PostgreSQL connector
Discovery (including columns), enforcement with column-level grants, access intelligence and grant drift.
Before you start
- A dedicated service user for Trinitis.
- Network access from Trinitis: a public endpoint, or an SSH tunnel through a bastion host.
- For access intelligence: pgaudit configured with pgaudit.log = 'read', or pg_stat_statements as a fallback.
- Migration import is not available on PostgreSQL.
What Trinitis reads
- Schema, table and column metadata
- Existing grants, including column-level grants
- Query activity from pgaudit or pg_stat_statements, for access intelligence
Trinitis stores metadata only. It never copies data values out of PostgreSQL.
What Trinitis writes
- Native GRANT and REVOKE for approved policies, including GRANT/REVOKE SELECT (column)
- Group roles and their membership
Trinitis writes only policies you have approved, into PostgreSQL's own native controls.
Required privileges
Grant only what you need for the capabilities you plan to use.
Discovery
- USAGE ON SCHEMA <schema>
- SELECT ON ALL TABLES IN SCHEMA <schema>
Group provisioning
- CREATEROLE
- GRANT <group> TO trinitis_user WITH ADMIN OPTION (for each mapped group)
Access intelligence
- pgaudit.log = 'read'
- or pg_stat_statements (fallback)
On Amazon Aurora PostgreSQL, Trinitis can apply native column masking (via the pg_columnmask extension). On community or RDS PostgreSQL, column access is enforced by restriction.
About the SELECT privilege
This platform exposes no metadata-only option, so the SELECT privilege that reveals column metadata is the same privilege that can read rows. Trinitis reads only schema and column metadata and stores no row values, but the credential is capable of reading data and should be evaluated on that basis.
See Security for how this compares across platforms.
Steps
- Create the service user and grant the privileges above for the capabilities you want.
- Sign in at app.trinitis.ai and open Connections → Add Connection → PostgreSQL.
- Enter the connection details for the service user, and choose Public endpoint or SSH tunnel.
- Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
- Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.