Redshift connector

Discovery, enforcement (including native dynamic data masking), access intelligence, migration import and grant drift.

Before you start

  • A dedicated service user and a capability role for Trinitis.
  • Network access from Trinitis: a public endpoint, or an SSH tunnel through a bastion host.
  • An administrator who can create users and roles and run the grants below.

What Trinitis reads

  • Schema, table and column metadata
  • Existing grants, from the grant catalog
  • Query history from system tables, for access intelligence

Trinitis stores metadata only. It never copies data values out of Redshift.

What Trinitis writes

  • Grants and roles for approved policies
  • Dynamic data masking policies
  • Roles used as platform groups

Trinitis writes only policies you have approved, into Redshift's own native controls.

Required privileges

Grant only what you need for the capabilities you plan to use.

Discovery

  • USAGE ON SCHEMA <schema>
  • SELECT ON ALL TABLES IN SCHEMA <schema>

Capability role (granted to the service user)

  • CREATE ROLE — platform groups
  • ACCESS SYSTEM TABLE — grant catalog
  • ROLE sys:secadmin — column masking

Access intelligence

  • SELECT ON stl_query
  • SELECT ON stl_querytext
  • SELECT ON stl_error
  • SELECT ON stl_scan

Optional — query history for all users

  • SYSLOG ACCESS UNRESTRICTED

About the SELECT privilege

This platform exposes no metadata-only option, so the SELECT privilege that reveals column metadata is the same privilege that can read rows. Trinitis reads only schema and column metadata and stores no row values, but the credential is capable of reading data and should be evaluated on that basis.

See Security for how this compares across platforms.

Steps

  1. Create the service user and capability role, and grant the privileges above for the capabilities you want.
  2. Sign in at app.trinitis.ai and open Connections → Add Connection → Redshift.
  3. Enter the connection details for the service user, and choose Public endpoint or SSH tunnel.
  4. Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
  5. Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.