Oracle AI Database 26ai Introduces Deep Data Security for Row and Column Access Control
Oracle AI Database 26ai has introduced a feature called Oracle Deep Data Security (Deep Sec), a database-enforced authorization framework that controls access at the row, column, and cell level. Unlike traditional application-layer security, Deep Sec enforces access policies directly within the database, regardless of whether the request originates from a human user, a reporting tool, or an AI agent. The system introduces three new building blocks: local end users (lightweight identities that own no schema), data roles (fine-grained privilege carriers that can sync with external identity providers like Microsoft Entra ID), and data grants (SQL-native policy objects defining read/write permissions). Local end users are created with a new CREATE END USER statement and tracked via a dedicated DBA_END_USERS dictionary view, but they cannot connect independently and must be authorized through data roles and grants. The feature is designed to complement existing Oracle tools like Label Security and Data Masking while offering a cleaner, more scalable approach to least-privilege access enforcement.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.


Discussion (0)
Log in to join the discussion and vote.
Log in