Universal data access management

Extensible and universal data access management with automated access workflows and security controls across data stores, analytical systems, and cloud products.
Powering the best data teams
gojek
midtrans
mapan
moka
zoomcar
gojek
midtrans
mapan
moka
zoomcar
gojek
midtrans
mapan
moka
zoomcar
gojek
midtrans
mapan
moka
zoomcar

Goals

Secure access anytime

Guardian is a data access management tool. It manages resources from various data providers along with the users‘ access. Users required to raise an appeal in order to gain access to a particular resource. The appeal will go through several approvals before it is getting approved and granted the access to the user.

Productivity

Replace manual processes with automated workflows to deliver, manage and secure access to essential business resources.

Visibility

Provide a complete view of all access across organization, including those hidden or unknown that may pose inherent risk.

Intelligence

Stay ahead of the security curve with recommendations, detection and remediation that adapts as your organization evolves.
architecture

Key Features

Built for security

Guardian is the data access and control solution, enabling data teams to accelerate data delivery, reduce risk, and safely unlock more data.

Universal control

Simplify access management for databases, pipelines, data lakes or reporting tools using your existing IAM tools and embrace zero trust by ensuring users access only the resources they should.

Access monitoring

Track and manage all data access requests across resources. Guardian enables governance teams to monitor and notifies your teams immediately when it detects unauthorized users accessing any resource.

Ephemeral access

Grant your users only just in time and just enough access to your mission-critical and sensitive data resources. Guardian helps reduce the attack surface by eliminating the need for long-term privileged access for users.

Compliant workflows

Ensure that access to resources complies with company policies and regulations. Guardian's YAML-based policy syntax gives you context-rich, highly granular enforcement over who can access what data.

Identity and context control

Guardian integrates with popular identity providers to apply policies to specific groups or individual users. In addition, it makes it easy to extend identity control through any third party or internal identity provider.

Configurable approval flow

Approval flow configures what is needed for an appeal to get approved and who is eligible to approve/reject. It can be configured so that every appeal created to their resources will follow the procedure in order to get approved.

Ecosystem

Pre-built integrations

Guardian‘s extensible system allows new providers to be easily added. Multiple providers are supported, including: Metabase, BigQuery, Tableau and more.

Providers

Support various providers like Big Query, Metabase, Tableau, and multiple instances for each provider. Guardian can be extended to support any provider with a simple plugin.

Identity

Guardian integrates with popular identity providers to apply policies to specific groups or individual users. In addition, it makes it easy to extend identity control through any third party or internal identity.

Notifiers

Guardian supports multiple notification systems like Slack, Email, and more. It can be extended to support any notifier with a simple plugin.

Community

Want to get involved?

Join the community on Slack and talk to maintainers to answer your questions.
Explore and contribute to Raystack data platform on Github.

© 2023 Raystack Foundation, Inc.oss