> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cedarai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Access and permissions

> Sign in to Data Depot, get the right role for your carrier, and understand what each permission allows.

Data Depot uses your Cedar login and the roles assigned to you in the Admin Portal. Access is always per carrier: you
can have full access for one carrier and none for another.

## Sign in

Go to [ddepot.cedarai.com](https://ddepot.cedarai.com), or open Data Depot from Cedar Accounts.⁠‌​‌‌‌‌​​‌‌‌​‌​‌​‌​​‌‌​‌‌⁠ If you aren't signed in,
Data Depot sends you to the Cedar sign-in page and brings you back afterwards. Your name and email appear in the top
right, next to **Sign out**.

## Roles

Most people need a single role, **Data Depot Admin**, granted on each carrier they work with.

| Role | Grants |
| - | - |
| **Data Depot Admin** (`dataDepot.admin`) | Everything in Data Depot for the carrier: Postgres views and logins, API clients, CDC delivery, and data warehouse configuration |
| `dataDepot.apiClientManager` | API clients only: create, edit, rotate, and delete them |
| `arms.dataWarehouseAdmin` | Postgres views and logins and data warehouse configuration. Does not include API clients |

<Tip>
  When you assign a role in the Admin Portal, search for `dataDepot` or `depot`. Searching for "Data Depot" with a space
  doesn't find the role, because the search matches the role name, which has no space.
</Tip>

After a role is granted, **sign out of Data Depot and sign in again** so your new access is picked up.

Your organization's Admin Portal administrator can grant these roles. If no one in your organization can, contact your
Cedar account team. See [Roles](/user-docs/admin/roles) for how roles and bindings work in the Admin Portal.

## What each action needs

If you build custom roles in the Admin Portal, use this table to choose permissions.⁠‌​‌‌‌‌​​‌‌‌​‌​‌​‌​​‌‌​‌‌⁠ Data Depot Admin includes all of
them.

| Action | Permission |
| - | - |
| Browse Postgres sources and columns, see existing views | `dataDepot.provision.read` or `dataDepot.provision.create` |
| Provision or update a view, create its database login | `dataDepot.provision.create` |
| Revoke a view, reset its database password | `dataDepot.provision.delete` |
| See CDC deliveries | `dataDepot.provision.read` or `dataDepot.provision.create` |
| Subscribe to CDC, change the interval, rotate the destination credential, delete a subscription | `dataDepot.provision.create` |
| See API clients | `dataDepot.apiClient.list` |
| Create an API client | `dataDepot.apiClient.create` |
| Edit an API client's access or assumed users | `dataDepot.apiClient.update` |
| Rotate an API client's credential | `dataDepot.apiClient.create` and `dataDepot.apiClient.update` |
| Revoke a credential, delete an API client, retry cleanup | `dataDepot.apiClient.delete` |
| View as a user group | `iam.userGroupPolicy.viewAs` |

The **MCP** pages don't need a Data Depot permission. What your AI assistant can read through MCP comes from your
existing ARMS permissions for each carrier. See [MCP](/user-docs/data-depot/mcp).

## If you don't have access

When something is missing, Data Depot tells you instead of showing an empty page.

| Message | What it means | What to do |
| - | - | - |
| **This account is not authorized for Data Depot** | Your Cedar login was accepted, but it has no Data Depot access at all | Ask for the Data Depot Admin role on your carrier |
| **No Data Depot access** | You have no Data Depot permission on any carrier you can see | Ask for the Data Depot Admin role, then sign out and sign in again |
| **No access for this carrier** | You have access to other carriers, but not the selected one | Pick another carrier, or ask for access to this one |
| **Postgres unavailable for this carrier** | You can use API clients or MCP for this carrier, but not Postgres | Ask for a role that includes Postgres views if you need them |
| **Could not load your Data Depot session** | Data Depot couldn't check your access, often because a Cedar service is briefly unavailable | Wait a moment and reload the page |

If you can't open Postgres for the selected carrier, Data Depot takes you to **API** or **MCP** instead, whichever you
can use.

## View as a user group

**View as user group** lets an admin check what Data Depot looks like for members of one of the carrier's user groups,
for example before granting a group access.⁠‌​‌‌‌‌​​‌‌‌​‌​‌​‌​​‌‌​‌‌⁠ It appears in the header when you have the
`iam.userGroupPolicy.viewAs` permission and the carrier has at least one user group. Carrier admin and operator roles
include this permission.

<Frame caption="Viewing Data Depot as the Data team user group">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/view-as.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=46e04f54a1a017f93df62574e7d00725" alt="Data Depot with the View as banner and a user group selected" width="1440" height="900" data-path="images/data-depot/view-as.png" />
</Frame>

<Steps>
  <Step title="Start View as">
    Select **View as user group** in the header. A banner appears with the text **Viewing Data Depot as user group**.
  </Step>

  <Step title="Pick the group">
    Choose the group from the list in the banner. You can pick any user group on the carrier, not just groups you belong
    to. Every page now uses that group's permissions.
  </Step>

  <Step title="Exit">
    Select **Exit view as** to return to your own permissions.
  </Step>
</Steps>

<Warning>
  View as is not a sandbox. Anything you change while viewing as a group, such as provisioning a view or creating an API
  client, really happens. The change is recorded under your own name, not the group's.
</Warning>

## Related pages

* [Cedar Data Depot overview](/user-docs/data-depot/overview)
* [Roles](/user-docs/admin/roles)
* [User groups](/user-docs/admin/user-groups)


## Related topics

- [Postgres views](/user-docs/data-depot/postgres.md)
- [Choosing the right option](/user-docs/data-depot/choosing.md)
- [MCP for AI assistants](/user-docs/data-depot/mcp.md)
- [MCP privacy addendum](/user-docs/api-reference/mcp-privacy.md)
- [API clients](/user-docs/data-depot/api-clients.md)
