Skip to content
PlainID
← Back to all integrations
Google BigQuery logo

Google BigQuery

Discover data access and manage fine-grained filtering and masking in BigQuery.

About PlainID + Google BigQuery

In order to ensure secure data access and collaboration, effective data access control is essential for managing both analytical and operational data. Identity has become a top priority in today's security landscape, and data access control must be designed to be identity-aware, dynamic, and capable of offering fine-grained controls. However, controlling access to data can be a significant challenge for many organizations, as traditional methods such as relying on built-in capabilities of data repositories or application filtering mechanisms are increasingly inadequate given evolving data access control requirements.

To address this challenge, the PlainID Google BigQuery Authorizer provides a solution by offering fine-grained controls over data selection access through the

Google BigQuery data management platform.

Technical Information

The PlainID Authorizer for Google BigQuery is Query Modifier that modifies the original query before it is sent to Google BiqQuery. The original query is modified based on the response it receives from the PlainID Policy Decision Point (PDP). This can be done by direct integration with the Authorizer or through an API gateway. The modified query is then sent to Google BigQuery and ensures that the user can only access data they are authorized to access

Architectures

  1. The end user accesses the app.
  2. The user is redirected to complete the authentication process on the Identity Provider (IdP).
  3. The application sends the SQL request to the PlainID Google BigQuery Authorizer. The Authorizer is a Query Modifier - a PDP component designated for Google BigQuery that modifies queries based on the dynamically calculated access decision. The modified query is sent back to the application.
  4. The modified request is sent to Google BigQuery by the application (specific path based on each application's unique architecture).

Technology

  • Data platforms

Capabilities

  • Discover
  • Manage
  • Enforce

Auth Patterns

  • Data Authorization - Filtering
  • Data Authorization - Masking
  • Policy Orchestration
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.