← Gallery
Diagram
dp-security-matrix
← Prev
Next →
dp-security-matrix
Platform entitlement matrix
Platform entitlement matrix
Four roles crossed with five platform components, every intersection rendered. Roles run left to right by descending privilege: platform administrator, data engineer, data scientist, reporting analyst. Components run top to bottom along the path data takes: identity provider, object store raw zone, query engine, notebook environment, ingest tool. The platform administrator holds full access to every component; the data engineer holds read-write everywhere except identity, where they only log in; the data scientist works in the query engine and notebooks but is denied the raw zone; the reporting analyst may only log in, run SELECT against the query engine, and nothing else. The focal cell is data scientist against the raw object store zone — no access — because raw personal data never reaches the analysis surface. There are no connectors in this diagram.
Platform component
Roles, by descending privilege
Platform admin
grp-platform-admins
Data engineer
grp-data-eng
Data scientist
grp-data-sci
Reporting analyst
grp-reporting
Identity provider
SSO
Realm admin
Login
Login
Login
Object store
raw zone
Bucket admin
R/W
No access
raw PII never reaches analysis
No access
Query engine
federation
Cluster admin
R/W
R/W
SELECT
Notebook environment
interactive
Hub admin
R/W
R/W
No access
Ingest tool
pipelines
Flow admin
R/W
Read flows
No access
full
rw
read
none
focal access rule