Everything else in this documentation assumes these words. They are not interchangeable: a project
is not a workspace, an identity is not a user, a library is not a Python dependency.
| Term |
What it is |
| Tenant |
The widest boundary. Each tenant has its own authentication realm: its users, its groups, its identity providers. Two tenants share nothing. In the API the tenant is chosen by the X-Tenant header — never by a field in the request body. |
| Project |
The unit of work and the unit of governance: rights, quotas and costs are read and set per project. A job, a bucket, a graph, an experiment belong to a project. |
If you only remember one sentence: the tenant isolates, the project governs.
| Term |
What it is |
| Job |
A definition: a type (python, spark, lowcode, bash), a file to execute, an instance type, environment variables, an identity. A job does not run by itself. |
| Run |
One execution of a job. It carries a status, a duration, logs, events, metrics and produced files. The run is what you watch, not the job. |
| Workflow |
A graph of jobs: each step is a job, dependencies are edges. Schedulable with cron. |
| Identity |
The account a run executes as — a client of the tenant’s authentication realm, not a person. A job without an identity cannot be created (the API refuses). The scheduler resolves it at every run. |
| Instance type |
The resource template of a run (CPU, memory). It is the sizing unit presented to the customer and the basis of the per-run cost. |
| Infrastructure |
Where the run is placed. Mandatory when starting a run: without it, the API answers that at least one infrastructure is needed. |
| Term |
What it is |
| Library |
The way a file reaches the run’s container. You upload a file, the API returns a key, and the job references that key. The scheduler copies it into /workspace before start-up. This is how a job’s code arrives — not only its dependencies. |
| Project secret |
A confidential value (database password, API token) sealed in the database. It is delivered to the run by an init container, not through its environment. See secrets and libraries. |
| Bucket |
A file container on your object storage. That is where a job reads its inputs and writes its outputs. |
| Term |
What it is |
| Layer |
The refining stage, per your own convention (raw, cleaned, exposed). The first level of the catalog. |
| Database / table / field |
The next three levels. A table is backed by files in the bucket; fields carry types and descriptions. |
| Warehouse |
The engine that makes those tables queryable in SQL (Trino), on Apache Iceberg tables sitting on your S3. |
| Term |
What it is |
| Permission |
The elementary right, shaped <resource>/<action>: project/read, bucket/edit, run/create, catalog/read… |
| Role |
A named set of permissions: Tenant Administrator, Project Owner, Project Reader, Bucket Reader… |
| Assignment |
The link between a role, a holder (user, group or identity) and a resource. The assignment is what you revoke, not the role. |
| Application |
A non-human holder of rights: API token, agent token. It is what backs the MCP server. |
| Term |
What it is |
| Notification |
An event addressed to a person. Every write by an AI agent pushes one: that is what lights the « Agent » badge in the console. |
| Workspace |
A Jupyter or VS Code started on demand, in the execution namespace, under the same constraints as a job. |
A feature disabled on your installation answers 501 feature_disabled, never 404. It is
not a failure: it is a setting, and the response body names the feature. A 404 therefore always
means “this resource does not exist”. See the REST API.