Skip to main content
The Data Access matrix organizes resources by source and entity. It also lists column-masking tags under Column Constraints.

Find a resource

Use Search entities and constraints… to filter entity names, source paths, and masking tags. Matching sections expand automatically. Resources can appear as:
All Future Entities changes the default for entities added later. Use it only for roles that should continue to receive broad access as the source grows.

Grant entity access

  1. Select the roles you want to compare.
  2. Expand the source section.
  3. Select the named entities each role needs.
  4. Leave All Future Entities clear unless future access is intentional.
  5. Select Save changes.
An entity without a source appears under Ungrouped. Confirm its ownership before granting access.

Apply column constraints

  1. Expand Column Constraints.
  2. Review each masking tag and its description.
  3. Select the tag only for roles approved to view data protected by that tag.
  4. Select Save changes.
The matrix assigns role access to existing masking tags. Define or apply those tags in the relevant DataX catalog workflow before you manage role visibility here.
A masking tag is a policy boundary, not a description alone. Use stable names, document the protected data class, and review every role that receives access.

Validate the result

  • Test a role that should see the entity.
  • Test a role that should not see it.
  • Verify a tagged sensitive column with both roles.
  • Reopen Data Access and confirm the saved checkboxes.
Return to Manage data access by role for role selection and bulk controls.
Last modified on September 16, 2026