This topic answers frequently asked questions (FAQs) about Security Center in DataWorks.
What permissions can I request in Security Center?
On the Security Center page, you can request table permissions within a DataWorks workspace, including permissions for both the development environment and the production environment.
Relationship between Data Management and Security Center
Security Center is the upgraded replacement for the permission and security features in Data Management. Permissions that were previously requested in the Data Management module or granted by using the odpscmd grant command can still be viewed in .
To request new permissions or approve permission requests through a visual interface, go to Security Center. The Data Management module will no longer support permission requests and approvals in the future.
Field selection in permission requests
If LabelSecurity is enabled for the workspace, you can select columns when submitting a request. Otherwise, you can only request permissions at the table level.
Who approves requests?
Submitted requests must be approved by a project administrator or the table owner. The request is completed as soon as either one approves or rejects it.
Why one submission creates two requests
If the tables in your request have different table owners, Security Center automatically splits the request by table owner.
Why temporary permissions become permanent
This indicates that the security level of the column is 0 or less than or equal to the security level of your account.
Why I have unrequested permissions
This can happen for two reasons:
-
In addition to Security Center, an administrator can grant access to you by using console command-line tools.
-
If you submitted a request through Security Center, this indicates that the security level of the column is 0 or less than or equal to the security level of your account.
Why requests disappear from the approval queue
Another project administrator or table owner has already approved the request before you, so the request is now completed and no longer appears in your Requests To Be Processed list.
Handling "MaxCompute project exception" errors
Send the error dialog and the error code to the project administrator for troubleshooting.
Why can't I return or revoke permissions?
You can only return or revoke permissions for columns whose security level is higher than the security level of your account. For columns with a security level of 0 or a security level less than or equal to that of your account, you cannot return or revoke column-level permissions.
Why Alibaba Cloud accounts cannot request permissions
Alibaba Cloud accounts have all permissions by default and do not need to request permissions separately. Features such as permission requests are hidden for Alibaba Cloud accounts, which does not affect normal usage.
Viewing Data Management records in Security Center
Currently, request and approval records in Security Center and Data Management are not linked. To view historical request or approval records from Data Management, go to the Data Management page.
Revoking permissions using request records
Security Center is not the only channel for granting permissions. To maximize support for permission revocation, the permission audit lists all ACL permissions of all users regardless of the authorization channel. You can revoke permissions based on the current permission status without using request records.
Resubmitting pending requests from Data Management
Request and approval records in Security Center and Data Management are not linked. You need to submit your request again in Security Center.
Configuring LabelSecurity for a field
You need to go to Data Map to configure LabelSecurity for a column.