graph-lakehouse
Monitor Access Control Activity
All Graph Lakehouse data access and access control modifications are logged in a system table named sth_acl. System administrators can monitor the sth_acl system table for various types of access control entries and activities. Those events include:
- "Init file execution"
- "Authorization Success"
- "Authorization Failure"
- "Create Role"
- "Drop Role"
- "Alter Role"
- "Alter Graph" (changes of ownership)
- "Alter Owned By"
- "Grant Membership"
- "Grant Privilege"
- "Revoke Membership"
- "Revoke Privilege"
In addition to monitoring access, an administrator can diagnose failures by examining the entries in the "sth_acl" table. You can query the Graph Lakehouse system table using regular SPARQL queries just like that of any other database source. For example:
azgi -c "select * where {table 'sth_acl'}"
The following provides a sample query of sth_acl table entries following execution of a GRANT statement:
xrowid | query | time | user | action_type | detail
---------+-------+---------------+------+-----------------------+------------------------------------------------
1219813 | 12453 | 2020-11-20... | test | Grant Privilege | Granted privileges 1 on
Access Control System Graphs
All Graph Lakehouse role and object attributes and privileges are stored in one of two system graphs,
Regardless of whether users are authenticated locally or by a remote directory service, the privileges granted to specific groups or roles is stored locally within the system graph named
A second system graph named
The
The System Graph
The Graph Lakehouse**
INSERT DATA {
GRAPH
The System Graph
A second system graph, named
INSERT DATA {
GRAPH
for subject - name of the graph
for predicate - name of the graph
for triple - name of the graph
. } }
Again, only an Graph Lakehouse system administrator, assigned the superuser role or belonging to a group with administration privileges, has the ability to directly modify the
Source: https://docs.sw.siemens.com/documentation/external/PL20260518131381558/en-US/html/acl-monitor.htm · retrieved 2026-08-23