Skip to content
PlainID
← Back to all integrations
SQL Database logo

SQL Database

Apply fine-grained data filtering and masking for application access to SQL databases.

About PlainID + SQL Database

SQL databases are widely used by enterprises to store various types of data, ranging from analytical to operational data. As the volume of data continues to grow, there is an increasing need for enterprises to ensure that data is not exposed to unauthorized users.

PlainID offers a platform that centralizes the management and control of authorization policies across the enterprise technology stack. With the PlainID Authorizer for SQL Databases, the query is dynamically modified at runtime to return only data that the user is authorized to see. This ensures continuous and contextual access to digital assets within the database.

The integration of PlainID's Authorization platform enables organizations to create, manage, and enforce authorization policies from a centralized platform. Moreover, it allows organizations to define and manage fine-grained access rules using attributes, roles, and permissions to ensure that only authorized users have access to specific data within SQL.

Technical Information

The PlainID SQL Database Authorizer operates as a data query modification service and addresses data security at scale, and dynamically, for all users who access SQL databases.
By leveraging the PlainID SQL SDK Libraries, this service communicates with the data layer, inside the applications, or internal to your microservices layer.
The SQL Database Authorizer processes the incoming intercepted queries and uses the PlainID Authorization Policy Decision Point to evaluate the required data controls according to dynamic identity-aware policies and modify the queries in accordance.

Architectures

  1. A User using an app that will allow interaction with digital assets.
  2. A PlainID library (Spring Boot or .NET) included in the app-level, or in the app's microservice layer that fetches data from the database, will intercept a DB query and initialize a call to the PlainID SQL Database Authorizer REST API. *These PlainID libraries helps developers to apply Data Access Control with low code (very minimal) or no code.
  3. The SQL Database Authorizer process the original query it received (such as SELECT * FROM CLIENTS_TABLE) with the user context and reaches out to PlainID PDP REST API for an authorization decision.
  4. The SQL Database Authorizer alters the original SQL statement, utilizing the identity-aware decision from the PDP, and returns a new SQL statement which includes data access controls, such as SELECT FNAME, LNAME, ADDRESS from CLIENTS_TABLE where CLIENTS TABLE.REGION=’US’.
  5. The altered SQL statement than sent for execution by database and the appropriate data is fetched and served to the user.

Technology

  • Data platforms

Capabilities

  • Manage
  • Enforce

Auth Patterns

  • Data Authorization - Filtering
  • Data Authorization - Masking
  • Policy information point (PIP)

Need help integrating?

Our experts can help you architect the perfect authorization strategy for your stack.

Contact Support

Better Together

Connect Context. Centralize Policy. Enforce Everywhere.