associated Masking Allowlist column to view the names of the masking rules that use the user group.

More operations

  • Copy a user group: To quickly create a user group with the same configuration, click the Copy icon icon in the Actions column of the target user group.

  • Edit a user group: To add allowlist permissions for accounts or revoke allowlist permissions from accounts, click the Settings icon icon in the Actions column of the target user group to modify its configuration.

  • Delete a user group: If a user group is no longer needed, click the Delete icon icon in the Actions column of the target user group to delete it.