Column-Based Access Policy
Column-based policy allows you to mask column values in query results by specifying individual column names. ALTR enforces column-based policies by failing, masking or NULLing query results for selected user roles.
Column-based policy is defined by a user, data and a masking policy to determine if and how query results are returned when data is accessed.
Create Column Policy
Section titled “Create Column Policy”Column-based policy is defined by a user, data and a masking policy to determine if and how query results are returned when data is accessed.
- Ensure the column to which you are applying policy has been connected in ALTR. Learn more .
- Select Policy in the Navigation menu.
- Click Create Policy .
- Locate the Column Policy card and click Create Policy .
- Select the Column that the policy affects. The policy applies masking rules to values within this column.
- Click Next .
- Create the policy rule statement by selecting the following options:
- Role that the policy affects, which is an ALTR user group. Learn more .
- Masking policy to determine what transformation, if any, occurs to query results when data is accessed. Learn more .
- (Optional) Click Add an alert to configure notifications and/or block users for this policy. Learn more.
- (Optional) Click + Rule Statement to add additional rules for this policy.
- (Optional) Disable Policy State to deactivate the policy if you want to create the policy now and activate it later. The policy can be activated at any time. To deactivate after the policy is created, first resolve all alerts. Deactivating a policy stops applying controls to your data.
- Click Save .
Edit Column Policy
Section titled “Edit Column Policy”Edit a column policy to update masking rules on specified columns or to activate/deactivate the policy. The policy can be activated at any time. To deactivate, first resolve all alerts.
To edit a column policy:
- Select Policy in the Navigation menu.
- Expand the policy to edit.
- Click Edit Policy .
- Update the policy as needed.
- Click Save .
Delete Column Policy
Section titled “Delete Column Policy”Delete a column policy to remove masking rules for the specified columns. Columns in query results based on the defined roles and column values will no longer be masked.
To delete a column policy:
- Select Policy in the Navigation menu.
- Expand the policy to delete.
- Click Edit Policy .
- Click Delete Policy ; the Delete column policy modal displays.
- Click Delete Policy to confirm.