tencent cloud


Data Development and Governance Platform

Last updated: 2024-06-29 09:57:39

    Fundamental information

    Product Abbreviation in CAM Console Authorization by Tag Authorization Granularity IP Restriction
    WeData wedata Supported not supported Resource level Partially supported


    The authorization granularity of cloud products is divided into three levels: service level, operation level, and resource level, based on the degree of granularity.

    • Service level: It defines whether a user has the permission to access the service as a whole. A user can have either full access or no access to the service. For the authorization granularity of cloud products at service level, the authorization of specific APIs are not supported.
    • Operation level: It defines whether a user has the permission to call a specific API of the service. For example, granting an account read-only access to the CVM service is an authorization at the operation level.
    • Resource level: It is the finest authorization granularity which defines whether a user has the permission to access specific resources. For example, granting an account read/write access to a specific CVM instance is an authorization at the resource level.

    API authorization granularity

    Two authorization granularity levels of API are supported: resource level, and operation level.

    • Resource level: It supports the authorization of a specific resource.
    • Operation level: It does not support the authorization of a specific resource. If the policy syntax restricts a specific resource during authorization, CAM will determine that this API is not within the scope of authorization, and deem it as unauthorized.

    Write operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    AssociateProjectCluster AssociateProjectCluster Operation level * not supported
    CreateBaseProject create base project Operation level * Supported
    CreateBizCatalog create catalog Operation level * Supported
    CreateBizCatalogs create catalog template Operation level * Supported
    CreateDuty Create Duty Operation level * Supported
    CreateDutySchedule Create Duty Schedule Operation level * Supported
    CreateProject create project Operation level * Supported
    CreateRestrictTypeV2 CreateRestrictTypeV2 Operation level * not supported
    CreateScheduleCalendar CreateScheduleCalendar Operation level * not supported
    CreateTableMetaAscriptions create table meta ascription Operation level * Supported
    CreateTag create tag Operation level * not supported
    CreateTenantUser create user Operation level * not supported
    CreateWorkspace create workspace Operation level * Supported
    DeleteDuty Delete Duty Operation level * Supported
    DeleteDutySchedule Delete Duty Schedule Operation level * Supported
    DeleteScheduleCalendar DeleteScheduleCalendar Operation level * not supported
    DeleteTag delete tag Operation level * not supported
    DisableProject Disable Project Operation level * Supported
    EnableProject Enable Project Operation level * Supported
    ModifyApproveStatus Modify Approve Status Operation level * Supported
    ModifyBizCatalog update catalog Operation level * Supported
    ModifyHttpChannelConfig Modify Http Channel Config Operation level * Supported
    ModifyTag update tag Operation level * not supported
    RefreshNotebookWorkspaceResource RefreshNotebookWorkspaceResource Operation level * not supported
    RemindScheduleCalendarConfig RemindScheduleCalendarConfig Operation level * not supported
    SaveIndicatorV2 SaveIndicatorV2 Operation level * not supported
    UpdateScheduleCalendar UpdateScheduleCalendar Operation level * not supported
    UpdateScheduleCalendarDetail UpdateScheduleCalendarDetail Operation level * not supported
    UpdateScheduleCalendarDetailByFile UpdateScheduleCalendarDetailByFile Operation level * not supported

    Read operations

    API API Description Authorization Granularity Six-segment Resource Description IP Restriction
    CodeCompletionColumns code completion columns Operation level * not supported
    DescribeAssetHistory describe asset history records Operation level * not supported
    DescribeBriefTenantProjects describe tenant project list Operation level * Supported
    DescribeDataAssetSearchTop describe data asset search history records Operation level * not supported
    DescribeDataAssets Describe data asset Operation level * not supported
    DescribeDataSourceResourceList DescribeDataSourceResourceList Operation level * Supported
    DescribeDimensionV2 search dimension info V2 Operation level * not supported
    DescribeEngineComponentsValid verify data engine Operation level * Supported
    DescribeEngineRegions list data engine available regions Operation level * not supported
    DescribeEngines list data engines Operation level * Supported
    DescribeExecutorResourceGroupPage DescribeExecutorResourceGroupPage Resource level qcs::wedata:${region}:uin/${uin}:schedule/${executorGroupId}
    not supported
    DescribeNetServers DescribeNetServers Operation level * not supported
    DescribeOpsPreviewMakePlanTask preview make task list Operation level * not supported
    DescribeResourcePackagesRequest DescribeResourcePackagesRequest Resource level qcs::wedata:${region}:uin/${uin}:schedule/${resourceId}
    DescribeRestrictTypesV2 DescribeRestrictTypesV2 Operation level * not supported
    DescribeScheduleCalendarDetail query Schedule Calendar Detail Operation level * not supported
    DescribeScheduleCalendarPageList qury Schedule Calendar info list Operation level * not supported
    DescribeScheduleCalendarUploadFileParam DescribeScheduleCalendarUploadFileParam Operation level * not supported
    DescribeServersVersion DescribeServersVersion Operation level * not supported
    DescribeServiceRoleExists verify wedata service role Operation level * Supported
    DescribeTaskLineage To describe task table lineage by taskId Operation level * not supported
    DescribeTchousePClusters get tchousep list Operation level * Supported
    DescribeTenant describe tenant Operation level * Supported
    DescribeTenantProjects describe tenant project list Operation level * Supported
    DescribeTenantUserList describe tenant user list Operation level * Supported
    DescribeUserProjects describe user project list Operation level * Supported
    DescribeVersionInfo DescribeVersionInfo Resource level qcs::wedata:${region}:uin/${uin}:platform/${resourceId} Supported
    DescribeWorkspaceDuplication check workspace duplication Operation level * Supported
    DescribeWorkspaceEngines list workspace engines Operation level * Supported
    DescribeWorkspaceRegions list workspace available regions Operation level * not supported
    DescribeWorkspaceUser list user detail information Operation level * Supported
    DescribeWorkspacesByUser list workspaces which include user Operation level * not supported
    DiagnoseRuleGroupExec Diagnose rule group execute error Operation level * not supported
    GetJobsWithoutExecutions GetJobsWithoutExecutions Operation level * not supported
    ListWorkspacesByPage list workspaces by page Operation level * not supported
    ScheduleCalendarExport ScheduleCalendarExport Operation level * not supported
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support