Authorization Policy
Cedar-based authorization policies for Spice.ai Enterprise — fine-grained access control over datasets, models, tools, and endpoints.
Authorization Model
Entity types
Entity
Description
Notable attributes
Actions
Action
Applies to
Description
Configuration
runtime.authorization fields
runtime.authorization fieldsField
Type
Default
Description
PolicyDefinition
Field
Type
Description
Policy Examples
Default-deny baseline
Read-only analysts
Restrict a dataset to a single role
Block PII columns from non-privileged roles
Limit model invocation to a paid tier
Endpoint-level access (e.g. lock down /v1/sql)
/v1/sql)Policy Providers
Provider
Use case
Reload
Combining Policy with Identity SQL Functions
Distributed Cluster Behavior
Production Checklist
See also
Last updated
Was this helpful?