Add custom metadata
Learn how to add custom metadata to your data assets in Atlan.
Learn how to add custom metadata to your data assets in Atlan.
You can add descriptions to your assets in Atlan, including tables, views, and individual columns. You can even add a description in the form of a [README](/product/integrations). Doing so enriches your data asset with the relevant contextual information.
Complete guide to administering and configuring your Atlan workspace, from basic settings to advanced customization.
Add Atlan's addresses to your Databricks workspace IP access list (or a corporate firewall in the path) so crawlers and miners can connect.
Enable a public IP on your AlloyDB for PostgreSQL instance and admit only Atlan's tenant-specific egress IPs through authorized networks.
Everything IP- and firewall-related for dbt - dbt Cloud's IP restrictions feature, and storage-side firewalls for dbt Core buckets.
The three gatekeepers that can sit between Atlan and Tableau - Tableau Cloud's IP allowlist, your firewall, and WAF content rules - and how to open each.
Integrate Atlan with Always On to enable continuous automation and suggestions.
What identity Atlan presents to your AWS account for AWS Glue, which values are tenant-specific, and exactly what to request from support in a single ticket.
The Atlan-side values an Amazon S3 role setup needs, what each is for, and how to get them in a single support ticket.
Integrate Atlan with AWS Lambda to automate workflows and triggers.
Use the Atlan browser extension to access metadata directly inside your data tools without leaving your workflow.
The Amazon S3 second doors - bucket policies, KMS key policies, and how to scope Atlan's access down to a single prefix.
Comprehensive REST APIs for managing apps, authentication, metadata operations, and configuration.
Atlan enables you to use spreadsheet tools to collaborate on assets with your team, make bulk metadata updates, and sync changes back to Atlan.
Atlan currently supports native integration with [Apache Airflow/OpenLineage](/apps/connectors/lineage/apache-airflow-openlineage/how-tos/integrate-apache-airflow-openlineage).
You can [create webhooks](/product/integrations/automation/webhooks/how-tos/create-webhooks) in Atlan to configure alerts or triggers for downstream actions for metadata change events, including schema changes. You can also configure alerts for asset creation or deletion events.
Refer to our [troubleshooting Jira documentation](/product/integrations/project-management/jira/troubleshooting/troubleshooting-jira) to learn more.
A number of Atlan's [supported connectors](/product/connections/references/connectors-and-capabilities) use a JDBC- or REST API-based approach for metadata extraction. If you are attempting to connect to a source with no native integration, [contact Atlan support](/support/submit-request) to share more details about your use case.
Atlan also allows you to [export your glossary assets](/product/integrations/collaboration/spreadsheets/how-tos/export-assets) to spreadsheets and keep a record of your contextual information.
You can query any data warehouse (DW) or data lake (DL) if the integration is supported via Atlan's [supported sources](/product/connections/references/supported-sources). Once integrated, you can query the underlying data using the [Data Exploration](/product/capabilities/insights/how-tos/query-data) feature.
Learn about can site renaming affect the jira integration?.
Learn about can the hive crawler connect to an independent hive metastore?.
The exact IAM permissions Atlan needs for AWS Glue, plus the Lake Formation grants whose absence silently empties crawls instead of raising errors.
Compare the three ways Atlan can reach your AlloyDB for PostgreSQL instance - the self-deployed runtime, Private Service Connect, and public IP with authorized networks.
Pick the right AWS identity type and network path for Atlan to connect to Amazon Athena - IAM access keys, IAM role delegation, or either with AWS PrivateLink.
Compare the three ways Atlan can reach your Amazon Redshift cluster or Serverless workgroup - public IP allowlisting, the AWS private network link, and the self-deployed agent.
Pick the identity Atlan uses to read your Amazon S3 metadata - a cross-account IAM role it borrows, or an IAM user whose keys you hand over.
Pick how Atlan proves its identity to AWS Glue - IAM access keys, a cross-account IAM role, or the self-deployed agent.
Compare the three ways Atlan can reach your Cloud SQL for PostgreSQL instance - public IP with authorized networks, the self-deployed runtime, and Private Service Connect.
Compare the two ways Atlan can read your dbt metadata - the dbt Cloud API with a token, or dbt output files in a cloud storage bucket for dbt Core.
Pick the network path and authentication method Atlan uses to reach Google BigQuery - public API endpoint or Private Service Connect, service account key or Workload Identity Federation.
Compare the three ways Atlan can reach your PostgreSQL database - internet with IP allowlisting, private connectivity, or a self-deployed agent - and pick the right one before touching any firewall.
Compare the three ways Atlan can reach your Snowflake account—public IP allowlisting, Private Link, and the self-deployed agent—and pick the right one before you touch any cloud configuration.
Compare the three ways Atlan can reach your Microsoft SQL Server - direct with IP allowlisting, a private network link, or the self-deployed runtime - and pick the right one before you touch any firewall.
Compare the four ways Atlan can reach your Tableau environment - direct, direct with IP allowlisting, AWS PrivateLink, and the self-deployed agent.
Configure ADFS authentication for Amazon Redshift connections using ADFS (Active Directory Federation Services) as the identity provider.
Configure Snowflake data metric functions <Badge variant="preview" text="Private Preview" link="/get-started/references/product-release-stages#private-preview" />
Learn about configure workflow execution.
Keep your Cloud SQL for PostgreSQL instance private - run a small Atlan-provided agent inside your network that reads metadata locally and sends it to Atlan over outbound HTTPS only.
Point Atlan at your dbt Cloud account using a token - four phases including the IP-restrictions network step most guides skip.
Connect dbt Core to Atlan - your pipeline uploads dbt's output files to a cloud bucket (S3, GCS, ADLS, or Atlan-managed) and Atlan reads them.
Connect Atlan to a SQL Server that is reachable from the internet - including Azure SQL Database with "Selected networks" enabled. Four phases, each labeled with who performs it.
Connect Atlan to Cloud SQL for PostgreSQL over the instance's public IP, with Cloud SQL's authorized-networks list and SSL keeping everyone else out.
The fastest path to connect Atlan to PostgreSQL - Atlan connects to your database's public endpoint over TLS, and you allowlist Atlan's fixed egress IPs. Five phases, each labeled with who performs it.
Connect Atlan to Tableau Cloud in four phases - service account and PAT, host and site, IP restrictions if enabled, configure and test.
Connect Atlan to Tableau Server - everything from the Cloud guide plus the two Server-only steps, enabling the Metadata API and getting SSL certificates right.
Connect Atlan to a private AlloyDB for PostgreSQL instance with the self-deployed runtime - a small service in your network that reads AlloyDB locally and sends metadata out over outbound-only HTTPS.
The recommended way to connect Atlan to AWS Glue - Atlan assumes a role you create, so no long-lived secret ever leaves your account.
The fastest path to connect Atlan to Amazon Athena - create a dedicated IAM user, attach the Atlan policy, and paste its access keys into Atlan.
The fastest path to connect Atlan to AWS Glue - create a read-only IAM user in your AWS account and give Atlan its key pair.
Set up cross-account IAM role delegation so Atlan connects to Amazon Athena with temporary credentials and no stored secret.
Once you have configured the [AWS Lambda permissions](/product/integrations/automation/aws-lambda/how-tos/set-up-aws-lambda), you can run an AWS Lambda function.
Adding an announcement to your data asset helps you call attention to an important feature or notify others about a change coming down the pipeline. Since announcements in Atlan display the time stamp and author information, you can easily identify whether an announcement is still relevant and who to ask for questions.
Admin users in Atlan can create, curate, and manage README templates from the governance center. Once admin users have created the templates, other users will be able to select these templates and [enrich their assets with READMEs](/product/integrations). They will also be able to see a rich preview of each template before adding the relevant documentation.
Learn about custom solutions.
General questions about connecting Atlan to your data sources, what metadata Atlan collects, and how to extend connectivity beyond native connectors.
Learn about delete a connection.
The Atlan Secure Agent is a Kubernetes-based application that runs within a customer's environment. It acts as a gateway between the single-tenant Atlan SaaS and external systems like Snowflake, Tableau, and other data sources. This document explains the Secure Agent's deployment architecture, key components, communication flows, and security considerations.
Once you've [connected Atlan with Google Sheets](/product/integrations/collaboration/spreadsheets/how-tos/integrate-atlan-with-google-sheets), you can download impacted assets in Google Sheets. This can help you assess the downstream impact of any changes made to an upstream asset for [impact analysis](/product/capabilities/lineage/concepts/what-is-lineage#impact-analysis).
Once you've [connected Atlan with Microsoft Excel](/product/integrations/collaboration/spreadsheets/how-tos/integrate-atlan-with-microsoft-excel), you can download impacted assets in Microsoft Excel. This can help you assess the downstream impact of any changes made to an upstream asset for [impact analysis](/product/capabilities/lineage/concepts/what-is-lineage#impact-analysis).
Atlan supports [Snowflake OAuth-based authentication](https://docs.snowflake.com/user-guide/oauth-snowflake-overview) for [Snowflake](/apps/connectors/data-ware.
Configure Okta SSO authentication for Amazon Redshift connections in Atlan, including Okta app setup, AWS identity provider configuration, and Atlan connection settings.
Credentials are used to obtain an access token from Google's authorization servers for authentication in Atlan.
Configure PingFederate as the External OAuth identity provider so Atlan Data Exploration queries on your Snowflake connection authenticate as each end user.
Set up OAuth SSO authentication for Databricks connections in Atlan.
Overview and entry point for all ETL tools connectors in Atlan.
Allow Atlan's fixed source IPs through your security group so crawlers and miners can connect to publicly accessible Amazon Redshift clusters and workgroups.
SQL Server traffic from Atlan usually crosses several firewalls, owned by different teams. Every layer, which Atlan value belongs in each, and the mistakes that generate the most support tickets.
The reference for gates 1 and 2 - what to allowlist where, how pg_hba.conf decides, and how to keep the SSL settings on both ends consistent. Applies to every connectivity method.
Learn why AlloyDB for PostgreSQL is hard to reach from outside, and what each of the three connection paths - self-deployed runtime, Private Service Connect, and public IP - actually does.
Learn about how are product updates deployed?.
Understand the three connectivity paths between Atlan and Databricks—public, Private Link, and site-to-site VPN—and what determines which one applies to your workspace.
Learn the two Tableau APIs Atlan uses, how sign-in works with PATs and Connected Apps, and where Tableau connections typically get blocked.
Learn how Atlan reaches Google BigQuery, why there are no IP addresses to allowlist on the main path, and the four traffic hops that matter.
Learn the three traffic paths between Atlan and your Cloud SQL for PostgreSQL instance, who owns each piece, and why connectivity is not authentication.
Learn how Atlan reads your AWS Glue Data Catalog - the traffic path, the two ways of proving identity, and the two-key door that makes role-based access safe.
Learn how Atlan reads Amazon S3 - IAM roles, trust policies, External IDs, and the four AWS doors every crawl must pass through.
A plain-language explanation of the journey a connection makes from Atlan to your PostgreSQL database - the three gates it must pass, the three paths it can take, and SSL in one minute.
Learn the three traffic paths between your dbt setup and Atlan - the dbt Cloud API pull, the storage-bucket read, and your own upload pipeline.
Sending messages and searching assets from Slack are disabled. Refer to [Troubleshooting Slack](/product/integrations/collaboration/slack/troubleshooting/troubleshooting-slack) to learn more.
Learn about how does atlan handle lineage from spark jobs?.
Learn how Atlan borrows an identity in your AWS account for Amazon Athena, why there are two halves to set up, and the four traffic paths a healthy connection uses.
Learn what a private link is, who is responsible for each part of the setup, and the three traffic paths between Atlan and Snowflake.
Learn how Redshift-managed VPC endpoints work, who builds which half, and the three traffic paths between Atlan and Amazon Redshift.
A plain-language explanation of where Atlan's crawler actually runs, the three traffic paths to your SQL Server, and how authentication rides on top of the network path.
Configure and run the Atlan ALTR workflow to import ALTR classification results into Atlan.
Learn about infrastructure security.
Create an ingestion workflow in Atlan to fetch data quality metadata from Bigeye and enrich your existing assets with DQ insights.
Create an ingestion workflow in Atlan to fetch data quality metadata from Telmai and enrich your existing assets with DQ insights.
Once you have [configured the Anomalo settings](/apps/connectors/observability/anomalo/how-tos/set-up-anomalo), you can establish a connection between Atlan and Anomalo.
Create an ingestion workflow in Atlan to fetch data quality metadata from Ataccama ONE and enrich your existing assets with DQ insights.
The Atlan add-on for Google Sheets makes it easy to edit column metadata in bulk for your data assets in Atlan.
The Atlan add-in for Microsoft Excel makes it easy to enrich metadata in bulk for your data assets in Atlan. You can use the Atlan add-in for both the web and desktop versions of Microsoft Excel.
Configure the Immuta workflow in Atlan to enrich data assets with Immuta access request links and column masking exception requests.
You must have at least one issue already created in Jira before integrating it with Atlan. This will enable Atlan to detect whether the Atlan app is installed in your Jira workspace for the integration to work.
You will need to [configure an incoming link](https://confluence.atlassian.com/adminjiraserver/configure-an-incoming-link-1115659067.html) with an external application - in this case, Atlan. This will allow Atlan to access Jira data, which means that Jira will act as the OAuth provider.
Install and configure the Atlan Assistant (Teams marketplace app) and connect your Atlan tenant to Microsoft Teams.
If your Atlan admin has [enabled the governance workflows and inbox module](/product/capabilities/governance/stewardship/how-tos/automate-data-governance) in your Atlan workspace, you can create a ServiceNow integration to allow your users to [grant or revoke data access](/product/capabilities/governance/stewardship/how-tos/automate-data-governance) for governed assets in Atlan or any other data source.
To integrate Slack and Atlan, follow these steps.
Connect Atlan to Microsoft Teams using the custom app approach. Use this method if you have an existing legacy setup or need specific deployment configurations.
Integrate Atlan with Jira to automate ticket creation and link your Jira account.
To [export assets to and bulk enrich metadata from](/product/integrations/collaboration/spreadsheets/how-tos/export-assets) a supported spreadsheet tool,.
To create and link Jira issues inside Atlan, you may first need to link your Jira account. This is done automatically for the admin user that [set up the Jira integration](/product/integrations/project-management/jira/how-tos/integrate-jira-cloud), but not for other users.
To request or revoke data access through ServiceNow inside Atlan, you may first need to link your ServiceNow account. This is done automatically for the user that [set up the ServiceNow integration](/product/integrations/project-management/servicenow/how-tos/integrate-servicenow), but not for other users.
To see previews of Slack messages inside Atlan, you may need to first link your Slack account. This is done automatically for the user that [set up the Slack integration](/product/integrations/collaboration/slack/how-tos/integrate-slack), but not for other users.
:::warning Who can do this? You must be an admin user to manage custom metadata structures, including defining new ones.
If your organization's [Slack account is integrated with Atlan](/product/integrations/collaboration/slack/how-tos/integrate-slack), you will receive Slack notifications when your requests are approved or rejected.
Understand all about the new marketplace Teams flow, including the technical nitty-gritties.
Integrate Atlan with Microsoft Teams to enable collaboration and notifications.
Once you've scheduled or run a workflow you can modify its configuration at any time. The configuration that can be modified may vary by workflow but the general steps remain consistent.
Monitor your data connection workflows and identify failures for troubleshooting.
Configure OpenLineage integration with Atlan — capture lineage metadata from Airflow, Spark, and other data processing tools.
The complete permission surface an Amazon Athena connection needs - including Lake Formation, KMS, and the S3 results bucket that cause most "test passed, crawl failed" issues.
Connect Atlan to a SQL Server that has no public access, over AWS PrivateLink or Azure Private Link - one common five-phase pattern covering EC2, RDS, Azure VM, and Azure SQL Database / Managed Instance.
Keep traffic between your GCP-hosted Atlan tenant and your Cloud SQL for PostgreSQL instance entirely on Google's internal network with Private Service Connect.
Learn about provide credentials to view sample data.
Learn about provider package versions for openlineage.
Learn about report on assets.
You can track asset enrichment through [suggestions from similar assets](/product/integrations/automation/always-on/references/suggestions-from-similar-assets). You can also view top users who have accepted automated suggestions.
Integrate Atlan with ServiceNow to automate ticket creation and link your ServiceNow account.
Once the Atlan team has confirmed the configuration is ready, please continue with the remaining steps.
:::warning Who can do this? You will need your AWS administrator involved - you may not have access to run these tasks yourself.
Create the database user Atlan connects to Amazon Redshift as, grant it read permissions, and choose one of the three authentication methods.
Atlan supports basic authentication (SCRAM-SHA-1, username and password) and IAM authentication (MONGODB-AWS) for fetching metadata from Amazon DocumentDB. This guide walks you through creating a crawl user with the permissions Atlan needs.
For all details, see [Databricks documentation](https://docs.databricks.com/administration-guide/cloud-configurations/aws/privatelink.html).
Atlan supports the API authentication method for fetching metadata from [Anomalo](https://docs.anomalo.com/integrations/atlan-integration). This method uses an API key to fetch metadata.
Set up the service account Atlan connects to Google BigQuery as, and choose between a service account JSON key and Workload Identity Federation.
Connect Atlan to a private Amazon Redshift cluster over a Redshift-managed VPC endpoint, so traffic never crosses the public internet.
Connect Atlan to an AWS-hosted Databricks workspace over AWS PrivateLink, so traffic never crosses the public internet.
Set up AWS PrivateLink between your Snowflake account and your Atlan tenant, including cross-region configurations.
Private connectivity from Atlan to Azure Database for PostgreSQL is a support-assisted VNet peering setup - what to ask for, what you configure yourself, and the caveats to insist on before signing off.
Connect Atlan to an Azure Databricks workspace over Azure Private Link, including the endpoint approval handshake and the NSG rule.
Configure the Fivetran Platform Connector and destination to enable Atlan to extract Fivetran metadata and logs.
Private connectivity to PostgreSQL on Google Cloud depends on what the database is - Cloud SQL and AlloyDB have Private Service Connect paths under their own connectors; self-managed Postgres uses the self-deployed agent.
Keep Atlan's BigQuery API traffic off the public internet with Google Private Service Connect - Atlan builds the private endpoint; you paste one DNS name.
Atlan supports SCRAM authentication (SCRAM-SHA-1 and SCRAM-SHA-256) for fetching metadata from MongoDB. This method uses a [username and password](#create-database-user) to fetch metadata.
Atlan supports the basic authentication method for fetching metadata from MongoDB. This method uses a username and password to fetch metadata
:::warning Who can do this? You will probably need your Monte Carlo [account owner](https://docs.getmontecarlo.com/docs/authorizationmanaged-roles-and-groups).
The Docker-based databricks-extractor offline tool has been sunset. For on-premises or network-restricted Databricks lineage extraction, use Self-Deployed Runtime, Secure Agent, or direct connectivity via private link.
Connect your Microsoft Teams account to get direct message alerts for starred assets in Atlan.
Let Atlan's SaaS reach your AlloyDB for PostgreSQL privately over Google's internal network - no public IP, nothing deployed on your side beyond a service attachment.
The production-recommended way to connect Atlan to Amazon S3 - Atlan temporarily assumes a role in your AWS account, with no secret created or exchanged.
The fully self-serve way to connect Atlan to Amazon S3 - create an IAM user, attach the permission policy, and paste its keys into Atlan.
Configure Salesforce authentication and connection with Atlan. Set up OAuth or JWT Bearer flow for secure integration with Sales Cloud and Financial Services Cloud.
Integrate Atlan with Slack to enable collaboration and notifications.
Tableau special cases - AWS PrivateLink, fully on-premises servers, Server-to-Cloud migrations, multiple sites, and org changes that quietly break connections.
Google BigQuery special cases - multiple projects, Delta external tables, Data Quality with WIF, per-user SSO, credential rotation, and the Lakehouse integration.
AlloyDB for PostgreSQL special cases - fleets of instances, very large databases, cross-cloud tenants, and connection paths that rewrite the port.
Amazon Athena special cases - PrivateLink, cross-account Glue catalogs, cross-region sources, very large catalogs, and multiple Atlan tenants.
Cloud SQL for PostgreSQL special cases - IAM authentication done right, cross-cloud tenants, multiple instances and read replicas, and private IPs that quietly change.
On-premises SQL Server via the self-deployed runtime, Windows/NTLM and Entra ID authentication quirks, Azure SQL Managed Instance failover listeners, and estates with many environments and ports.
On-premises PostgreSQL, many databases behind one PrivateLink, Aurora failovers and moving IPs, Azure and GCP hosting, cross-region IAM authentication, and VPC Lattice.
AWS Glue special cases - multiple AWS accounts, multiple regions, cross-account resource links, S3 Table Bucket federated catalogs, and the circuit breaker.
dbt special cases - multiple environments, token rotation, Core migration, managed buckets, shared IAM roles, Cloud and Core in parallel.
Amazon S3 special cases - multi-million-object buckets, multiple AWS accounts, Atlan-hosted bucket flows, External ID limitations, and the region field.
Multiple workspaces, extra hostnames and custom ports, cross-cloud and cross-region setups, site-to-site VPNs, and the reversed traffic of lakehouse and MCP integrations.
Amazon Redshift Serverless, DC2 clusters, multiple clusters, cross-region and cross-cloud tenants, external (Glue/Spectrum) schemas, and sources reachable only from inside your network.
Reference for the parameters and field mappings when PingFederate is the OAuth identity provider for Snowflake query authentication.
Connect to data sources — out-of-the-box connectors or custom integrations using App Framework and Open APIs.
Resolve common issues with the Atlan browser extension, including loading errors, blank pages, and missing metadata icons.
Learn about troubleshooting Cube connectivity, including authentication, deployment and environment selection, and missing lineage.
Troubleshoot Jira integration issues with error, cause, and solution guidance.
Learn about troubleshooting metabase connectivity.
Why do I get an error while adding Atlan to Microsoft Teams?
Learn about troubleshooting Mixpanel connectivity, including authentication, service-account permissions, and description write-back.
Learn about troubleshooting mode connectivity.
Learn about troubleshooting Omni connectivity, including authentication, permissions, and missing lineage.
Troubleshoot PingFederate OAuth errors when querying Snowflake from Atlan Data Exploration, with error, cause, and solution guidance.
Learn about troubleshooting redash connectivity.
Why is the security\_admin role required to complete the ServiceNow integration?
Learn about troubleshooting sisense connectivity.
What do the colors in Slack notifications for modified assets mean?
Why do I need admin consent for exporting assets to Microsoft Excel?
Learn about troubleshooting thoughtspot connectivity.
Once you've [connected Atlan with Google Sheets](/product/integrations/collaboration/spreadsheets/how-tos/integrate-atlan-with-google-sheets), you can import the column metadata for all your data assets in Atlan and make changes to them directly in Google Sheets.
Once you've [connected Atlan with Microsoft Excel](/product/integrations/collaboration/spreadsheets/how-tos/integrate-atlan-with-microsoft-excel), you can import the column metadata for all your data assets in Atlan and make changes to them directly in Microsoft Excel.
Learn how to share assets, link conversations, and receive notifications using Atlan in Microsoft Teams.
You can refine the search for your assets in Atlan using the filters menu. Add filters to your asset search to find assets that are more relevant to you.
View audit logs to track configuration changes made to your workflow connections.
The Google services and VPC Service Controls ingress rules your security team must allow for Atlan to reach Google BigQuery.
Learn about what does atlan crawl from cloudera impala?.
During a Metabase crawl, Atlan extracts metadata for Collections, Dashboards, and Questions. Reference tables map each Metabase property to its Atlan asset.
Atlan crawls and maps the following assets and properties from Microsoft SQL Server.
Atlan crawls and maps the following assets and properties from Mode.
With two of your most important workspaces connected, you can save time and improve the way you track issues for your data.
With two of your most important workspaces connected, you can save time and improve the way you share data assets with your team.
Learn about the features and capabilities of the Slack integration with Atlan.
Learn about what is the crawler logic for a deprecated asset?.
Learn about what's the difference between connecting to athena and glue?.
Monitor workflow execution and asset creation — track lineage coverage, connection metadata, and extraction progress.