ADMM - Masking/Decrypt capabilities
Currently Masking/Decrypt capabilities are provided via a SQL function that can be called once data in extacted into SQL server. That raises a risk of developer have an access to sensitive data before they are hidden. Idealy, there should be a capability in the SDR to call a function right after data is extracted to mask/encrypt data before it is written into SQL database. Also decrypt capability should be based on the user security. If that encrypted/masked data is outputted on the report, then only user with security access should be able to see.
Log in to comment and vote
Comments1
John Munkberg
Jan 23
Developers need access to decrypt the data, or it can’t be loaded.
Developers should only publish reports with decrypted data using the Security Whitelist option built into Migrate. In that case, the developer assign SPECIFIC, NAMED user who will have access to View the report. Recommendation is the general reports don’t include sensitive data, and only where required provide a decrypted version of the report for the authorized Business Validator.