You create data filter rules to control access to rows or records of data.
1Open a data filter policy and select the Rules tab.
2 Click the plus sign.
The Overview tab appears.
3Enter a name and a description for the rule.
The following image shows the Overview tab:
4Click Next.
The Rule tab appears. On this tab, specify the conditions under which Data Access Management will deny access to data records. The options in the Conditions section depend on whether the data filter policy that includes this rule uses the Data Integration/Data Marketplace enforcement method or the pushdown enforcement method.
The following image shows the Conditions section of the Rule tab for the Data Integration/Data Marketplace enforcement method:
The following image shows the Conditions section of the Rule tab for the pushdown enforcement method:
5In the Conditions section, click New Row in the For section.
6For each condition, select an attribute, an operator, and relevant values.
aSelect a contextual attribute, such as User Group.
bSelect an operator, such as is any of.
cClick Add Value to select the value of the contextual attribute.
7Click New Row again to create another condition.
8For the pushdown enforcement type, click New Row in the And assets in section.
aClick Add Filter to select the catalog source type and data assets.
The Add Filter window appears.
The following image shows the Add Filter window:
bEnter a search query to find the data assets that you want to grant permissions to.
The Preview section shows the current results of that query. Adjust your search query to refine the results as needed.
Note the following about query results:
▪ The preview returns results based on currently accessible metadata. This might change with the addition of other assets that match the filter query.
▪ Don't use the universal wildcard * because it grants access to all tables and views within the identified Data Governance and Catalog catalog source type.
▪ A single permission assignment has a limit of 2,000 assets. If your query results in more than 2,000 assets, partition your filter across multiple rules to reduce the number of assets in the query.
▪ For each data filter asset with a pushdown enforcement type, Data Access Management only processes the first 10,000 columns.
cClick the Filter icon.
dClick the Add Filter link, and select Catalog Source Type.
Note:
Data access control policies only work with specific catalog source types.
For more information on catalog source types, see Catalog Source Quick Reference in the Data Governance and Catalog help.
eSelect a catalog source type.
fClick Add Filter again, and select Asset Type.
gSelect one or more asset types.
hClick the Add Filter button to return to the Rule section of the Rule tab.
iClick New Row again to create additional filters.
You have now created conditions and filters for this rule.
Creating filters for data filter rules
After you create conditions for data filter rules, you create filters to deny access to data. Filters can determine if a rule activates when a single condition is true or when all conditions are true.
1 In the Filter section of the Rule tab, click New Row.
The following image shows the Filter section of the Rule tab:
2Click Select Data Element Classification.
The Select Data Element Classification window appears.
Note:
If a data element has multiple data classifications, Data Access Management denies access to the row if any of the classifications matches the filter criteria.
The following image shows the Select Data Element Classification window:
3Enter a search query to find the data assets.
The Preview section shows the current results of the query. Adjust your search query to refine the results as needed.
4Click a result and click Select to assign the data classification and return to the Rule tab.
5Select a data type.
Note:
If you use data filter rules involving dates that might be applied in Access Policy transformations in Data Integration, create a data filter rule with two distinct criteria. In one criterion, use the date data type. In the other criterion, use the timestamp data type with the same values as the first criterion. This second criterion is for the Access Policy transformation.
6Select an operator.
Note:
The data type you select determines list of available operators. Not all operators work with all data types.
7Click Add Value.
Note:
Text strings are case-sensitive. The timestamp values that you enter are converted to and stored in Coordinated Universal Time (UTC).
8Click Add Value again to add more values.
9Click New Row to select another data element classification.
aAdd the data element classification, data type, operator, and values as needed.
10 Continue this process until you have specified filters for the required data element classifications.
Data Access Management denies access to a field if it meets any one of the filters.
11Save the rule.
Your updates take effect when the policy associated with the rule is published.
If you do not have a workflow configured, the rule will automatically change to published status.
If you have a workflow configured, the rule and its associated policy will change to draft status.
For more information about designing workflows, see Workflows in the Metadata Command Center help.
Note:
You can monitor the process to push down the policy initiated by using the data access sync job type on the Monitor page in Metadata Command Center.
For more information about data access sync jobs, see Monitor data access jobs in the Metadata Command Center help.