Data Access Governance
Cortex Data Security enables Data Access Governance (DAG) by providing visibility into the relationships between identities and sensitive data across your cloud and identity estates. The platform calculates the effective permissions of every human and machine identity, helping you identify over-privileged access and enforce the principle of least privilege for your critical data assets.
Net-effective permission calculation
The platform calculates the effective permissions of an identity by resolving its assigned IAM roles, group memberships, and resource-level policies into the access it actually has.
Identity Security dashboard: Monitor your entire identity estate from a centralized dashboard that provides a unified view of identities, effective permissions, access paths, and over-privileged or high-risk access across cloud and SaaS environments.
Identity-enriched security graph: Visualize access paths across AWS, Azure, and GCP to see how human and non-human identities can reach sensitive data.
Cross-environment access analysis: Map permissions from identity providers (IdPs) such as Okta and Google Workspace to their downstream cloud resources.
Effective permissions modeling: Consolidate policies, group memberships, and resource-level permissions into a single allow or deny verdict.
Least privilege enforcement
The platform identifies excessive or unused permissions that increase your attack surface so you can remediate them.
Unused access detection: Audit and revoke permissions that have not been used for an extended period (for example, 90 or more days).
Rightsize recommendations: Provides data-aware recommendations to reduce the permissions of over-privileged service accounts and admin roles.
Privileged identity monitoring: Track shadow admins and high-risk machine identities that hold potentially destructive permissions on sensitive data stores.
AI-aware access governance
The platform extends identity controls to agentic workflows and AI-driven data access.
AI agent monitoring: Track and govern the permissions of AI agents that handle sensitive corporate information.
Copilot readiness: Generate reports to confirm that your Microsoft 365 or Google Workspace environment has the required data access controls in place before you deploy generative AI tools.
Autonomous identity response: Use playbooks to revoke access or trigger reviews when anomalous identity behavior is detected.
Last updated
Was this helpful?
