Skip to main content
Version: 0.0.38

Groups

Groups are collections of users that serve as the foundation for access control and permission management within Lakehousecat. All permissions for objects such as models, data sources, dashboard charts, and other resources are managed through group-based assignments rather than individual user permissions.

Overview​

The group system provides a scalable and maintainable approach to access control by:

  • Centralizing Permission Management: All access rights are assigned to groups rather than individual users
  • Simplifying User Administration: Users inherit permissions from their group memberships
  • Enabling Role-Based Access: Groups can represent different organizational roles, departments, or project teams
  • Maintaining Security: Only administrators can create and manage groups, ensuring controlled access management

Group Management Access​

Administrator Only

Group creation and management is restricted to users with the Administrator role. Regular users cannot create, modify, or delete groups, ensuring centralized control over the permission system.

Creating and Managing Groups​

Accessing Group Management​

  1. Login: Sign in to your Lakehousecat workspace with administrator credentials
  2. Navigate to Access: Go to the main navigation and select the Access section
  3. Open Groups Tab: Click on the Groups tab to view all existing groups

Viewing Existing Groups​

The Groups interface displays:

  • Group List: All existing groups in the workspace
  • Group Names: Clear identification of each group
  • Member Count: Number of users assigned to each group
  • Creation Date: When each group was established
  • Last Modified: Most recent changes to group configuration

Creating a New Group​

To create a new group:

  1. Click the Plus Icon (➕) in the Groups interface
  2. Enter Group Name: Provide a descriptive name for the group
  3. Add Description (Optional but Recommended): Include details about the group's purpose and intended use
  4. Save: Click "Create" to establish the new group

Group Naming Best Practices​

For effective group management, follow these naming conventions:

Department-based: "data-science-team", "marketing-department", "finance-users"
Role-based: "analysts", "data-engineers", "model-reviewers"
Project-based: "project-alpha-team", "customer-analytics-group"
Access-level: "read-only-users", "power-users", "data-contributors"

Group Configuration​

Required Fields​

  • Group Name: Unique identifier for the group (required)
    • Use descriptive, meaningful names
    • Follow consistent naming conventions
    • Avoid special characters and spaces

Optional Fields​

  • Description: Detailed explanation of the group's purpose
    • Recommended for all groups
    • Include information about intended use cases
    • Specify any special access requirements or limitations

Managing Group Members​

Adding Members to a Group​

  1. Select Group: Click on the group you want to modify
  2. Edit Group: Click the "Edit" or gear icon to open group details
  3. View Available Users: The interface displays all users that can be assigned to the group
  4. Add Members: Click the "Add" button next to users you want to include
  5. Save Changes: Click "Save" to apply the membership changes

Removing Members from a Group​

  1. Access Group Details: Open the group editing interface
  2. View Current Members: See all users currently assigned to the group
  3. Remove Members: Click the "Remove" button next to users you want to exclude
  4. Confirm Changes: Click "Save" to apply the updates

Member Management Interface​

The group editing dialog provides:

  • Available Users List: Shows all users who can be added to the group
  • Current Members List: Displays users already in the group
  • Add/Remove Controls: Simple buttons for membership management
  • Search Functionality: Find specific users quickly in large user bases
  • Batch Operations: Select multiple users for simultaneous add/remove actions

Permission Integration​

Group-Based Permissions​

All access control in Lakehousecat operates through groups:

  • Models: Access to view, edit, or deploy models
  • Data Sources: Permissions to read from or write to data sources
  • Dashboards: Rights to view, create, or modify dashboard charts
  • Analytics: Access to different analytical tools and reports
  • Administrative Functions: System configuration and user management rights

Permission Inheritance​

Users automatically inherit all permissions assigned to their groups:

  • Multiple Group Membership: Users can belong to multiple groups and inherit combined permissions
  • Permission Union: Users receive the union of all permissions from their groups
  • Dynamic Updates: Permission changes to groups immediately affect all group members

Group Management Workflows​

Organizational Structure Mapping​

Design groups to reflect your organization:

Example Corporate Structure:
├── executives
├── data-science-team
├── business-analysts
├── data-engineers
├── marketing-team
└── external-consultants

Project-Based Groups​

Create temporary or project-specific groups:

Example Project Groups:
├── project-customer-segmentation
├── project-fraud-detection
├── project-recommendation-engine
└── project-market-analysis

Access Level Groups​

Establish different permission tiers:

Example Access Levels:
├── viewers (read-only access)
├── contributors (read-write access)
├── power-users (advanced features)
└── administrators (full control)

Best Practices​

Group Design Principles​

  1. Keep Groups Focused: Each group should have a clear, specific purpose
  2. Use Descriptive Names: Group names should immediately convey their purpose
  3. Document Group Purpose: Always include descriptions explaining the group's role
  4. Regular Review: Periodically audit group memberships and permissions
  5. Minimal Privilege: Grant only the permissions necessary for the group's function

Scaling Group Management​

For large organizations:

  • Hierarchical Naming: Use consistent prefixes or suffixes for related groups
  • Regular Audits: Schedule periodic reviews of group memberships
  • Documentation: Maintain external documentation of group purposes and policies
  • Automation: Consider API-based group management for large-scale operations

Security Considerations​

  • Regular Access Reviews: Audit group memberships quarterly or bi-annually
  • Principle of Least Privilege: Only grant necessary permissions
  • Separation of Duties: Use different groups for different organizational functions
  • Emergency Access: Maintain procedures for urgent access modifications

Troubleshooting​

Common Issues​

Cannot Create Groups​

  • Verify Administrator Role: Ensure you have administrator privileges
  • Check Login Status: Confirm you're logged in with the correct account
  • Browser Issues: Try refreshing the page or clearing browser cache

Users Not Visible for Assignment​

  • User Account Status: Verify target users have active accounts
  • Permission Conflicts: Check if users are already in conflicting groups
  • System Synchronization: Allow time for user directory synchronization

Group Changes Not Reflected​

  • Save Confirmation: Ensure you clicked "Save" after making changes
  • Cache Refresh: Users may need to log out and back in to see new permissions
  • System Propagation: Allow time for permission changes to propagate

Advanced Topics​

API Integration​

Groups can be managed programmatically through the Lakehousecat API:

# Create a new group
curl -X POST /api/groups \
-H "Authorization: Bearer <token>" \
-d '{"name": "data-analysts", "description": "Data analysis team"}'

# Add user to group
curl -X POST /api/groups/{group-id}/members \
-H "Authorization: Bearer <token>" \
-d '{"user_id": "user-123"}'

Bulk Operations​

For large-scale group management:

  • CSV Import: Import group memberships from spreadsheets
  • LDAP Integration: Synchronize groups with existing directory services
  • Automated Assignment: Use rules-based group assignment for new users

Monitoring and Reporting​

Track group usage and effectiveness:

  • Membership Reports: Generate reports on group sizes and compositions
  • Permission Audits: Review what permissions each group provides
  • Usage Analytics: Monitor which groups access which resources most frequently