Help Center/ DataArts Lake Formation/ User Guide/ LakeFormation Data Permission Management/ Creating a LakeFormation Role and Granting Permissions
Updated on 2025-07-31 GMT+08:00

Creating a LakeFormation Role and Granting Permissions

If a role has some permissions on resources (such as databases), users or user groups with this role also have the corresponding resource operation permissions.

Constraints

If a service interconnected with a LakeFormation instance requires role authorization, the LakeFormation agency must contain the permissions of the role. For example, if the query permission of a role is required after LakeFormation is interconnected with an MRS cluster, select lakeformation:role:describe when creating a LakeFormation agency.

Creating a Role and Granting Permissions

  1. Log in to the LakeFormation console.
  2. Select the target LakeFormation instance from the drop-down list box on the left and choose Data Permissions > Roles.
  3. Click Create, set Role Name and Description, and click OK.
  4. Grant permissions to the created role. For details, see Configuring LakeFormation Metadata Permissions. Specifically:

    • Entity Type: Select Role.
    • Role: Select the role to be authorized.
    • Set other parameters as needed.