## Set up team access (persona) URL: https://docs.atlan.com/product/capabilities/governance/access-control/how-tos/create-a-persona > Create a persona in Atlan to scope what a team sees and can do: define access policies, add members, and set the UI experience for a team or function. Create a persona to scope what a team sees in Atlan and what they can do with those assets. A persona bundles a set of users and groups, the [metadata, data, and domain policies](https://docs.atlan.com/llms/governance/access-control/what-are-purposes/llms.txt) that govern their access, and the display preferences (landing page, sidebar tabs, asset filters) that shape their view. Once you create the persona, every user or group you add inherits its policies and view automatically. ## Prerequisites - You are an **admin** in Atlan, or you have the **Governance Admin** [sub-role](https://docs.atlan.com/llms/governance/access-control/delegate-administration/llms.txt). - You know who the persona is for: which users or groups will belong to it, and which assets or actions you want to scope. - You have a plan for the persona's policies: metadata, data, business graph, and domain policies are all optional, but a persona without policies doesn't actually grant any access yet. ## Create persona 1. In your Atlan workspace, click **Settings** from the left menu. If you are using the **Old UI (Classic)**, from the left menu, click **Admin**. 2. Click **Persona** to open the personas list. 3. Click the **Get started** button (if this is your first persona) or the **New persona** button (if you already have personas). 4. Enter a meaningful **name** for the persona, optionally a description, then click **Create**. You now have an empty persona. The next sections add users, policies, and preferences. ## Add users and groups A persona needs at least one user or group to do anything. You can add more (or remove members) at any time. 1. Open the persona, then click the **Add** button to the right of the _Users and groups_ box. 2. Select users, groups, or both: - Under the **single-user icon**, select individual users. - Under the **double-user icon**, select groups. 3. Click **Update** to save. Members immediately inherit the persona's policies (none yet, until you add them in the next section) and view. ## Add policies Policies are how the persona actually grants or restricts access. Add one policy per set of assets and permissions you want to control. The higher the level you define the policy at, the better: for example, a policy at the database level automatically covers future schemas and tables in that database. 1. In the persona, switch to the **Policies** tab. 2. Click **New Policy** and choose the type that fits what you want to control: - **Metadata policy**: grants or restricts permissions to change metadata (descriptions, ownership, tags, custom metadata, data quality rules). - **Data policy**: grants or restricts permissions to query data and preview samples. - **Business Graph policy**: controls which assets appear in the business graph view for users in this persona. - **Domain policy**: grants or restricts access to specific domains and their assets. :::warning Glossary policies require manual updates for new glossaries There is no "All Glossaries" option in persona policies. Each glossary must be added to the persona policy individually. When a new glossary is created in your workspace, it is **not automatically included** in any existing persona policies. You must manually add it to each affected persona. If users outside the intended scope can see a new glossary, this is almost always the cause. ::: ### Add metadata policy 1. Choose **Metadata Policy**. 2. Under _Name_, briefly describe the policy's intention, for example, *Marketing team: read-only on Snowflake*. 3. Under _Select a connection_, choose the connection on which to apply the policy. 4. (Optional) Under _Asset selector_, narrow the policy to specific assets. By default, all assets in the connection are included. - Click the **x** in the _All assets_ box, then click the **Add** link. - In the _Add Assets_ dialog, choose **Browse** (pick from databases), **Search** (find individual assets), or **Custom** (use qualified names). :::info Custom selector tip With the custom asset selector, you can add `/*` after a database name to select all schemas inside it. ::: 5. (Optional) Under _Configure permissions_, click **Edit** to choose which [permissions the policy grants](https://docs.atlan.com/product/capabilities/governance/access-control/metadata-policy). By default, all permissions are granted. Hover over each checkbox to see what it controls. 6. (Optional) Under _Deny selected permissions_, choose whether the policy should explicitly **deny** these permissions instead of granting them. :::warning Deny overrides every grant If enabled, this denial overrides grants from any other policy for the same users, across every persona they belong to. ::: 7. At the bottom of the _Metadata Policy_ sidebar, click **Save**. :::warning Policies don't expand automatically when a workflow discovers new asset types, as it doesn't assume they automatically have access to those assets. If a new workflow run surfaces an asset type not covered by the policy (for example, View after a Glue re-crawl), then non-admin persona users lose edit access to those assets. To account for this, return to the persona, open the affected metadata policy, and add the new asset type to the asset selector. ::: ### Add data policy {#add-data-policy} To grant or restrict permissions to query or preview data: 1. Choose **Data Policy**. 2. Under _Name_, briefly describe the policy's intention. 3. Under _Select a connection_, choose the connection on which to apply the policy. 4. (Optional) Under _Asset selector_, narrow the policy to specific assets. By default, all assets in the connection are included. Use the same Browse / Search / Custom flow described under metadata policies. 5. (Optional) Under _Deny Query_, choose whether the policy should explicitly deny the ability to query and preview data on these assets. :::warning Deny overrides every grant A deny overrides grants from any other policy for the same users, across every persona they belong to. ::: 6. Click **Save**. ### Add Business Graph policy 1. Choose **Business Graph Policy**. 2. Under _Name_, briefly describe the policy's intention. 3. Under _Select connection_, choose the connection to apply the policy to. 4. (Optional) Under _Asset selector_, narrow the policy to specific assets. By default, all assets in the connection are included. 5. Click **Save**. ### Add Domain policy 1. Choose **Domain Policy**. 2. Under _Name_, briefly describe the policy's intention. 3. Under _Select domain_, choose the domain or domains the policy applies to. 4. (Optional) Under _Configure permissions_, click **Edit** to choose which permissions the policy grants. By default, all permissions are granted. 5. Click **Save**. ## Add rich documentation (optional) Help other admins understand why this persona exists and who manages it. Inside the persona: - Under _Summary > Channels_, add any Slack channels relevant to the persona. - Under _Resources_, add links to external resources (PDFs, repositories, Notion, Confluence, Google Drive, or anything with a URL). - Under _Readme_, write a richly-formatted description of the persona. ## Set preferences (optional) Tailor what users in the persona see: landing page, asset types, sidebar tabs, filters, and custom metadata visibility. See [Customize the persona view](https://docs.atlan.com/llms/governance/access-control/configure-persona-preferences/llms.txt) for the full walkthrough. ## Need help? If a persona isn't granting access the way you expect, double-check whether any other persona the same user belongs to has a **deny** rule. Deny always wins. If you still need help, contact [**Atlan Support**](https://docs.atlan.com/support/submit-request). ## Next steps Now that the persona exists, populate it and shape what its members see: - [Add team members](https://docs.atlan.com/llms/governance/access-control/assign-users-and-groups-to-a-persona/llms.txt): Add the users and groups who inherit this persona. - [Customize the catalog view](https://docs.atlan.com/llms/governance/access-control/configure-persona-preferences/llms.txt): Set the landing page, visible asset types, sidebar tabs, and filters. - [Restrict asset visibility](https://docs.atlan.com/llms/governance/access-control/access-control-settings/llms.txt): Turn off the see-everything default so the persona's scope actually limits what users browse. ---