BigID
Bring BigID data classification and sensitivity context into access decisions.
About PlainID + BigID
Customers use BigID to reduce their data risk, automate security and privacy controls, achieve compliance, and understand their data across their entire data landscape: including multi-cloud, hybrid cloud, IaaS, PaaS, SaaS, and on-prem data sources. BigID enables organizations to discover, manage, protect, and get more value from highly regulated, sensitive, and personal data.
PlainID provides a platform that centralizes the management and control of authorization policies across the enterprise technology stack.
The integration of PlainID's Authorization Platform with BigID creates a powerful combination that allows companies to ensure their sensitive and personal data will be protected. This approach enables organizations to maintain consistent policy-based access control across the entire technology stack for resilient data protection globally.
Technical Information
PlainID can integrate with BigID using The Authorization Platforms' PIP service. PlainID’s Policy Information Point (PIP) can fetch data from any API or Data service. In the case of the integration with BigID, the data's meta-data can be pulled from BigID through their REST interface or through BigID’s database itself
Architectures
ACME Corp is a US-based financial institution with global operations. One of the measures ACME Corp is taking to meet GDPR regulatory requirements is to apply access controls on the data exposed to Marketing Analysts. ACME Corp has achieved it using BigID, The PlainID Authorization Platform, and their integration:
- BigID discovers and classifies data across different databases.
- BigID's data classification is integrated into PlainID's Policy Information Point (PIP) as a source of attributes for data-type assets, enabling their utilization in the configuration of access policies and access decision calculation.
- A policy is configured within PlainID's Authorization Platform to restrict Marketing Analysts' access to PII. In this policy, the information about a user indicating they are a Marketing Analyst can be retrieved from the IdP, LDAP, HR system, or an identity SOR such as IGA. Customer Records are the data asset configured within the PlainID's PAP. BigID provides information about which columns are Labeled as PII.
- A Marketing Analyst is attempting to log into an application to review sales and marketing reports and is being redirected to complete the authentication process through the IdP.
- Utilizing one of PlainID's authorizers, the data access request is evaluated and an access decision is dynamically calculated. Using the PlainID PIP service, the information about which columns are Labeled as PII is pulled in real-time from BigID to modify the original query. In this example, the SELECT clause will be modified to exclude/mask the columns containing PII. The technical mechanism of modifying the query is contingent on the architecture access pattern.
- The Marketing Analysts access the sales and marketing reports excluding PII or with masked PII columns.
Technology
- Data platforms
Capabilities
- Enforce
Auth Patterns
- Policy information point (PIP)
Need help integrating?
Our experts can help you architect the perfect authorization strategy for your stack.
Better Together
Connect Context. Centralize Policy. Enforce Everywhere.


