Redshift
Apply fine-grained data filtering and masking for application access to Amazon Redshift.
About PlainID + Redshift
Amazon Redshift is a cloud-based data warehousing service that stores and analyzes vast amounts of data for businesses where access control is crucial.
PlainID offers a platform that centralizes the management and control of authorization policies across the enterprise technology stack. With the PlainID Authorizer for Redshift, the query is dynamically modified at runtime to return only data that the user is authorized to see. This ensures continuous and contextual access to digital assets within the database.
The PlainID Authorizer for Redshift is an essential component that is responsible for defining and enforcing access policies within the Redshift data warehouse. Acting as a gatekeeper, it regulates who can access what data based on user attributes, roles, and contextual information. The value of using this Authorizer lies in its ability to provide granular access control, real-time authorization, and centralized policy management. It ensures data security and compliance in complex Redshift environments by offering an effective solution for managing access control in a way that is both efficient and easy to use.
Technical Information
The PlainID Authorizer seamlessly operates at the data layer, embedded within applications or within the microservices architecture.
By leveraging a PlainID SQL SDK Library, the user's data requests to the Redshift database will be intercepted and sent for authorization evaluation by PlainID.
A modified query based on authorization policies will be returned and forwarded to the DB for data extraction with the appropriate security filters.
This combination of Redshift and PlainID provides a powerful solution for enterprises to centralize and enhance data authorization and security in the face of growing data volumes and security concerns.
Architectures
- A User using an app that will allow interaction with digital assets.
- A PlainID library (Spring Boot or .NET) included in the app-level, or in the app's microservice layer that fetches data from the database, will intercept a DB query and initialize a call to the PlainID SQL Database Authorizer’s REST API. *These PlainID libraries helps developers to apply Data Access Control with low code (very minimal) or no code.
- The SQL Database Authorizer process the original query it received (such as SELECT * FROM CLIENTS_TABLE) with the user context and reaches out to PlainID PDP REST API for an authorization decision.
The SQL Database Authorizer alters the original SQL statement, utilizing the identity-aware decision from the PDP, and returns a new SQL statement which includes data access controls, such as SELECT FNAME, LNAME, ADDRESS from CLIENTS_TABLE where CLIENTS TABLE.REGION=’US’. - The altered SQL statement than sent for execution by Redshift and the appropriate data is fetched and served to the user.
Technology
- Data platforms
Capabilities
- Manage
- Enforce
Auth Patterns
- Data Authorization - Filtering
- Data Authorization - Masking
- Policy information point (PIP)
Need help integrating?
Our experts can help you architect the perfect authorization strategy for your stack.
Better Together
Connect Context. Centralize Policy. Enforce Everywhere.


