| AI / Agent | AI Application, Agent Execution, Agent Strategy, AI Governance Policy, AI Persona, Dynamic Agent | Who can build, run, and govern AI workflows and personas. Over-permissioning here can cause automated processes to run without oversight. | High |
| APIs and apps | API Collection, API Endpoint, API Service, App, App Marketplace Definition, Bot | Who can register and call external APIs and install marketplace apps or bots. Controls your third-party integration surface. | Medium |
| Analytics and dashboards | Chart, Dashboard, Dashboard Data Model, Dashboard Service, Data Insight Chart | Who can view or modify BI visualizations. Dashboard Services (Tableau, Power BI) govern the source connection itself. | Medium |
| Data assets | Database, Database Schema, Table, Stored Procedure, Query, Saved Query, Query Cost Record | The broadest data access category. Controlling Table access effectively gates most downstream use – queries, dashboards, and pipelines all depend on it. | High |
| Data platform services | Database Service, Pipeline Service, Messaging Service, Search Service, Storage Service, Drive Service, Metadata Service, Security Service | Controls connection credentials and pipeline execution authority. Over-permissioning here can affect your entire data infrastructure. | Critical |
| Data governance | Glossary, Glossary Term, Tag / Classification, Domain, Data Product, Data Contract, KPI / Metric | Who can define business vocabulary, apply sensitive labels like PII or Confidential, and manage data products and contracts. | Medium–High |
| Files and documents | File, Directory, Container, Page, Learning Resource | Access to file-level metadata and documentation. Lower risk unless the files themselves contain sensitive data. | Low–Medium |
| Ingestion and pipelines | Ingestion Pipeline, Ingestion Runner | Who can create or trigger metadata ingestion jobs. Controls what metadata flows into OpenMetadata. | High |
| ML and LLM | ML Model, ML Model Service, LLM Model, LLM Service | Governs AI and ML model usage and the platforms hosting them. Controls your AI inference surface. | High |
| Workflow and automation | Workflow, Workflow Definition, Workflow Instance, Event Subscription | Who can design, deploy, and trigger automation flows and event-driven processes. | High |
| Data quality and testing | Test Case, Test Definition, Test Suite, Test Case Result, Test Connection Definition | Who can create, edit, or view test results – including failed row samples, which may contain production data. | Medium–High |
| Collaboration | Feed, Notification Template, Web Analytic Event | Activity feeds and user interaction tracking. | Low |
| User and access control | User, Team, Role, Policy, SCIM | The most sensitive category – controls who exists in the system and what they’re allowed to do. | Critical |
| Reporting and monitoring | Report, Entity Profile, Entity Report Data, Audit Log | Access to usage reports and audit history. Audit Logs are particularly sensitive – they reveal all system activity. | Medium–High |
| Misc | Topic (Kafka), Worksheet, Context Memory, Prompt Template, MCP Execution, MCP Server, MCP Service | Messaging topics, AI prompt templates, and the MCP orchestration layer. Prompt Templates and MCP Services carry elevated AI risk. | Medium–High |