Granting Ascend Access to Your Applied Epic Data Lake (Google BigQuery)
Last updated: June 30, 2026
This is a guide that will teach you:
The access required for Ascend to connect to your Applied Epic Data Lake.
How to grant the appropriate permissions in Google Cloud.
What information to provide to Ascend after access has been granted.
How to ensure the required datasets and tables are available for the integration.
What to expect regarding security, data access, and BigQuery billing.
To enable Ascend to access your Applied Epic Data Lake, please grant our service account read-only access to your Google Cloud BigQuery environment.
Service Account
Please grant access to the following service account:
Required Permissions
Our service account requires the following permissions:
1. Browser (Project Level)
Grant the Browser role (roles/browser) at the project level.
This permission allows Ascend to:
View the project name and structure
Identify available resources
This role does not allow Ascend to view or query your data.
2. BigQuery Data Viewer
Grant the BigQuery Data Viewer role (roles/bigquery.dataViewer).
You can assign this role in one of two ways:
Project Level (recommended for simplicity)
Dataset Level (recommended if you would like to limit access to specific datasets)
This permission allows Ascend to:
Read data from authorized tables
View table and dataset metadata
List available tables within the shared dataset
Note: Please ensure that the service account has access to all tables identified in the data mapping document provided by your designated Ascend Solutions Consultant. These tables are required for the integration to function correctly.
Information to Share with Ascend
Once permissions have been granted, please provide:
Google Cloud Project ID
BigQuery Dataset Name
If you are unsure of these values, you can simply send us a sample BigQuery query that references the dataset, and we can identify the required information.
How to Grant Access
Step 1: Grant the Browser Role
In the Google Cloud Console, navigate to IAM & Admin → IAM.
Select Grant Access.
Enter [email protected] in the New principals field.
Assign the Browser role.
Save your changes.
Step 2: Grant BigQuery Data Viewer
Choose one of the following options.
Option A: Grant Access at the Project Level
Assign the BigQuery Data Viewer role to [email protected].
This option provides read-only access to all datasets within the project.
Option B: Grant Access to a Specific Dataset
If you prefer to limit access to a single dataset:
Open the BigQuery Console.
Select the dataset you would like to share.
Choose Share → Manage Permissions.
Select Add Principal.
Enter [email protected].
Assign the BigQuery Data Viewer role.
Save your changes.
Security and Billing
Ascend's access is read-only. We cannot modify, create, or delete any of your data.
All queries are executed from Ascend's Google Cloud project, which means:
Your data remains in your BigQuery environment.
Ascend pays for all BigQuery query costs associated with accessing your data.
Your organization is not billed for Ascend's queries.
If you have any questions during setup, please reach out to your designated Ascend Solutions Consultant. We are happy to assist throughout the configuration process.
Contact Us
Need more help? Contact us at [email protected] for more help.