SAS Viya: CAS Authorization Window

Introduction

Use this window to manage access to caslibs, tables, and rows.

For concepts and background information, see CAS Authorization: Overview in SAS Viya: CAS Authorization.

Navigation

Here is one way to access the Authorization window for caslibs and tables:

  1. In the applications menu (applications menu icon), under ADMINISTRATION, select Manage Environment.
  2. In the vertical navigation bar in SAS Environment Manager, click the Data icon.
  3. On the Data page, locate and select a global caslib or table.
  4. Right-click, and select View authorization or Edit authorization.
    Note: If Edit authorization is not available, you are not authorized to modify access to the selected object.

Examine Access

Scope

The scope of the display is as follows:

  • There is always a row for Authenticated Users.
  • There is always a row for you, the currently connected user who is using the display.
  • There is a row for each principal that is assigned to an access control that affects access to the current object.
  • If you add an identity and do not give that identity at least one direct setting, that identity is automatically removed from the display.
  • You cannot directly remove a row. If you remove all direct settings for an identity and there is no other reason for that identity to be displayed, that identity is automatically removed from the display.
  • Only the permissions that are relevant for an object (directly or for inheritance purposes) are displayed for that object.
  • The display does not reflect the impact of CAS role membership or status.

Permissions

For each principal and permission, the following icons describe effective (net) access to the current caslib or table.

Effective Access Icons

Icon

Meaning

authorized icon

Authorized

not authorized icon

Not Authorized

row-level access icon

Row-Level

gray circle icon

Unknown

Note: An additional icon (diamond icon) indicates that a permission is directly assigned to the specified principal on the current object.

Access Levels

The Access Level column provides an alternative to interacting with individual permissions.

  • When you manage access, each access level is a shortcut for adding a set of direct access controls.
  • When you view access information, each access level is a shorthand description of a set of effective permissions.
Access Levels

Access Level

Permissions

No access

None

Read

Only ReadInfo and Select

Write

All except ManageAccess and AlterCaslib

Full control

All

Custom

Any other combination, including any row-level access

Note: Access levels exist only in the presentation layer in SAS Environment Manager. CAS stores and evaluates individual permissions, not cumulative access levels.

Set an Access Level

  1. Open the Edit Authorization window for a CAS object.
  2. If the principal that you want to work with is not already listed, click the Add identities icon. In the Add Identities window, move the user or group to the right pane, and click OK.
    Note: If guest access is enabled, you must select Add Identities after you click the Add identities icon. Or, if you need to add Guest to the display, select Add Guest after you click the Add identities icon.
  3. In the Access Level column, click and drag a gauge to adjust access.
    Note: If a gauge is not displayed, select an access level other than (custom) from the drop-down list.
    Note: Each time you change an access level, direct access controls are added as needed to meet the definition of the new access level. If you want to discard all unsaved changes, click Cancel.

    CAUTION

    Reducing the access level for a group that you belong to might block your access. To preserve your access, make sure you have a higher precedence (offsetting) direct grant. If you are a Superuser, this precaution is not strictly necessary.

  4. If you modified access for a group, click Preview. Examine the impact of the change on other principals. For example, increasing the access level for Authenticated Users from No access to Full control affects all authenticated users who do not have a more specific denial.
  5. Click Save.

Add a Direct Access Control

  1. Open the Edit Authorization window for a CAS object.
  2. If individual permissions are not already displayed, select the Show individual permissions check box.
  3. If the principal that you want to work with is not already listed, click the Add identities icon. In the Add Identities window, move the user or group to the right pane, and click OK.
    Note: If guest access is enabled, you must select Add Identities after you click the Add identities icon. Or, if you need to add Guest to the display, select Add Guest after you click the Add identities icon.
  4. Click the effective access icon (for example, the Authorized icon) for the principal and permission that you want to modify.
  5. In the pop-up window, select Grant or Deny in the Direct Setting drop-down list.

    CAUTION

    Before you deny access for a group that you belong to, make sure you have a higher precedence (offsetting) direct grant. If you are a Superuser, this precaution is not strictly necessary.

  6. If you modified access for a group, click Preview in the Edit Authorization window.
    • Notice that a diamond is displayed in the cell that you modified. The diamond indicates that effective access comes from a direct setting.
    • Examine the impact on other principals. For example, a direct denial for GroupA affects all members of GroupA who do not have their own direct settings.
  7. Click Save.

Remove a Direct Access Control

  1. Open the Edit Authorization window for a CAS object.
  2. In a cell that includes a diamond, click the effective access icon.
  3. In the pop-up window, select (none) from the Direct settings drop-down list.
  4. In the Edit Authorization window, notice that the new effective access value is unknown (gray circle icon). Click Preview.
    • Notice that the new effective access value is known. Or, if you removed the only setting that made the associated user or group a relevant principal for the current object, the user or group is no longer included in the display.
    • If you modified access for a group, examine the impact on other principals.
  5. Click Save.

Remove Multiple Direct Access Controls

  1. Open the Edit Authorization window for a CAS object.
  2. In a row that includes at least one direct setting, click the first cell. The row is selected.
  3. Click the clear all icon to remove all direct access controls for the selected identity.
  4. Notice that effective access for any affected cells is unknown (gray circle icon). Click Preview.
    • Notice that all effective access values are known. Or, if the associated user or group is no longer a relevant principal for the current object, the user or group is no longer included in the display.
    • If you modified access for a group, examine the impact on other principals.
  5. Click Save.

Examples: Manage Access to a Caslib

Provide Public Access to a Caslib

To give all users Read access to a new global caslib that you added:

  1. Open the caslib’s Edit Authorization window.
  2. In the row for Authenticated Users, increase the Access Level to Read.
  3. Click Save.

Provide Selective Access to a Caslib

To give a particular user Read and Write access to a new global caslib that you added:

  1. Open the caslib’s Edit Authorization window.
  2. Click the Add identities icon in the table toolbar.
  3. In the left pane of the Add Identities window, locate the user. Move the user to the right pane, and click OK.
  4. In the Edit Authorization window, increase the user’s Access Level to Write.
  5. Click Save.

Block All Access to a Caslib

To block all access for a particular identity:

  1. Open the caslib’s Edit Authorization window.
  2. If the identity is not already listed, click the Add identities icon in the table toolbar.

    In the left pane of the Add Identities window, locate the user, group, or custom group that you want to block. Move that identity to the right pane, and click OK.

  3. In the Edit Authorization window, decrease the identity’s Access Level to None.
  4. If the identity is not an individual user, click Preview. Examine the impact of your change on other listed identities.
  5. Click Save.

Limit Write Access to a Caslib

To allow only Read access for a particular identity:

  1. Open the caslib’s Edit Authorization window.
  2. If the identity is not already listed, click the Add identities icon in the table toolbar.

    In the left pane of the Add Identities window, locate the user, group, or custom group that you want to block. Move that identity to the right pane, and click OK.

  3. In the Edit Authorization window, decrease the identity’s Access Level to Read.
  4. If the identity is not an individual user, click Preview. Examine the impact of your change on other listed identities.
  5. Click Save.

Provide Row-Level (Filtered) Access

To make different subsets of rows available to different identities, set one or more row-level grants. Each row-level grant includes a filter that limits the available rows.

  1. Open the Edit Authorization window for a CAS table.
  2. If the principal that you want to work with is not already listed, click the Add identities icon. In the Add Identities window, move the user or group to the right pane, and click OK.
    Note: If guest access is enabled, you must select Add Identities after you click the Add identities icon. Or, if you need to add Guest to the display, select Add Guest after you click the Add identities icon.
  3. If individual permissions are not displayed, select the Show individual permissions check box.
  4. In the Select column, click an effective access icon.
  5. In the pop-up window, select Row-level Grant from the Direct setting drop-down list.
  6. In the Row-Level Filter window:
    1. Specify an expression that includes only the rows that the principal should be able to access. The basic format is: column-name operator value. Here are basic examples:
      Types and Examples of Row-Level Filters

      Type of Filter

      Example

      Numeric

      sales<1000

      Character

      Make='Ford'

      Dynamic

      user='SUB::SAS.Userid'

      For details, see Row-Level Access in SAS Viya: CAS Authorization.

      Note: If you view or edit a filter that was initially created programmatically, you might see escape characters and a different pattern of quotation marks.
    2. Click OK.
  7. In the Edit Authorization window, next to the new setting, notice that a diamond is displayed. The diamond indicates that effective access comes from a direct setting.
  8. If you modified access for a group, click Preview. Examine the impact on other principals.
  9. Click Save.

Identify the Source of Effective Access

To determine which access control causes a particular effective access result, examine the origins information for that result.

  1. Open the View Authorization window for the target CAS object.
  2. Click the effective access icon for which you want origins information.
  3. In the pop-up window, next to the Effective Access value, click the information icon.
    Note: The icon is disabled if you have changes that you have neither saved nor previewed.
  4. In the Origins window, review the displayed information.
    • The Source object field indicates where the determinative access control is set.
    • The Principals field indicates which identity the determinative access control are assigned to.
      Note: If multiple access controls of equal precedence cause the result, multiple principals are listed.

    For details, see Origins of Effective Access in SAS Viya: CAS Authorization.

Last updated: October 31, 2020