dp-security-matrix

Platform entitlement matrix

Platform entitlement matrix Four roles crossed with five platform components, every intersection rendered. Roles run left to right by descending privilege: platform administrator, data engineer, data scientist, reporting analyst. Components run top to bottom along the path data takes: identity provider, object store raw zone, query engine, notebook environment, ingest tool. The platform administrator holds full access to every component; the data engineer holds read-write everywhere except identity, where they only log in; the data scientist works in the query engine and notebooks but is denied the raw zone; the reporting analyst may only log in, run SELECT against the query engine, and nothing else. The focal cell is data scientist against the raw object store zone — no access — because raw personal data never reaches the analysis surface. There are no connectors in this diagram. Platform component Roles, by descending privilege grp-platform-admins grp-data-eng grp-data-sci grp-reporting Identity provider SSO Realm admin Login Login Login Object store raw zone Bucket admin R/W No access raw PII never reaches analysis No access Query engine federation Cluster admin R/W R/W SELECT Notebook environment interactive Hub admin R/W R/W No access Ingest tool pipelines Flow admin R/W Read flows No access full rw read none focal access rule