Setting up the IBM watsonx.data intelligence service

The watsonx.data intelligence service is provisioned automatically with a Trial plan when you sign up. To set up IBM watsonx.data intelligence for an organization, you start with upgrading the service and assigning IBM watsonx.data intelligence roles to users in your IBM Cloud account. Within IBM watsonx, an administrative user must create catalogs and the top-level categories for governance artifacts, and then add collaborators with the appropriate roles to each.

  1. Upgrade the service.
  2. Assign IBM watsonx.data intelligence roles.
  3. Develop a plan for implementing data governance.
  4. Delegate a user to manage Data Product Hub.

If you have a watsonx.data intelligence Trial plan, your capabilities are limited and some of these tasks are not applicable.

Upgrade the service to the appropriate plan

Required permissions
You must be the IBM Cloud account owner or administrator.

To upgrade IBM watsonx.data intelligence:

  1. Determine the IBM watsonx.data intelligence service plan that you need. The features and functionality of IBM watsonx.data intelligence vary considerably across the service plans. See Watsonx.data intelligence service plans.
  2. While logged in to IBM watsonx, from the main menu, click Services > Service instances.
  3. Click the menu next to the IBM watsonx.data intelligence service and choose Upgrade service.
  4. Choose the plan you want and click Upgrade.

Assign IBM watsonx.data intelligence roles to users or access groups

Required permissions
You must be the IBM Cloud account owner or administrator. Make sure that object storage is configured to allow users to create catalogs and projects. See Setting up IBM Cloud Object Storage for use with IBM watsonx.

After you add users to your IBM Cloud account, you must assign the appropriate IAM service and platform level roles to provide permissions for IBM watsonx.data intelligence. You have two choices for assigning roles:

Assigning access with access groups

For each access group, create an access policy by assigning service access and platform access roles.

  1. From the Access tab for the group, click Assign access+.
  2. For Service, choose IBM Cloud Pak for Data. The Service roles for IBM Cloud Pak for Data apply to IBM watsonx.data intelligence.
  3. Next, assign a Service access role for the group. You can create a separate group for each role, for example:
    • Assign the Manager role to an access group called Manager for users who are responsible for creating top-level categories and creating catalogs.
    • Assign the Data Steward or Data Engineer role to access groups for users who are responsible for creating governance artifacts and curating data into catalogs.
    • Assign the Data Scientist role to access groups for users who need to use catalog assets in projects.
  4. Assign the Editor role for Platform access role to each group. The Editor role can perform all platform actions except for managing the account and assigning access policies.
  5. Add and Assign the policy for the access group.
  6. Add users to the group who require the access dictated by the group policy.

To add users to an access group, you choose a group in the IBM Cloud account and then add users. Follow these steps:

  1. From IBM watsonx, choose Administration > Access (IAM) to open the Manage access and users page in your IBM Cloud account.
  2. Select Access groups to see a list of available groups.
  3. Select the access group that you want to populate with users and click Add users+ to show the list of users.
  4. Checkmark the members for the access group and click Add to group.

If you do not have access groups yet, you can create them:

  1. From IBM watsonx, choose Administration > Access (IAM) to open the Manage access and users page in your IBM Cloud account.
  2. On the Access groups page, click Create+.
  3. Provide a unique name of the group and optionally a description that describes the group's role.
  4. Click Create and then add users to the group.

Assigning access to individual users

To assign IBM watsonx.data intelligence and Cloud Pak for Data roles to users who are already in your IBM Cloud account:

  1. From IBM watsonx, choose Administration > Access (IAM) to open the Manage access and users page in your IBM Cloud account.
  2. Select the user on the Users page.
  3. Click the Access tab and then choose either Assign group+ or Assign access+.
  4. For Assign group+, select one or more Access groups for the user, then Add and Assign them to the group.
  5. To Assign access to an individual user, create an Access policy.
  6. For Service, choose IBM Cloud Pak for Data. The Service roles for IBM Cloud Pak for Data apply to IBM watsonx.data intelligence.
  7. Next, select one of the Service access roles:
    • Assign the Manager role to users who are responsible for creating top-level categories, creating catalogs, and generating reports about IBM watsonx.data intelligence data.
    • Assign the Data Steward or Data Engineer role to users who are responsible for creating governance artifacts and curating data into catalogs.
    • Assign the Data Scientist role to users who need to use catalog assets in projects.
  8. For Platform access:
    • Assign the Editor role to each user with the other service access roles. The Editor role can perform all platform actions except for managing the account and assigning access policies.
  9. Add and Assign the policy for the user.
  10. To assign Data Product roles or Catalog roles, select the following IAM services, and roles based on their level in these tables:
Table 1. Data product roles
Data product roles IAM Service Role level Role
Data Product Administrator
Data Product Provider
Data Product Consumer
watsonx.data intelligence Platform Viewer
Data Product Administrator Cloud Pak for Data Service Data Product Administrator
Data Product Administrator All IAM Account Management services Platform Viewer
Data Product Provider Cloud Pak for Data Service Data Product Provider
Data Product Consumer Cloud Pak for Data Service Data Product Consumer

Table 2. Catalog roles
Catalog roles IAM Service Role level Role
Data Steward
Data Engineer
Data Scientist
watsonx.data intelligence Platform Editor
Data Steward Cloud Pak for Data Service Cloud Pak Data Steward
Data Engineer Cloud Pak for Data Service Cloud Pak Data Engineer
Data Scientist Cloud Pak for Data Service Cloud Pak Data Scientist
  1. Add to review each role in the Access summary.
  2. After you have added each role for the user, select Assign in the Access summary.

For more information about the roles, see User roles and permissions for watsonx.data intelligence.

Develop a plan for implementing data governance

As a IBM watsonx.data intelligence administrator, you must perform other set up tasks for IBM watsonx.data intelligence, such as creating catalogs. You must understand the choices that you have and the implications of those choices before you start.

See Planning to implement data governance and Planning to set up IBM watsonx.data intelligence.

Delegate a user to manage Data Product Hub

Either the IBM Cloud account administrator or their delegate must initialize Data Product Hub.

The account administrator assigns the Manager role and other roles to delegate a user who can initialize Data Product Hub. The required roles are described in the following table:

IAM roles to delegate a user to manage Data Product Hub
Service Role level Role Action
watsonx.data intelligence Platform Viewer View watsonx.data intelligence service instance
Cloud Pak for Data Service Manager Initialize Data Product Hub upon initial log in
All Account Management services Platform Administrator To create a service ID and assign policies
Cloud Object Storage Service Manager Configure a bucket for storing data contracts
Cloud Object Storage Platform Administrator Configure a bucket for storing data contracts

After initializing Data Product Hub, the Manager performs the following next steps:

Next steps

Finish the remaining steps for setting up the platform.