{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["img"]},"redocly_category":"Products","product_name":"Control Panel","type":"markdown"},"seo":{"title":"About Policies and Permissions","description":"Learn how to use policies and permissions to manage user access to Treasure Data features and data, including database, workflow, Audience Studio, and authentication permissions.","siteUrl":"https://docs.treasuredata.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"about-policies-and-permissions","__idx":0},"children":["About Policies and Permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As part of Treasure Data's Trust for CDP, Treasure Data provides security management using policies and permissions. The Policies feature is available only to accounts that have purchased the feature. Contact your Treasure Data representative to obtain the Policies feature."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/image2023-5-8_10-49-47.2f18684f1a98eb5c357981b72481112fb8b1487bea4cbdb0957258987b6ab123.f0cddcd7.png","alt":"Policies overview in Treasure Console","withLightbox":false},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["The policy feature increases your level of control and security and makes it easier to manage user access to features and data. You grant users access rights through the use of policies. Policies combine permissions together so you can configure multiple policies and assign one or more policies to one or more users."]},{"$$mdtype":"Tag","name":"Image","attributes":{"src":"/assets/image2021-1-21_8-34-55.ac30dd06345a302bb99e946fa828ff19a314f8de85d75937e3f96e07ddca8afa.f0cddcd7.png","alt":"Policies and permissions relationship diagram","withLightbox":false},"children":[]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Account Owner and Administrator users define and control the TD policies and permissions."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"about-permissions","__idx":1},"children":["About Permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Permissions enable users to:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Perform an operation, such as table modification or segment activation"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Act upon a specified entity, such as a database or segment"]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"managing-policies","__idx":2},"children":["Managing Policies"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/creating-policies"},"children":["create"]},", ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/applying-policies"},"children":["apply"]},", and ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/deleting-policies"},"children":["delete"]}," policies in Treasure Console's Control Panel. Before creating policies, ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/plan-your-policy-structure"},"children":["plan your policy structure"]}," to establish naming conventions and organize permission levels."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"permission-categories","__idx":3},"children":["Permission Categories"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Policy-based permissions allow Owner and Administrator users to set permissions per policy and then apply that policy to specific users. The following permission categories are available:"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Database permissions"]},": Control access levels (full access, query-only, import-only) for individual databases. You can set permissions through ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/setting-policy-based-database-permissions-in-td-console"},"children":["Treasure Console"]}," or the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/setting-policy-based-database-permissions-using-the-api"},"children":["API"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Workflow permissions"]},": Control what users can do with workflows and projects, including view, run, and edit operations. You can configure ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/project-level-permissions"},"children":["project-level permissions"]}," for fine-grained access control."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Audience Studio permissions"]},": Manage access to master segments, segment folders, activations, and predictive scoring within ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/policy-based-audience-studio-permissions"},"children":["Audience Studio"]},"."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Authentication permissions"]},": Control which users can create, view, edit, and delete ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/policy-based-authentications-permissions"},"children":["authentication connections"]}," used by integrations and activations."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Column-level access control"]},": Restrict visibility of specific columns in databases using ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/policy-based-column-level-access-control-permissions"},"children":["column-level access control permissions"]}," to protect sensitive data."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["LLM permissions"]},": Control access to ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/policy-based-llm-permissions"},"children":["LLM features"]}," within Treasure Data."]}]}]}]},"headings":[{"value":"About Policies and Permissions","id":"about-policies-and-permissions","depth":1},{"value":"About Permissions","id":"about-permissions","depth":2},{"value":"Managing Policies","id":"managing-policies","depth":2},{"value":"Permission Categories","id":"permission-categories","depth":2}],"frontmatter":{"seo":{"title":"About Policies and Permissions","description":"Learn how to use policies and permissions to manage user access to Treasure Data features and data, including database, workflow, Audience Studio, and authentication permissions."}},"lastModified":"2026-06-01T09:09:59.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/control-panel/security/policies","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}