DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofRuntime Visibility

Application-User Attribution

See the Person Behind Each Database Action

When an application uses one database account for everyone, DataSunrise connects recorded activity to the person who performed it.

  • Investigate by User
  • Keep Clearer Audit Trails
  • Apply Rules by User

One database login can hide hundreds of people

Many business applications connect everyone to a database through one shared account. The database can record the account, but not the person using the application.

When the application provides that person's identity, DataSunrise records it alongside the database login. Teams can investigate activity and apply policies by application user while keeping the original database context.

Connect application users to database activity

The application knows who is signed in. The database may see only a shared account. DataSunrise records both.

  1. Application users

    People sign in to the application

    Each person uses their own application identity.

  2. Shared account

    The application uses one database login

    A connection pool can make every action appear to come from the same technical account.

  3. DataSunrise

    DataSunrise records both identities

    When the application passes the user identity, DataSunrise adds it to the activity used for investigations and policies.

Teams can see the application user and the original database login together.
01

Use the Identity in Audit and Protection

Investigation and audit

Search recorded activity by application user and see which person performed an action through the shared account.

Dynamic Data Masking

Use the application user as context when masking rules decide who can see clear data and who receives protected values.

Database security rules

Use the application user as part of the session context for supported security rules.

Database Activity Monitoring records the database activity. Application-User Attribution adds the person behind it.

02

How DataSunrise Receives the User Identity

DataSunrise can receive the signed-in user's identity in several ways. The right method depends on how the application communicates with the database.

Custom applications

Pass the user through a value in a query, a prepared-statement parameter, a session setting, or a lookup response.

Enterprise applications

Use documented identity context from Oracle EBS, SAP ECC, or Bizagi.

More than one application path

Configure multiple supported methods for the same database connection when needed.

After DataSunrise receives the identity, it associates later activity in that session with the application user.

FAQ

Frequently Asked Questions

How does DataSunrise know who used the application?

The application provides a reliable user identity in one of the supported forms. DataSunrise records that supplied identity; it does not infer a person when the information is missing.

Does this replace the database user in the trail?

No. The application user appears beside the database identity, so teams can see both.

Can one database connection use more than one identity method?

Yes. Teams can configure multiple supported methods as alternative ways to identify the application user.

Which enterprise applications have documented identity support?

Current documentation includes Oracle EBS, SAP ECC, and Bizagi.

Does Application-User Attribution identify AI agents?

No. It connects supplied application identities to database activity. Generative AI Activity Monitoring covers activity sent to and received from AI services.

See how DataSunrise works with your technology stack

View Integration Examples