Security & Access Control

Govern who accesses what.
Down to the field.

Security & Access Control enforces governance-authored policies across every identity — human users and AI agents — with column, row, and cell-level granularity and a complete, immutable audit trail.

RBAC + ABACAgent identity governanceField-level controlReal-time enforcementImmutable audit trail
Access Matrix — Customer Domain
Compliance Officer
Full access · All fields · All records
Full
Branch Manager — Mumbai
Masked PAN · Mumbai records only
Partial
CredXplain Agent
Credit fields only · Score visible
Scoped
Analytics Dashboard
Anonymised · No identifiers
Restricted
TextIQ Agent
No access to customer domain
No Access

Can you prove who accessed
what data, when, and why?

Regulators don't ask if you have access controls. They ask whether you can demonstrate consistent, policy-driven enforcement — for every human and every AI agent.

Access sprawl accumulates silently.

Users change roles but retain old permissions. Agents deployed with broad test access never tightened for production. The gap between who should and who does have access widens undetected.

Agents are unmanaged identities.

AI agents typically access data through service accounts that bypass the governance framework — ungoverned by the same policies that cover human access, and invisible to compliance teams.

Per-system rules fragment governance.

One policy in the database, another in the cloud platform, another in the analytics tool. No single view of the full access estate. No consistent enforcement across federated sources.

Hybrid RBAC + ABAC.
Evaluated in real time.

Role-based foundations combined with context-aware attribute-based controls — enforced at the federation layer for every data request from every identity.

RBAC — Role-Based

Baseline permissions by role.

A credit analyst accesses credit data domains. A compliance officer accesses audit records. CredXplain accesses credit decisioning data. Roles define what functions require.

  • Roles aligned to job functions and organisational hierarchy
  • Agent roles aligned to agent purpose and governed scope
  • Role lifecycle management — creation, modification, retirement
ABAC — Attribute-Based

Context-aware precision.

Location, time of access, device type, data sensitivity, consumer type (human vs. agent), and request context. Conditions evaluated in real time — not pre-configured statically.

  • Location attributes — branch, region, geography
  • Temporal conditions — business hours, access windows
  • Data sensitivity classification — restricted, confidential
Identity customer_name pan_number account_no bureau_score annual_income Row Scope
Compliance OfficerAll Records
Branch Manager — MumbaiPartialPartialMumbai Only
Credit AnalystPartialAll Records
CredXplain AgentScopedAll Records
Analytics DashboardBandedBandedAnonymised
TextIQ AgentNo Access
Full access P Masked / Partial S Scoped No access

What Security & Access Control
delivers.

⚖️

Federation-Wide Enforcement

One access policy governs data across all federated sources — on-premise, cloud, partner, and legacy. No per-system drift. Every request evaluated against the same governed policy.

🤖

Agent Identity Governance

AI agents enrolled as governed identities with defined scopes and access policies — exactly like human users. CredXplain has access to credit data. Not HR. Not payroll. Governed and auditable.

🔬

Column, Row & Cell-Level Control

Access operates at the finest granularity the data structure permits — same dataset, different views based on identity, role, and context. Governed at the federation layer for every request.

🔄

Continuous Access Review

Automated periodic reviews surface stale permissions, over-provisioned accounts, and dormant access rights. Findings routed to data stewards — least-privilege maintained as the organisation evolves.

📋

Complete Audit Trail

Every access grant, modification, revocation, and usage event captured. Demonstrate to regulators: who had access, who granted it, when, under which policy, and what was accessed.

📊

Compliance Reporting

Pre-built reports for access governance: permission change history, access review outcomes, over-provisioned identity alerts, and agent access summaries — aligned to GDPR, HIPAA, and RBI requirements.

One policy.
Every identity. Every field.

See how Tantor enforces governed access across human users and AI agents — with full auditability and zero configuration drift.