Security & Access Control enforces governance-authored policies across every identity — human users and AI agents — with column, row, and cell-level granularity and a complete, immutable audit trail.
Regulators don't ask if you have access controls. They ask whether you can demonstrate consistent, policy-driven enforcement — for every human and every AI agent.
Users change roles but retain old permissions. Agents deployed with broad test access never tightened for production. The gap between who should and who does have access widens undetected.
AI agents typically access data through service accounts that bypass the governance framework — ungoverned by the same policies that cover human access, and invisible to compliance teams.
One policy in the database, another in the cloud platform, another in the analytics tool. No single view of the full access estate. No consistent enforcement across federated sources.
Role-based foundations combined with context-aware attribute-based controls — enforced at the federation layer for every data request from every identity.
A credit analyst accesses credit data domains. A compliance officer accesses audit records. CredXplain accesses credit decisioning data. Roles define what functions require.
Location, time of access, device type, data sensitivity, consumer type (human vs. agent), and request context. Conditions evaluated in real time — not pre-configured statically.
| Identity | customer_name | pan_number | account_no | bureau_score | annual_income | Row Scope |
|---|---|---|---|---|---|---|
| Compliance Officer | ● | ● | ● | ● | ● | All Records |
| Branch Manager — Mumbai | ● | Partial | Partial | ● | ○ | Mumbai Only |
| Credit Analyst | ● | Partial | ● | ● | ● | All Records |
| CredXplain Agent | ○ | ○ | Scoped | ● | ● | All Records |
| Analytics Dashboard | ○ | ○ | ○ | Banded | Banded | Anonymised |
| TextIQ Agent | ○ | ○ | ○ | ○ | ○ | No Access |
One access policy governs data across all federated sources — on-premise, cloud, partner, and legacy. No per-system drift. Every request evaluated against the same governed policy.
AI agents enrolled as governed identities with defined scopes and access policies — exactly like human users. CredXplain has access to credit data. Not HR. Not payroll. Governed and auditable.
Access operates at the finest granularity the data structure permits — same dataset, different views based on identity, role, and context. Governed at the federation layer for every request.
Automated periodic reviews surface stale permissions, over-provisioned accounts, and dormant access rights. Findings routed to data stewards — least-privilege maintained as the organisation evolves.
Every access grant, modification, revocation, and usage event captured. Demonstrate to regulators: who had access, who granted it, when, under which policy, and what was accessed.
Pre-built reports for access governance: permission change history, access review outcomes, over-provisioned identity alerts, and agent access summaries — aligned to GDPR, HIPAA, and RBI requirements.
See how Tantor enforces governed access across human users and AI agents — with full auditability and zero configuration drift.