Data Lake Formation (DLF) enforces a two-layer permission model — API permissions and data permissions. A RAM user must pass both layers to access DLF features and data.
Permission check workflow
API permissions: Control whether a RAM user can call specific DLF APIs or access console pages. Managed through RAM system policies.
Data permissions: Control access to specific data lake assets such as catalogs, databases, and tables. Managed through DLF roles and authorization.
Related topics
Select the topic that matches your use case.
Scenario | Reference |
Set up DLF permissions for RAM users for the first time | |
View API-to-RAM-Action mappings | |
Manage DLF users and roles | |
Grant access to data resources (catalogs, databases, tables) | |
Configure row-level data filtering rules | |
Restrict REST API access by source VPC | |
Troubleshoot permission errors |