Cloud credential governance
Control source-system identities, prefixes, rotation, and revocation.
Control source-system identities, prefixes, rotation, and revocation.
Cloud connections extend the Unitlab trust boundary into another system. Scope the identity to the minimum bucket or prefix, monitor its ownership, and define how Unitlab behavior changes when access is removed.
For enterprise use, the connection should be treated as infrastructure, not as a convenient personal login:
Create a dedicated read-only or least-privilege identity for Unitlab.
Restrict it to the required bucket/container and prefix.
Avoid root or account-wide credentials.
Test with a small non-sensitive prefix.
Confirm that files, metadata, nested paths, and synchronization behave as expected.
Record the source system and connection owner.
Separate permission to manage cloud connections from permission to annotate data.
Workspace administrators can create, update, delete, test, and browse cloud connections from Workspace Settings. Connection administration requires cloud-storage permission and should remain separate from ordinary data browsing or annotation.
Use a dedicated organization-owned cloud identity.
Grant the minimum read or write actions and exact storage scope required.
Store secrets or role configuration in approved systems and rotate on schedule.
Test enumeration and import against the intended prefix only.
Before revocation, understand whether already-registered data, source references, and releases remain usable.
Do not publish provider account IDs, secret names, bucket paths, signed URLs, or regulated filenames in public documentation.
Continue with Unitlab: Unitlab’s data annotation platform · Unitlab’s data curation platform