Part ofRuntime Visibility
Application-User Attribution
See the Person Behind Each Database Action
When an application uses one database account for everyone, DataSunrise connects recorded activity to the person who performed it.
- Investigate by User
- Keep Clearer Audit Trails
- Apply Rules by User
The shared-login problem
One database login can hide hundreds of people
Many business applications connect everyone to a database through one shared account. The database can record the account, but not the person using the application.
When the application provides that person's identity, DataSunrise records it alongside the database login. Teams can investigate activity and apply policies by application user while keeping the original database context.
How it works
Connect application users to database activity
The application knows who is signed in. The database may see only a shared account. DataSunrise records both.
-
Application users
People sign in to the application
Each person uses their own application identity.
-
Shared account
The application uses one database login
A connection pool can make every action appear to come from the same technical account.
-
DataSunrise
DataSunrise records both identities
When the application passes the user identity, DataSunrise adds it to the activity used for investigations and policies.
Use the Identity in Audit and Protection
Investigation and audit
Search recorded activity by application user and see which person performed an action through the shared account.
Dynamic Data Masking
Use the application user as context when masking rules decide who can see clear data and who receives protected values.
Database security rules
Use the application user as part of the session context for supported security rules.
Database Activity Monitoring records the database activity. Application-User Attribution adds the person behind it.
How DataSunrise Receives the User Identity
DataSunrise can receive the signed-in user's identity in several ways. The right method depends on how the application communicates with the database.
Custom applications
Pass the user through a value in a query, a prepared-statement parameter, a session setting, or a lookup response.
Enterprise applications
Use documented identity context from Oracle EBS, SAP ECC, or Bizagi.
More than one application path
Configure multiple supported methods for the same database connection when needed.
After DataSunrise receives the identity, it associates later activity in that session with the application user.
Frequently Asked Questions
How does DataSunrise know who used the application?
The application provides a reliable user identity in one of the supported forms. DataSunrise records that supplied identity; it does not infer a person when the information is missing.
Does this replace the database user in the trail?
No. The application user appears beside the database identity, so teams can see both.
Can one database connection use more than one identity method?
Yes. Teams can configure multiple supported methods as alternative ways to identify the application user.
Which enterprise applications have documented identity support?
Current documentation includes Oracle EBS, SAP ECC, and Bizagi.
Does Application-User Attribution identify AI agents?
No. It connects supplied application identities to database activity. Generative AI Activity Monitoring covers activity sent to and received from AI services.
Map the right workflow