Sundial
Workspace administration

User groups and warehouse access

User groups organize workspace members and control which warehouse data they can query. A group can use the workspace account for a connector, use a scoped warehouse account limited to selected databases and schemas, or have its access to that connector revoked.

Admins only

Only workspace admins can create user groups, change group membership, or update warehouse access.

Progressive rollout

Group-based warehouse access is rolling out progressively. If the warehouse account step or Group Access is not available in your workspace, contact your Sundial representative.

Find and manage user groups

  1. Open the user menu and select Personal Settings.
  2. Open Members.
  3. Use the group tabs to review membership, or select + User group to create a group.

Open a group's menu to rename the group, edit its members, delete a non-default group, or update its warehouse access.

Each workspace has a default group that includes everyone. You cannot delete the default group or remove members from it.

Create a user group

  1. Select + User group, enter a group name, and continue.
  2. Add the people who should belong to the group. Workspace admins are included in every group by default.
  3. Select Create.
  4. When the Warehouse accounts step is available, choose how the group should connect to each supported warehouse connector.

You can choose one access option per connector:

  • Workspace account: Use the connector's shared workspace connection. The group can query all databases and schemas available to that connection.
  • Scoped connection: Use a separate warehouse account as the group's warehouse identity and limit it to selected databases and schemas.
  • Revoke access: Remove the group's access to that connector.

Update warehouse access

To change access from the Members page, open the group's menu and select Update access.

You can also open Context Engine → Connectors → Group Access to review scoped warehouse accounts and update the groups that use them.

Group warehouse accounts are supported for Snowflake and BigQuery connectors. dbt and Astro connectors cannot host group accounts.

On this page