BigQuery connector

Metadata-only discovery, dataset- and table-level enforcement, access intelligence and grant drift.

Before you start

  • A Google Cloud service account for Trinitis, with a JSON key.
  • These APIs enabled on the project: BigQuery, Cloud Resource Manager, Cloud Identity, Data Catalog, and BigQuery Data Policy.
  • For group membership and provisioning: a Google Workspace admin to set up domain-wide delegation.
  • Column masking and migration import are not available on BigQuery today.

What Trinitis reads

  • Dataset, table and column metadata — with data reads denied
  • Project IAM policy, for grant reading and drift detection
  • BigQuery job history, for access intelligence
  • Google group membership

Trinitis stores metadata only. It never copies data values out of BigQuery.

What Trinitis writes

  • Dataset- and table-level IAM bindings for approved policies
  • Google group membership, when group provisioning is enabled

Trinitis writes only policies you have approved, into BigQuery's own native controls.

Required privileges

Grant only what you need for the capabilities you plan to use.

Discovery and classification (no data access)

  • roles/bigquery.metadataViewer

Access intelligence

  • roles/bigquery.jobUser
  • roles/bigquery.user
  • bigquery.jobs.listAll (to see all users' jobs)

Grant reading, drift detection and group mapping

  • resourcemanager.projects.getIamPolicy or roles/iam.securityReviewer
  • Cloud Resource Manager API enabled

Group membership and provisioning

  • Cloud Identity Groups Reader or Admin
  • Domain-wide delegation

Steps

  1. Create the service account, grant the roles above for the capabilities you want, enable the listed APIs, and download a JSON key.
  2. Sign in at app.trinitis.ai and open Connections → Add Connection → BigQuery.
  3. Enter the connection details for the project and provide the service-account JSON key.
  4. Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
  5. Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.