Skip to content

Concepts and vocabulary

Everything else in this documentation assumes these words. They are not interchangeable: a project is not a workspace, an identity is not a user, a library is not a Python dependency.

Term What it is
Tenant The widest boundary. Each tenant has its own authentication realm: its users, its groups, its identity providers. Two tenants share nothing. In the API the tenant is chosen by the X-Tenant header — never by a field in the request body.
Project The unit of work and the unit of governance: rights, quotas and costs are read and set per project. A job, a bucket, a graph, an experiment belong to a project.

If you only remember one sentence: the tenant isolates, the project governs.

Term What it is
Job A definition: a type (python, spark, lowcode, bash), a file to execute, an instance type, environment variables, an identity. A job does not run by itself.
Run One execution of a job. It carries a status, a duration, logs, events, metrics and produced files. The run is what you watch, not the job.
Workflow A graph of jobs: each step is a job, dependencies are edges. Schedulable with cron.
Identity The account a run executes as — a client of the tenant’s authentication realm, not a person. A job without an identity cannot be created (the API refuses). The scheduler resolves it at every run.
Instance type The resource template of a run (CPU, memory). It is the sizing unit presented to the customer and the basis of the per-run cost.
Infrastructure Where the run is placed. Mandatory when starting a run: without it, the API answers that at least one infrastructure is needed.
Term What it is
Library The way a file reaches the run’s container. You upload a file, the API returns a key, and the job references that key. The scheduler copies it into /workspace before start-up. This is how a job’s code arrives — not only its dependencies.
Project secret A confidential value (database password, API token) sealed in the database. It is delivered to the run by an init container, not through its environment. See secrets and libraries.
Bucket A file container on your object storage. That is where a job reads its inputs and writes its outputs.
Term What it is
Layer The refining stage, per your own convention (raw, cleaned, exposed). The first level of the catalog.
Database / table / field The next three levels. A table is backed by files in the bucket; fields carry types and descriptions.
Warehouse The engine that makes those tables queryable in SQL (Trino), on Apache Iceberg tables sitting on your S3.
Term What it is
Permission The elementary right, shaped <resource>/<action>: project/read, bucket/edit, run/create, catalog/read…
Role A named set of permissions: Tenant Administrator, Project Owner, Project Reader, Bucket Reader…
Assignment The link between a role, a holder (user, group or identity) and a resource. The assignment is what you revoke, not the role.
Application A non-human holder of rights: API token, agent token. It is what backs the MCP server.
Term What it is
Notification An event addressed to a person. Every write by an AI agent pushes one: that is what lights the « Agent » badge in the console.
Workspace A Jupyter or VS Code started on demand, in the execution namespace, under the same constraints as a job.

A feature disabled on your installation answers 501 feature_disabled, never 404. It is not a failure: it is a setting, and the response body names the feature. A 404 therefore always means “this resource does not exist”. See the REST API.