Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Managed Service for Trino
  • Getting started
    • All guides
      • Access management
      • Getting access rules
      • Assigning rules for catalog objects
      • Assigning rules for schemas
      • Assigning rules for tables
      • Assigning rules for functions
      • Assigning rules for procedures
      • Assigning rules for queries
      • Assigning rules for system session properties
      • Assigning rules for catalog session properties
      • Deleting access rules
  • Terraform reference
  • Quotas and limits
  • Access management
  • Pricing policy
  • Yandex Monitoring metrics
  • Audit Trails events
  • Release notes

In this article:

  • What a rule is composed of
  • Types of rules
  • Actions with rules
  • Using names and IDs
  1. Step-by-step guides
  2. Object access rules
  3. Access management

Access management in Managed Service for Trino

Written by
Yandex Cloud
Updated at January 29, 2026
  • What a rule is composed of
  • Types of rules
  • Actions with rules
  • Using names and IDs

In Managed Service for Trino, you can flexibly control access to cluster objects for individual users or user groups. You can manage access by setting access rules.

What a rule is composed ofWhat a rule is composed of

Each access rule in Managed Service for Trino contains the following parameter types:

  • Subjects: Users or user groups the rule applies to.
  • Objects: Objects the rule applies to.
    You can specify objects using a combination of parameters, e.g., the object's name and catalog it resides in.
  • Privileges: Actions the users can perform with objects.
  • Additional parameters: Any other rule parameters, e.g., its description.

Types of rulesTypes of rules

User access to cluster objects is determined by a combination of these two rule types:

  • Top-level rules that manage access to all objects in the catalog.
  • Granular rules that manage access to individual schemas, tables, functions, procedures, queries, session’s system properties, or catalog’s session properties.

Actions with rulesActions with rules

In Managed Service for Trino, you can:

  • Get information about current access rules.
  • Set access rules for the following:
    • All objects in a catalog
    • Schemas
    • Tables
    • Custom functions and procedures
    • Queries
    • Session system properties
    • Catalog session properties
  • Delete all access rules for a cluster.

Using names and IDsUsing names and IDs

The following conventions apply to object names and IDs in the rules:

  • Names of schemas, functions, procedures, tables, session system properties, or catalog session properties are not validated. A rule with an error in its name will still be created; however, such a rule will not apply correctly.
  • Catalog names and IDs are validated. If catalog name or ID contains an error, the rule will not be created.
  • If you rename a catalog, its name will be automatically updated in all the rules that contain it.
  • If you delete a catalog, its name and ID will be automatically deleted from all the rules that contain them. If you delete the only catalog specified in the rule, the rule itself will be automatically deleted.

Was the article helpful?

Previous
Viewing cluster logs
Next
Getting access rules
© 2026 Direct Cursus Technology L.L.C.