The Data Vault access role assignments determine the data that users can see when they run Data Discovery searches. The role assignments also determine the data that users can see when they view and create custom reports and dashboards.
After you create the Data Vault access roles, you assign the Data Vault access roles to one or more of the following objects:
Users
A Data Vault access role assignment is required. Users can only access data for entities or projects that have the same Data Vault access role assignment as the user.
Entities
A Data Vault access role assignment is optional. If you assign a Data Vault access role to an entity, access is restricted to all archived data from the entity, regardless of the project that includes the entity. Only users that have the Data Discovery role and the access role that is assigned to the entity can access the archived data from the corresponding entity.
If you view or create custom reports and dashboards, you must assign a Data Vault access role to each entity on which you want to base a report. Users that create or view a report must have the same role assignment as the entity on which the report is based.
Archive or Retirement Projects
A Data Vault access role assignment is optional for projects that have the Data Vault as the target connection. If you assign an access role to an archive or retirement project, access is restricted to data that is archived from the project. The assignment at the project level overrides the assignment at the entity level. If the project include entities that have role assignments, Data Discovery ignores the entity level assignment. Only users that have the Data Discovery role and the Data Vault access role that is assigned to the project can access the archived data.
You must assign a Data Vault access role to an entity or to a project. If you do not assign a Data Vault access role to an entity or to a project, no users have access to the archived data.
When you assign Data Vault access roles to users or entities, you specify a validity period of the role assignment. You determine when the role assignment begins. For example, you can assign a Data Vault access role to a user, but make the role assignment effective in two months. You can also determine when the role assignment ends. For example, you may want to assign a Data Vault access role to a user for a limited amount of time, such as a few months. By default, all role assignments do not have an end date unless you specify one.