User Access to Alation Analytics V2¶
Alation Cloud Service Applies to Alation Cloud Service instances of Alation
Customer Managed Applies to customer-managed instances of Alation
Available from version 2020.3
DB Connections page behavior by access level available from version 2026.7.0.0.
Note
If you created your Alation Analytics database username and password before this version, they are not affected by this change. You can continue to use the same username and password to connect to Alation Analytics. No action is required on your part.
Important
You are viewing documentation for Alation’s Classic User Experience.
Alation Analytics V2 is a private data source. This means users must be granted access to this data source before they can use it.
Note
Alation Analytics V2 cannot be set to Public. The Public option on the Access tab of the settings is disabled for this data source.
Starting with version 2024.3, access can be granted to both individual users and groups, including built-in, custom, and SCIM groups. In earlier versions, only individual users can be granted access.
Users with the Server Admin, Source Admin, or Catalog Admin roles who are also designated as Data Source Admins for this data source can grant access to other users and groups.
Grant Access to Alation Analytics¶
To grant access:
Find Alation Analytics V2 in the catalog. You can use Search or click on Data Sources in the left-side navigation to open the Data Sources page and locate it from the list of data sources.
Open the catalog page of Alation Analytics V2.
In the upper-right corner of the page, click the three-dots icon and in the menu that opens, under Manage, click Settings. The Access tab of the data source settings page opens.
Note
Server Admins without current access to Alation Analytics can initially grant access to themselves before adding other users and groups. If you attempt to access the settings of a data source you don’t manage, a warning—Edit Your Permissions to Access Settings—will appear after you click on Settings. Click Go to Access in the popup. This action will direct you to the Access tab on the data source settings page. From there, follow the steps to first grant access to yourself.
Find Alation Analytics V2 in the catalog. You can use Search or browse through the Sources page to find it.
Open the catalog page of Alation Analytics V2.
In the upper-right corner of the page, click More and then click Settings. The Access tab of the data source settings page opens.
Note
Server Admins without current access to Alation Analytics can initially grant access to themselves before adding other users and groups. If you attempt to access the settings of a data source you don’t manage, a warning—Edit Your Permissions to Access Settings—will appear after you click on Settings. Click Go to Access in the popup. This action will direct you to the Access tab on the data source settings page. From there, follow the steps to first grant access to yourself.
Under the section People, click Add on the right, and in the search widget that opens, start typing a username or a group name. The list will update accordingly. Click the user or group in the list. This user or group will be granted access and added to the Viewers & Data Source Admins table.
All new users and groups, including Server Admins, are initially added with the access level Viewer. You can change the access level in the Access Level column of the Viewers & Data Source Admins table. For a specific user or group, click the list of options in the Access Level column, and select the access level you want to assign:
Data Source Admin—Can manage the data source settings, grant access to users and groups, and query the data source. A database account is automatically created for Data Source Admins to access Alation Analytics.
Querier—Can view the extracted metadata on the data source catalog page and query Alation Analytics in Compose. A database account is automatically created for Queriers to access Alation Analytics.
Viewer—Can view the extracted metadata or edit custom fields on the data source catalog page. They don’t receive an account to query Alation Analytics.
Note
If a user belongs to a group with a certain access level and is also granted access as an individual user, the highest access level will be retained. For example, if the user is part of a group with Querier access and is added individually as a Viewer, the higher Querier access level will prevail.
Users with Querier or Data Source Admin access to Alation Analytics also gain visibility of the Analytics navigation icon and both the Classic Alation Analytics tile and the Chat with Alation Analytics tile. This applies whether access is granted directly to the user or through a group.
Users with the Querier or Data Source Admin access must create a database user for their Alation Analytics account before connecting to the source from Compose or Snowflake. What you see on the DB Connections tab depends on your current access level to the Alation Analytics data source.
Set Up Database Account for Alation Analytics V2¶
Users granted the Querier or Data Source Admin access to Alation Analytics V2 must complete the setup of their Alation Analytics database account before they can query this database in Compose or from Snowflake.
DB Connections Page Messages by Access Level¶
The DB Connections tab on the Profile Settings page displays a different message or a different set of actions depending on your access level to the Alation Analytics data source.
Access Level |
What Appears on the DB Connections Tab |
|---|---|
No access |
A message stating that you must be added to Alation Analytics before you can create a PostgreSQL or Snowflake connection. |
Viewer |
A message stating that you do not have permission to create a connection. |
Querier or Data Source Admin |
A Create User action for each available connection type. PostgreSQL is always available. Snowflake appears only if it is enabled for your instance. |
Note
If you do not have access, or if you have Viewer access, contact a Server Admin, Catalog Admin, or Source Admin to request or upgrade your access.
If you were granted Querier or Data Source Admin access before this behavior was introduced, your existing username and password continue to work as before. Your username continues to appear with a single Update password action. No action is required on your part.
Create a Database User¶
To query Alation Analytics in Compose, create a database user for each connection type that is available to you.
To create a database user:
Click the User icon in the upper right-hand corner of Alation.
Click Profile Settings to open the Profile Settings page.
Click the DB Connections tab.
Under Alation Analytics Connection, locate the connection type you want to set up.
Click Create User next to PostgreSQL Username or Snowflake Username.
Enter a new password in the New Password field.
Re-enter the same password in the Confirm New Password field.
Click Create User.
Important
The username field in this dialog is prefilled and cannot be changed. See Database Username Conventions for how each username is generated.
Database Username Conventions¶
Alation generates your database username automatically. You cannot choose or edit it.
PostgreSQL username: matches your Alation username exactly.
Snowflake username: your Alation username prefixed with your instance subdomain. This prevents username conflicts when the same person has accounts on multiple instances from the same customer, such as development and production.
Note
The Snowflake Username column only appears if Snowflake is enabled for your instance. If Snowflake is not enabled, only the PostgreSQL Username column is shown.
Update Your Database Password¶
Update your database password from the DB Connections tab at any time.
To update your database password:
Click the User icon in the upper right-hand corner of Alation.
Click Profile Settings to open the Profile Settings page.
Click the DB Connections tab.
Next to the username you want to update, click Update password.
Enter a new password in the New Password field.
Re-enter the same password in the Confirm New Password field.
Click Update password.
Password criteria differ depending on the connection type.
Your new PostgreSQL password must meet the following criteria:
Must be at least 14 characters long.
Must contain at least one digit.
Must contain at least one uppercase letter and one lowercase letter.
Must not contain any special characters.
Your new Snowflake password must meet the following criteria:
Must be at least 14 characters long.
Must contain at least one digit.
Must contain at least one uppercase letter and one lowercase letter.
Must not match any of the last five passwords used.
Note
If your account predates this feature, a single Update password action updates your password for both PostgreSQL and Snowflake, if enabled. Accounts created after this feature maintain separate passwords for PostgreSQL and Snowflake.
View Your Snowflake Username¶
Applies to Alation Cloud Service instances
After you create or update your Alation Analytics database password, the DB Connections tab shows your PostgreSQL Username and Snowflake Username in the Alation Analytics Connection table.
Note the following behavior:
The Snowflake Username column appears only on Alation Cloud Service instances. On customer-managed (on-premises) instances, only the PostgreSQL Username is shown.
The URI column only appears on customer-managed (on-premises) instances, and is not shown on Alation Cloud Service instances.
The Snowflake Username column is not shown until you have created your Alation Analytics database password.
After you create or update your password, the Snowflake Username column displays your current Snowflake login name.
If your Snowflake login name changes after a password update, the Snowflake Username column updates immediately.
To update your password, click Update Password in the Actions column.
Effect of Access and Account Changes on Database Users¶
Changes to your Alation account or your access level to Alation Analytics affect your PostgreSQL and Snowflake database users.
Change |
Effect on the Database User |
|---|---|
Access downgraded from Querier or Data Source Admin to Viewer |
The corresponding PostgreSQL and Snowflake users are removed. |
Access to Alation Analytics revoked |
The corresponding PostgreSQL and Snowflake users are removed. |
Alation account suspended |
The user cannot log in to PostgreSQL or Snowflake with their existing username and password. Access is restored automatically with the same credentials once the account is reactivated. |
Alation account permanently deleted |
The corresponding PostgreSQL and Snowflake users are removed, if they exist. |
Important
If Querier or Data Source Admin access is restored after a downgrade or removal, the user must create a new database user, since the previous one was removed.
Accessing Data via Snowflake Data Sharing¶
Applies from version 2025.3.1
You can get direct, read-only access to the entire Alation Analytics database within your own Snowflake account. This method uses Snowflake’s native data sharing technology and is the recommended approach for performing cross-reporting by joining analytics data with your organization’s own datasets.
This provides a powerful way to generate custom reports and insights by leveraging your own BI tools and data warehouse. For more information, see Share Alation Analytics Data with Your Snowflake Account
Revoke Access to Alation Analytics¶
To revoke access to Alation Analytics from a user or group:
Open the settings of the Alation Analytics data source.
On the Access tab, in the Viewers & Data Source Admins table, find the user or group you’re revoking access from. You can use the table filter in the top right corner of the table to find users and groups. Start typing a name in the Filter field, and the Viewers & Data Source Admins table will update accordingly to display the names that match your search string.
For this user or group, click Remove. The corresponding Alation Analytics database account will be removed, and the user or group will no longer have access to the Alation Analytics data source.