Organization-level account on data platform
Systems and methods for an organization-level account for an organization on a data platform, users of which can possess administrative or management privileges with respect to the organization and across one or more others accounts of the organization.
1. A system comprising:
a set of hardware processors; and
memory storing instructions that cause the set of hardware processors to perform operations comprising:
receiving, from a user of an organization-level account for a specified organization, a request to perform an administrative-level operation with respect to the specified organization; and
in response to the request:
determining a set of roles assigned to the user within the organization-level account;
determining whether at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization; and
in response to determining that at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization, performing the administrative-level operation with respect to the specified organization.
2. The system of claim 1 , wherein the administrative-level operation comprises merging the specified organization into a target organization.
3. The system of claim 2 , wherein a merged organization is generated by the merging of the specified organization into the target organization, and wherein the administrative-level operation causes the organization-level account of the specified organization to be retained for the merged organization.
4. The system of claim 2 , wherein the organization-level account is a first organization-level account of the specified organization, wherein a merged organization is generated by the merging of the specified organization into the target organization, and wherein the administrative-level operation causes a second organization-level account of the target organization to be retained for the merged organization.
5. The system of claim 2 , wherein the organization-level account is a first organization-level account of the specified organization, wherein a merged organization is generated by the merging of the specified organization into the target organization, and wherein the administrative-level operation causes a second organization-level account to be generated for the merged organization.
6. The system of claim 1 , wherein the specified organization resides on a specified deployment of a data platform, and wherein the administrative-level operation comprises moving the organization-level account from the specified deployment to a target deployment of the data platform.
7. The system of claim 1 , wherein the organization-level account is a primary organization-level account of the specified organization, and wherein the administrative-level operation comprises enabling failover for the primary organization-level account using one or more secondary organization-level accounts.
8. The system of claim 7 , wherein the administrative-level operation causes each of the one or more secondary organization-level accounts to be generated on a different deployment on a data platform, wherein the specified organization resides on a specified deployment of the data platform, and wherein each different deployment is different from the specified deployment.
9. The system of claim 7 , wherein the administrative-level operation causes data replication from the primary organization-level account to at least one of the one or more secondary organization-level accounts to be established.
10. The system of claim 7 , wherein the user is a first user of the primary organization-level account, and wherein any user of a secondary organization-level account is limited to requesting a set of read-only administrative-level operations.
11. The system of claim 7 , wherein the primary organization-level account is an existing primary organization-level account of the specified organization, wherein the specified organization resides on a specified deployment of a data platform, and wherein the operations comprise:
detecting failure of the specified deployment; and
in response to detecting the failure, causing a secondary organization-level account of the one or more secondary organization-level accounts to be set as a new primary organization-level account of the specified organization.
12. The system of claim 1 , wherein the administrative-level operation comprises management of an organization-level data object of the specified organization.
13. A method comprising:
receiving, at a specified deployment of a data platform, from a user of an organization-level account for a specified organization, a request to perform an administrative-level operation with respect to the specified organization, the specified organization residing on the specified deployment; and
in response to the request:
determining, by the specified deployment, a set of roles assigned to the user within the organization-level account;
determining, by the specified deployment, whether at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization; and
in response to determining that at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization, performing, by the specified deployment, the administrative-level operation with respect to the specified organization.
14. The method of claim 13 , wherein the administrative-level operation comprises merging the specified organization into a target organization.
15. The method of claim 13 , wherein the administrative-level operation comprises moving the organization-level account from the specified deployment to a target deployment of the data platform.
16. The method of claim 13 , wherein the organization-level account is a primary organization-level account of the specified organization, and wherein the administrative-level operation comprises enabling failover for the primary organization-level account using one or more secondary organization-level accounts.
17. The method of claim 13 , wherein the administrative-level operation comprises management of an organization-level data object of the specified organization.
18. A machine-storage medium comprising instructions that, when executed by one or more hardware processors of a machine, configure the machine to perform operations comprising:
receiving, from a user of an organization-level account for a specified organization, a request to perform an administrative-level operation with respect to the specified organization; and
in response to the request:
determining a set of roles assigned to the user within the organization-level account;
determining whether at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization; and
in response to determining that at least one role in the set of roles permits the user to perform the administrative-level operation with respect to the specified organization, performing the administrative-level operation with respect to the specified organization.
19. The machine-storage medium of claim 18 , wherein the administrative-level operation comprises merging the specified organization into a target organization.
20. The machine-storage medium of claim 18 , wherein the specified organization resides on a specified deployment of a data platform, and wherein the administrative-level operation comprises moving the organization-level account from the specified deployment to a target deployment of the data platform.