VegaGraph access control
Resource-family and object permissions, subject types, visibility and least privilege.
VegaGraph applies authorization before returning graph objects or traversal results. Knowing an ID does not make the object visible.
Set up users, groups, roles and service principals through platform access management, then grant the graph permissions required by each consumer.
Permissioned resources
Collection- and instance-level permission APIs exist for:
- entity types and aspect types;
- relationship types;
- contexts;
- entities and field references;
- edges;
- labels;
- search.
Assignments can target users, groups, roles and service principals.
API pattern
POST /entities/{entity_id}/permissions
DELETE /entities/{entity_id}/permissions
GET /entities/{entity_id}/permissions/users
GET /entities/{entity_id}/permissions/groups
GET /entities/{entity_id}/permissions/roles
GET /entities/{entity_id}/permissions/service-principalsEquivalent collection paths such as /entities/permissions manage type-wide or resource-family policy. Subject-specific routes expose direct and derived grants.
Visibility rules
- List and search results contain only visible resources.
- Traversal cannot use an invisible intermediate node to disclose its existence.
- A not-found response does not distinguish a missing object from a cross-workspace or non-visible object.
- Field and aspect access cannot exceed the visibility of their parent entity.
- Context selection does not bypass access to canonical or inherited facts.
Write dependencies
Creating an entity requires permission for the entity resource and use of its entity type. Aspect writes require access to the entity and aspect type. Edge writes require access to both endpoints, optional field endpoints and the relationship type.
Type mutation and impact preview require broader administrative rights because they can affect many graph records.
Recommended roles
| Role | Typical responsibility |
|---|---|
| Graph viewer | Search and read approved entities, aspects, edges and views. |
| Metadata steward | Curate ownership, descriptions, labels and reviewed classifications. |
| Connector publisher | Upsert source-owned entities/aspects/edges using a service principal. |
| Type designer | Create and evolve workspace type contracts and run impact previews. |
| Graph administrator | Manage permissions, protected types and governance policy. |
Use a separate service principal per connector/source domain. Grant it only the type families and relationship paths it publishes.
Sensitive fields
Authorization is not a reason to store secrets in the graph. Store only a managed secret reference when a relationship to a credential is necessary. Treat evidence URLs and source locations as potentially sensitive and scope them accordingly.