Skip to main content
Administrator Guide
Last Updated: 2026-08-07
Configure Data Lake Access Roles

Configure Data Lake Access Roles

See the Data Lake Setup in Workday section of Get Started with Workday Data Lake. This topic is part of a larger procedure.
The data refresh, according to the schedule on your Admin Console configuration, has run at least once.
Security:
Data Cloud: Manage Data Lake Access Policies
domain in the Data Cloud functional area.
After you add tables and columns to your data lake, you can configure data lake access roles to determine which users can read them. You create a data lake access role, assign one or more integration system users, and select the tables those users may read.
Workday Data Lake enforces these rules at the catalog layer. Access is enforced at the table level. Column selection is configured when you add tables and columns to the lake. Partner platforms may apply additional filters such as row or column access, but cannot grant access beyond what you assign here.
  1. Access the
    Data Lake Admin Console
    report.
  2. On the
    Access Management
    tab, select
    Add Data Lake Access Role
    .
  3. Enter an appropriate name and description for the role.
  4. From the
    Principal
    prompt, select an ISU you set up in Set Up Integration System Users for Data Lake.
  5. From the
    Object Access
    prompt, select tables the principal needs read access to. If the prompt is empty, review the Prerequisites section of this topic.
  6. Click
    Save
    .
After you click
Save
, the Data Lake access role is active in Polaris:
  • The principals you selected can authenticate to Data Lake (using credentials configured in Workday) only within the table scope you assigned on the role.
  • Principals can’t read Iceberg tables that you didn’t select from the
    Object Access
    prompt for that role.