Identity and access
ComponentsKeycloak · LDAP or Active Directory · OPA or Ranger · Kerberos
Your directory remains the source of accounts and groups. Keycloak federates identity (OIDC, SSO); data rights are expressed per group and applied by the engine: row filters and column masks, for a dashboard, a notebook, a model or an agent. OPA or Apache Ranger decide, whichever you already have.







