Admin Path
Learn to operate organizational sign-in, users and groups, and data-access policies, then distinguish Recents and version history from audit logs.
0/6 complete
About this Path
This Path walks a D.Hub portal administrator through the full operational cycle. It covers the permission model, external IdP registration, user and group operations, FGAC policy authoring and change operations, and the boundary between Recents, version records, and audit logs — six lessons, about 45 minutes total.
Each lesson is sized for 5–10 minutes. The sequence — permissions → users → policies → change history — mirrors the real agenda order during admin onboarding.
Terms to know before you start
- Identity provider (IdP): The system that manages organizational accounts and sign-in information, such as Keycloak, Okta, or Azure AD.
- OIDC: The standard connection D.Hub uses to exchange identity information with an identity provider.
- Single sign-on (SSO): Signing in with an organizational account instead of creating a separate D.Hub password.
- Automatic provisioning: Preparing a D.Hub account when an external identity-provider user first signs in.
- Fine-grained access control (FGAC): Policies that limit the columns and rows visible to selected users or groups after dataset access is granted.
Prerequisites
- A D.Hub portal account with Admin role
- An organizational identity provider that supports the standard connection used in Lesson 2
- The user manual's Permission model page nearby — this Path focuses on operational flow, leaving the manual for the feature reference role
If you've finished the Essentials Path, the Admin Path lands more smoothly because the five portal surfaces and collection-level work already feel familiar.
What you'll be able to do
- Explain how Reader / Writer / Owner roles start at the collection level, become the minimum inherited role on sub-assets, and allow higher resource-specific grants.
- Verify the deployment-level external IdP connection and register the SSO users who should access D.Hub.
- Share a collection with a local or registered IdP group to grant permissions to its members in bulk.
- Author and apply your first FGAC policy combining column masking and row filtering.
- Walk through the operational pattern of change impact verification → staged rollout for policy changes.
- Find recently modified assets, inspect version history where supported, and explain why neither surface is an audit or access log.
What comes after this Path
If you want more operational depth, two branches.
- Agent Builder Path — When you introduce AI automation, the permission and policy patterns you built here stack directly on top. Admins naturally sit at the safety gate of AI adoption.
- Review refunds with AI recommendations and human decisions — Walk the permission · policy · reviewer separation pattern of HITL agents through a real scenario.
Permission model at a glance (7 min), SSO and account provisioning in one page (8 min), and Column and row masking — from FGAC policy authoring to rollout feed into Lessons 1, 2, and 4. They stay around as cheat-sheets for specific situations, and you'll find yourself returning to them often even after finishing this Path.
Check off each lesson as you finish it — progress is recorded automatically.
Lessons
- 01Permission model at a glance — Role · Collection · FGACUnderstand D.Hub's three permission layers—roles, collection permission inheritance, and FGAC—and configure access from the collection downward.7 min
- 02Verify the external IdP connection and register SSO usersUnderstand the deployment-level OIDC connection, register external IdP users in D.Hub, and verify SSO login.8 min
- 03Register an IdP group and grant collection accessRegister and sync an external IdP group in D.Hub, then grant a collection role to its members.7 min
- 04Create your first dataset FGAC policySelect a user or group in a dataset's Data Access Policies tab and configure column masking and row filtering.9 min
- 05Change and recover an FGAC policy safelyRecord the current policy, validate a change with a test subject, and restore it manually if a problem occurs.8 min
- 06Review recently modified items and version historyFind modified assets in Recents and understand how version history differs from an audit log.7 min