Skip to main content
Perimeters are boundaries within your platform that isolate and group the work of a team or project. Each perimeter carries its own governance policy, which defines the resources and access available to the team or project. Administrators can create as many perimeters as needed.

Why perimeters matter

Access to resources is inherited from access to a perimeter. A user who can access a perimeter can use the compute, packages, and models registered to it, while a user without access cannot. This keeps one team’s resources and workloads separate from another’s within the same platform.

Perimeters and the data plane

The data plane is the part of the platform that runs in your cloud: the cluster where tasks execute and the storage where your data is kept. Creating a perimeter provisions a dedicated slice of the data plane for a team or project. Each perimeter has:
  • Its own namespace, where all of the perimeter’s tasks run
  • Its own cloud identity (an IAM role or service account) that the perimeter’s tasks assume
  • Its own database schema and artifact storage, holding the perimeter’s run metadata and results
  • Its own set of secure package channels and policies, governing which packages are available to the perimeter’s workloads
Cloud permissions attach to the perimeter’s identity, so a task in one perimeter cannot authenticate as another perimeter’s identity, and cannot reach that perimeter’s storage or data sources. Compute pools are the exception to this per-perimeter provisioning. Pools are shared data plane infrastructure, and a perimeter’s policy grants its workloads access to specific pools, so teams share the underlying hardware while their workloads stay isolated.

What a perimeter governs

Each perimeter carries its own configuration and policy, including: Because most governance features attach to a perimeter, configuring package channels, model access policies, or compute limits is almost always done for a specific perimeter rather than for the platform as a whole.

Working with perimeters

For details on the policies a perimeter can carry, see Channel governance and Model governance.