Skip to content
PlainID
← Back to all integrations
PostgreSQL logo

PostgreSQL

Apply fine-grained data filtering and masking for application access to PostgreSQL.

About PlainID + PostgreSQL

PostgreSQL is a popular open-source relational database management system that prioritizes extensibility and SQL compliance.

PlainID provides a platform that serves as a centralized tool to manage and control authorization policies across an organization's technology stack. The PlainID Authorizer for PostgreSQL Databases is a dynamic solution that modifies the query at runtime to return only data that is authorized for a user to access.
This ensures that users have continuous and contextual access to digital assets within PostgreSQL databases.

The integration of PlainID's Authorization Platform enables organizations to centrally create, manage, and enforce access policies for PostgreSQL databases. It helps organizations to define and manage fine-grained access to data stored in PostgreSQL, ensuring that users have the right permissions to specific data within PostgreSQL.

Technical Information

The PlainID Authorizer seamlessly operates at the data layer, embedded within applications or within the microservices architecture.
By leveraging a PlainID SQL SDK Library, the user's data requests to PostgreSQL database will be intercepted and sent for authorization evaluation by PlainID. A modified query based on authorization policies will be return and forward to the DB for data extraction with the appropriate security filters.
This combination of PostgreSQL and PlainID provides a powerful solution for enterprises to centralize and enhance data authorization and security in the face of growing data volumes and security concerns.

Architectures

  1. A User using an app that will allow interaction with digital assets.
  2. A PlainID library (Spring Boot or .NET) included in the app-level, or in the app's microservice layer that fetches data from the database, will intercept a DB query and initialize a call to the PlainID SQL Database Authorizer’s REST API. *These PlainID libraries helps developers to apply Data Access Control with low code (very minimal) or no code.
  3. The SQL Database Authorizer process the original query it received (such as SELECT * FROM CLIENTS_TABLE) with the user context and reaches out to PlainID PDP REST API for an authorization decision.
    The SQL Database Authorizer alters the original SQL statement, utilizing the identity-aware decision from the PDP, and returns a new SQL statement which includes data access controls, such as SELECT FNAME, LNAME, ADDRESS from CLIENTS_TABLE where CLIENTS TABLE.REGION=’US’.
  4. The altered SQL statement than sent for execution by PostgreSQL and the appropriate data is fetched and served to the user.

Technology

  • Data platforms

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Data Authorization - Filtering
  • Data Authorization - Masking
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.