{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"redocly_category":"Products","product_name":"Control Panel","type":"markdown"},"seo":{"title":"Verifying Successful Migration to Policy Based Database Permissions","description":"Treasure Data Product Documentation · Collect and Unify · Segment and Activate · Experiment and Analyze · Decisioning Automate with AI Scale and Trust.","siteUrl":"https://docs.treasuredata.com","lang":"en-US","llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"verifying-successful-migration-to-policy-based-database-permissions","__idx":0},"children":["Verifying Successful Migration to Policy Based Database Permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["With Policy-based Database permissions, you can assign the same policy to a group of users instead of setting up individual permissions for each user. Contact your Customer Success representative about enabling this feature."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After the Policy-based Database permission feature is enabled, database access at the user level is no longer available. You cannot revert to the previous database access (legacy)."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["If you recently migrated from Legacy Database Permissions to Policy-based Database Permissions, you may want to verify that you've migrated successfully by checking that you have the default permissions you were assigned in Legacy Database Permissions."]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"confirming-database-permissions---admin","__idx":1},"children":["Confirming Database Permissions - Admin"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can verify users' permissions and can verify your ability to set up database permissions by checking policies."]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"verify-your-own-database-permissions","__idx":2},"children":["Verify Your Own Database Permissions"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["After migration, you can verify your own permissions by checking the permissions assigned to you by default. You should see that you continue to have full permission for all databases."]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By default, a brand new administrator begins with no access to user-defined databases. After you've been promoted to an Administrator role by another TD Administrator you can grant yourself \"Full Access\" permissions by creating a policy or adding yourself to an existing policy with \"Full Access\" permission."]}]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Open Treasure Console."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Data Workbench"]},". Confirm you can see all your databases and you continue to be the administrator for the list of databases."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-3-22_12-5-38.a570666b0c80999ec292388e1f99c8485e844504a71ba90680b59be65a486df2.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verify-database-permissions-of-other-users---admin","__idx":3},"children":["Verify Database Permissions of Other Users - Admin"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["You can verify the legacy permissions of users who have migrated by checking their default policies."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open Treasure Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the Control Panel, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["User"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-22_15-17-59.c1c703691264fed2dd68360cc6cf5b39bb4e5e3ec3b86d1b9176aa1702b30f68.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":3},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select a user."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the right-hand panel, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Resources"]}," to view the databases. You may see variations depending on the previous permissions of the user."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Confirm the user has two additional default database permissions: Download Databases and Manage Own Databases, and that the user continues to have access to databases they had access to prior to the migration."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For example, a restricted user who had the following access permissions in the legacy system including ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Import Only"]}," access to DB \"admins_db_b\" database, ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Query Only"]}," access to \"admins_db_c\" database, \"sample_datasets\" database, \"information_schema\" database, and ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Full"]}," ",{"$$mdtype":"Tag","name":"em","attributes":{},"children":["Access"]}," for \"admins_db_a\" database and \"user1_db_a\" database, will have the following permissions upon enabling Database Policy-based Permissions."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-26_13-22-44.68f466a6cba55b009c246cfb51caa2c11b4845a703b33c039f17f68fbefb8e10.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verifying-default-policies-of-other-users---admin","__idx":4},"children":["Verifying Default Policies of Other Users - Admin"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As an admin, you can verify default policies to ensure the specified user has the same access they had prior to migration."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open Treasure Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the Control Panel, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Users"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-22_15-17-59.c1c703691264fed2dd68360cc6cf5b39bb4e5e3ec3b86d1b9176aa1702b30f68.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":3},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Policies"]},"."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm the user continues to have the same policies they had access to prior to the migration plus additional policies that describe the user's database permissions."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["For each user, the following three policies will automatically be created after migration, depending on the legacy permissions they have. Learn more by reviewing the ",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/products/control-panel/security/policies/policy-based-database-permissions-matrix"},"children":["Policy-based Database Permissions Matrix"]},"."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Legacy: Full Access"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Policy created:"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Database edit for {user_id}"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["What it means:"]}," The user retains general (full) access to the database. If user A has user ID ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["1234"]},", the policy name becomes ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Database edit for 1234"]},"."," ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-26_13-24-31.5fcada4926bff85fdce6adde774fdfa10e6200e82626c01abc38763251692c69.9f549006.png","alt":""},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Legacy: Query Only"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Policy created:"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Database query for {user_id}"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["What it means:"]}," The user keeps query-only access to the database."," ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-26_13-23-29.c8f1cd5c6ad884f69aba163fb6ac12f2a94ec05542536b3390b2102cb8dc8d6e.9f549006.png","alt":""},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Legacy: Import Only"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Policy created:"]}," ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["Database import for {user_id}"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["What it means:"]}," The user retains import-only access to the database."," ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-26_13-23-53.184f3326840543cd65ee0da296df32031dbae09344686d085618c02372038ab7.9f549006.png","alt":""},"children":[]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"verify-database-permissions-of-new-users---admin","__idx":5},"children":["Verify Database Permissions of New Users - Admin"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open Treasure Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["From the Control Panel, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["User"]},". As an admin, you can verify default policies."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-22_15-17-59.c1c703691264fed2dd68360cc6cf5b39bb4e5e3ec3b86d1b9176aa1702b30f68.9f549006.png","alt":""},"children":[]}," ","3. Search for a new user."," ","4. From the right-hand panel, select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Resources"]}," to view the databases. You may see variations depending on the previous permissions of the user."," ","5. Confirm the user has access to two default query-only databases ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sample_datasets"]}," , ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["information_schema."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-9-26_15-23-52.046688d4da09c35545109a41755bfba8da9429fe81caa767fbb0a8733807e97d.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"confirming-database-permissions---restricted-user","__idx":6},"children":["Confirming Database Permissions - Restricted User"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["As a restricted user, you can verify the database permissions you have following migration."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open Treasure Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Data Workbench."]}," ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-7-30_6-47-11.489efc8dce92745603ae22f5351eef4f4106e82d2e8e5911463143dddb810897.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["My Settings > Resources."]}," ",{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-8-2_12-26-39.02896110e1d3b6bebab5cc5df019fe70b45548f1ab3c27edc35889cfecf60bf4.9f549006.png","alt":""},"children":[]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Hover over the question mark beside ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Permission"]}," to view your permissions. You can see the explanation of what each permission allows you to do. For example, Manage Own allows you to create, edit, and delete databases you created."]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-3-11_16-40-43.a9dd8ab44fdc39a29617fdc432a5d68429bbfcbdb27493a2e5d4d0c71a82ddcf.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"confirming-database-permissions---newly-created-user","__idx":7},"children":["Confirming Database Permissions - Newly Created User"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["By default, new users would not have any policies attached to their profiles. Each user has access to default databases, which can only be queried."]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Open Treasure Console."]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Data Workbench"]},"."]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-3-11_16-27-14.c22afdb9d1ebe6b5ad375e0a9ed8ba5ea08e8377804e0527e2dc867552e112ed.9f549006.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":3},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Select ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["Databases."]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Confirm you have limited viewing capabilities and query-only access to sample datasets set up by your organization and that each user has access to two default query-only databases",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["sample_datasets"]}," , ",{"$$mdtype":"Tag","name":"code","attributes":{},"children":["infomation_schema."]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2021-8-2_12-32-29.12d395577053a841cc3bd3856da358d70ce3539f54ed5d6a5708da91bba09da8.9f549006.png","alt":""},"children":[]}]}]},"headings":[{"value":"Verifying Successful Migration to Policy Based Database Permissions","id":"verifying-successful-migration-to-policy-based-database-permissions","depth":1},{"value":"Confirming Database Permissions - Admin","id":"confirming-database-permissions---admin","depth":2},{"value":"Verify Your Own Database Permissions","id":"verify-your-own-database-permissions","depth":3},{"value":"Verify Database Permissions of Other Users - Admin","id":"verify-database-permissions-of-other-users---admin","depth":2},{"value":"Verifying Default Policies of Other Users - Admin","id":"verifying-default-policies-of-other-users---admin","depth":2},{"value":"Verify Database Permissions of New Users - Admin","id":"verify-database-permissions-of-new-users---admin","depth":2},{"value":"Confirming Database Permissions - Restricted User","id":"confirming-database-permissions---restricted-user","depth":2},{"value":"Confirming Database Permissions - Newly Created User","id":"confirming-database-permissions---newly-created-user","depth":2}],"frontmatter":{"seo":{"title":"Verifying Successful Migration to Policy Based Database Permissions"}},"lastModified":"2026-06-01T09:09:59.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/products/control-panel/security/policies/verifying-successful-migration-to-policy-based-database-permissions","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}