Skip to main content

Permissions & data access

Connect docs via MCP

Once users are in your workspace, permissions control what they can see and do. Atlan layers a few mechanisms, and which one you reach for depends on what you are scoping: access by team, by data sensitivity, by connection, or hiding specific assets entirely.

Your platform role sets the ceiling on what is possible at all. Personas and purposes then scope that access to the right assets. The sections below help you pick the right control.

Which control to use

Personas or purposes?

The two main controls scope access along different dimensions, and most teams use both together:

Use a persona when…
Access depends on who the user is. You want a team to see a curated slice of the catalog and land on a tailored view.
Scope team access
Use a purpose when…
Access depends on how assets are tagged. You want the same rule to apply to every PII or confidential asset, no matter which team owns it.
Protect sensitive data

How layers combine

Role, persona, and purpose stack. Your platform role sets the ceiling, personas and purposes add scoped grants (a user gets the union of all their grants), and an explicit deny in any policy overrides every grant, including the Admin role. For the full evaluation order and the "which wins" table, see how access policies combine.