VegaGraph access control

Resource-family and object permissions, subject types, visibility and least privilege.

VegaGraph applies authorization before returning graph objects or traversal results. Knowing an ID does not make the object visible.

Set up users, groups, roles and service principals through platform access management, then grant the graph permissions required by each consumer.

Permissioned resources

Collection- and instance-level permission APIs exist for:

  • entity types and aspect types;
  • relationship types;
  • contexts;
  • entities and field references;
  • edges;
  • labels;
  • search.

Assignments can target users, groups, roles and service principals.

API pattern

POST   /entities/{entity_id}/permissions
DELETE /entities/{entity_id}/permissions

GET /entities/{entity_id}/permissions/users
GET /entities/{entity_id}/permissions/groups
GET /entities/{entity_id}/permissions/roles
GET /entities/{entity_id}/permissions/service-principals

Equivalent collection paths such as /entities/permissions manage type-wide or resource-family policy. Subject-specific routes expose direct and derived grants.

Visibility rules

  • List and search results contain only visible resources.
  • Traversal cannot use an invisible intermediate node to disclose its existence.
  • A not-found response does not distinguish a missing object from a cross-workspace or non-visible object.
  • Field and aspect access cannot exceed the visibility of their parent entity.
  • Context selection does not bypass access to canonical or inherited facts.

Write dependencies

Creating an entity requires permission for the entity resource and use of its entity type. Aspect writes require access to the entity and aspect type. Edge writes require access to both endpoints, optional field endpoints and the relationship type.

Type mutation and impact preview require broader administrative rights because they can affect many graph records.

RoleTypical responsibility
Graph viewerSearch and read approved entities, aspects, edges and views.
Metadata stewardCurate ownership, descriptions, labels and reviewed classifications.
Connector publisherUpsert source-owned entities/aspects/edges using a service principal.
Type designerCreate and evolve workspace type contracts and run impact previews.
Graph administratorManage permissions, protected types and governance policy.

Use a separate service principal per connector/source domain. Grant it only the type families and relationship paths it publishes.

Sensitive fields

Authorization is not a reason to store secrets in the graph. Store only a managed secret reference when a relationship to a credential is necessary. Treat evidence URLs and source locations as potentially sensitive and scope them accordingly.

Vegalake, VegaDB and VegaFlow are trademarks or registered trademarks of Vegalake Inc.

On this page