Skip to main content

Access Control

VeloDB Cloud uses organizations as top-level boundaries and separate identity and permission systems for console access, Management API requests, and warehouse SQL connections. Choose the path or scope that matches what you need to control, then open the linked guide for setup and management details.

Access pathUse it forIdentity or scopeWhere to manage
OrganizationIsolate members, warehouses, billing, and organization settings between teams or business units.OrganizationOrganizations
Console accessLet people sign in to the VeloDB Cloud console and manage organization resources.Organization member and organization roleMembers, Multi-Factor Authentication, and SAML Single Sign-On
Management API accessLet automation call VeloDB Cloud management endpoints.API key with an organization roleAPI Keys
Warehouse SQL accessLet people, applications, BI tools, and data pipelines connect to a warehouse and access SQL objects.Warehouse user and warehouse SQL roleWarehouse Users and Roles

How the access paths relate

Members manages console-level identities, the people you invite to your organization. A member's organization role (Organization Admin, Organization Billing, Warehouse Admin, Warehouse Viewer) controls what they can see and do in the console, not what SQL they can run. Premium organizations can use SAML Single Sign-On to authenticate members through a corporate identity provider.

Warehouse Users and Roles manages warehouse-level identities, the SQL accounts your data pipelines and BI dashboards use to run queries. These credentials appear in your connection string. The roles here are SQL roles scoped to the warehouse, which are separate from the organization roles assigned to Members.

Note:

  • Console accounts, Management API keys, and warehouse users are separate credentials. A person who needs both console access and SQL access must be an organization member and have a warehouse user.
  • An API key does not provide direct warehouse access.

Choose a guide