Allow Access to a Repository
An Impersonation Policy maps identity provider (IdP) users or groups to a repository user. For the value an Impersonation Policy provides, see Impersonation Policy.
Prerequisites
Section titled “Prerequisites”- SSO and SCIM are configured for your organization.
- The repository and its repository users are registered to ALTR.
- The sidecar is installed and registered to ALTR, and bound to the relevant repositories.
Create an Impersonation Policy
Section titled “Create an Impersonation Policy”To create an Impersonation Policy:
- Log in to ALTR through your IdP.
- Click Policy in the navigation menu.
- Click Create Policy.
- Locate the Control access to repository users card and click Create Policy.
- Locate the card for your database and click Create Policy.
- Enter a Display Name to identify the policy.
- Select the Data Source — the repository name as registered in ALTR.
- Click Next.
- Build the rule statement:
- Select a user or group and enter its Name — an individual IdP user or a group (for example,
Marketing team) as configured in your IdP. - Select the Repository User the IdP user or group will impersonate.
- (Optional) Expand IdP User/Group to add additional users or groups to the same rule.
- Select a user or group and enter its Name — an individual IdP user or a group (for example,
- Click Save.
Data consumers can now connect, using a temporary token instead of the repository user’s credentials — see Connect to a Repository through Impersonation for the connection steps.
Edit an Impersonation Policy
Section titled “Edit an Impersonation Policy”To edit a policy:
- Click Policy in the navigation menu.
- Expand the policy to edit.
- Click Edit Policy.
- Update the policy as needed.
- Click Save.
Delete an Impersonation Policy
Section titled “Delete an Impersonation Policy”To delete a policy:
- Click Policy in the navigation menu.
- Expand the policy to delete.
- Click Edit Policy.
- Click Delete Policy; a modal displays to confirm.
- Click Delete Policy.