Enterprise ArchitectureFinancial Services & Data WarehousesFINRA / SEC / SOX Compliant

Securing Enterprise Database Access Agents & Static NHIs

A comprehensive technical guide for institutional financial customers to govern legacy static service accounts and autonomous AI agents: SCIM 2.0 user sync, Zanzibar ReBAC modeling, passive agent discovery, mandatory management owner assignment from SCIM, MCP query gating, Three-Clock real-time governance, and automated certification campaigns.

Interactive 5-Phase Guided Journey & Live SimulatorLevel 3

Step-by-step UI onboarding wizard with live Aiven PostgreSQL and SpiceDB ReBAC query gating, HMAC masking, and sub-50ms kill switches.

Phase 1

1. Dual-Track Architecture & Lifecycle Overview

Financial enterprises operate with two distinct categories of Non-Human Identities (NHIs) accessing core data warehouses (Databricks Unity Catalog, Snowflake, AWS Redshift, PostgreSQL). AuthHub unifies both under a single governance and attestation plane:

Track A: Static NHIs (Long-Lived Accounts)

Scheduled ETL pipelines (Airflow, dbt, Spark), database service accounts (authorization_mode: standalone). Require 4-role ownership, dual-secret overlapping rotation, dependency graphs, and SOX recertification.

Track B: Dynamic AI Agents (Autonomous LLMs)

Text-to-SQL bots, quant research assistants, ad-hoc scenario workers (authorization_mode: dynamic_jit). Require passive SPIFFE discovery, MCP query gating, sub-50ms kill-switches, and deterministic PII masking.

Phase 2

2. Enterprise Identity Sync: SCIM 2.0 Ingress

Enterprise customer directory sync occurs via the SCIM 2.0 Ingress endpoint (/scim/v2/Users and /scim/v2/Groups). AuthHub translates IdP directory attributes directly into SpiceDB relations.

Human Accountability Pool

Every SCIM-synced employee receives an immutable AuthHub subject identifier (e.g. usr-scim-alex-quant). These identities form the authoritative pool from which all agent and service account managers are drawn.

Instant Departure Cascade

When an employee departs the firm, the IdP sends a SCIM deactivation (active: false). AuthHub immediately triggers self-repair workflows and suspends database query agents supervised by that departed individual.

Phase 3

3. Fine-Grained SpiceDB ReBAC Schema & Tuples

AuthHub models enterprise data assets as a three-tier securables hierarchy (catalog β†’ database_schema β†’ table) while enforcing non-human identity (NHI) isolation and Material Non-Public Information (MNPI) boundaries.

schema.zanzibarZanzibar DSL
definition user {}

definition trading_desk {
    relation compliance_officer: user
    relation desk_member: user
}

definition nhi {
    relation supervisor: user
    relation certified_by: user
    relation assigned_desk: trading_desk
}

definition catalog {
    relation data_owner: user
}

definition database_schema {
    relation parent_catalog: catalog
    relation schema_reader: user | nhi
}

definition table {
    relation parent_schema: database_schema
    relation data_steward: user
    relation delegated_desk_reader: nhi
    relation mnpi_restricted: user

    // Autonomous agent can SELECT if granted delegated desk reader
    // or schema-level reader, provided table is not MNPI restricted.
    permission select = (parent_schema->schema_reader + delegated_desk_reader) - mnpi_restricted
    permission export_data = data_steward
}

Tuple Ingestion via Management API

To authorize the autonomous agent quant-alpha-bot-01 to query trade_executions, the enterprise backend issues an atomic tuple write:

POST/api/v1/tenant/tuples
{
  "writes": [
    {
      "resource": { 
        "objectType": "table", 
        "objectId": "trade_executions" 
      },
      "relation": "delegated_desk_reader",
      "subject": { 
        "objectType": "nhi", 
        "objectId": "quant-alpha-bot-01" 
      }
    }
  ]
}
Phase 4

4. Static NHI Governance: Service Accounts & Legacy Pipelines

Enterprise financial firms possess hundreds of long-lived database accounts, ETL credentials (Airflow, dbt, Spark), and cron jobs. Governed as authorization_mode: standalone, AuthHub enforces lifecycle governance to eradicate unmonitored shadow credentials.

1. Enrolling Static Database Service Accounts
POST /api/v1/tenant/nhis

Declare static database accounts with their environmental risk tier (0 for core settlement / general ledger, 1 for trading desk datamarts) and data classification (mnpi, restricted):

{
  "name": "etl-settlement-ingest",
  "actorType": "service_account",
  "environment": "production",
  "tier": 0,
  "dataClassification": "restricted",
  "authorizationMode": "standalone",
  "attestationWindowDays": 30,
  "businessContext": {
    "purpose": "Daily trade settlement sync to Snowflake warehouse",
    "criticality": "high"
  }
}
2. Zero-Downtime Dual-Secret Credential Rotation

When rotating static database credentials via POST /api/v1/tenant/nhis/:id/credentials/rotate, AuthHub provisions an overlapping validity window (72 hours for Tier 0, 24 hours for Tier 1). The previous credential remains active during this window so long-running ETL batches never fail. Once the window elapses, the credential_overlap worker auto-revokes the old secret.

3. Dependency Graph & Impact Analysis

AuthHub models both upstream database assets and downstream consumer microservices (POST /api/v1/tenant/nhis/:id/dependencies). Before an engineer revokes a static credential, the Dependency Engine performs impact analysis to prevent accidental outages in trade settlement pipelines.

Phase 5

5. Dynamic Agent Discovery & Authoritative Adoption

Quantitative researchers frequently spin up ad-hoc AI agents locally or in development Kubernetes clusters. AuthHub provides passive traffic discovery that intercepts and fingerprints agent connections without requiring intrusive local software agents.

1. Passive Workload Interception & Scoring (0–100)

When an unmanaged bot requests an OAuth token exchange (RFC 8693) or issues a tool call to the Model Context Protocol (MCP) gateway, AuthHub captures its SPIFFE identity, cloud authority (AWS IAM / Azure Managed Identity), and requested database scopes. Target tables containing MNPI automatically push the score above 75, triggering immediate Quarantine.

2. Governed Adoption into NHI Registry

To permit queries, the discovered agent must be formally adopted via POST /api/v1/tenant/discovery/:id/adopt. This transactionally registers the agent in the NHI database, assigns its initial Technical Owner, and links identity lineage.

Phase 6

6. Mandatory Management Ownership Assignment (SCIM Users)

Mandatory Prerequisite: Before any certification campaign can be launched, every agent (and static service account) must be assigned verified human management owners who were synchronized via SCIM 2.0. An agent without accepted owners remains in pending_acceptance and cannot be recertified.
Role 1: Technical Owner

Lead Quant / MLOps Engineer

Responsible for SQL model logic, prompt evaluation, schema migrations, and credential rotations.

Role 2: Business Owner

Trading Desk Head / Portfolio Manager

Holds business accountability, validates query need under FINRA/SEC rules, and attests campaigns.

Role 3: Deputies (Bench β‰₯ 2)

Backup Qualified Reviewers

Mandatory bench depth of at least two deputies. Prevents attestation gridlock when primary owners are out of office.

Role 4: Escalation Contact

Chief Risk Officer / VP Engineering

Automatically notified by the ownership_escalator worker if assignments are unaccepted after 7 days.

Owner Assignment API: Binding SCIM Identities

Assign the Business Owner and Deputies using their SCIM-synchronized user IDs (usr-scim-*):

POST/api/v1/tenant/nhis/:id/owners (Assign Business Owner)
{
  "role": "business_owner",
  "assigneeType": "user",
  "assigneeId": "aaron.barlow@authhub.cloud",
  "assigneeEmail": "aaron.barlow@authhub.cloud",
  "orgId": "org-equities-trading",
  "priority": 1
}
POST/api/v1/tenant/nhis/:id/owners (Assign Deputy 1 β€” Primary Reviewer)
{
  "role": "deputy",
  "assigneeType": "user",
  "assigneeId": "abby.nguyen@authhub.cloud",
  "assigneeEmail": "abby.nguyen@authhub.cloud",
  "priority": 1
}
POST/api/v1/tenant/nhis/:id/owners (Assign Deputy 2 β€” Secondary Reviewer)
{
  "role": "deputy",
  "assigneeType": "user",
  "assigneeId": "adam.atkins@authhub.cloud",
  "assigneeEmail": "adam.atkins@authhub.cloud",
  "priority": 2
}

Owner Acceptance Workflow & Management Status Activation

Ownership is not assumedβ€”it must be formally accepted by the assigned human:
POST /api/v1/tenant/nhis/:id/owners/:ownerId/accept

Once both the Technical Owner and Business Owner have accepted, AuthHub transitions the agent's managementStatus to healthy. The agent is now eligible for certification campaigns.

Phase 7

7. Enterprise Cloud Database Registration API (Zero-Filesystem Onboarding)

External Customer Zero-Filesystem Rule: External enterprise customers have no access to the AuthHub internal filesystem or cluster secrets. Database onboarding, credential validation, schema introspection, and proxy gateway routing are performed entirely via authenticated public API calls: https://api.authhub.cloud/api/v1/tenant/database-connections.

Step 1: Register Cloud Database (e.g. Aiven PostgreSQL / AWS RDS / Snowflake)

View in OpenAPI Explorer β†’

AuthHub performs a live connectivity test with the target host, auto-introspects available tables across all schemas (e.g. market_data, confidential, settlement), verifies that owners are valid SCIM identities from Connection n9, and issues an isolated Assigned Gateway URL.

POST/api/v1/tenant/database-connections
{
  "name": "aiven-market-data-prod",
  "database_type": "postgres",
  "host": "pg-authhub1-authhub-poc1.f.aivencloud.com",
  "port": 10952,
  "database": "defaultdb",
  "user": "avnadmin",
  "password": "β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’β€’",
  "ssl": "require",
  "governance": {
    "technical_owner": "Hanif@NiloDevelopments.onmicrosoft.com",
    "business_owner": "aaron.barlow@authhub.cloud",
    "deputies": [
      "abby.nguyen@authhub.cloud",
      "adam.atkins@authhub.cloud"
    ],
    "escalation_contact": "Hanif@NiloDevelopments.onmicrosoft.com"
  },
  "security_controls": {
    "max_rows_per_query": 50,
    "prohibited_keywords": ["DROP", "TRUNCATE", "ALTER", "DELETE"],
    "pii_masking": true,
    "require_where_clause": true
  }
}
API Response (201 Created) & Assigned Gateway URL
{
  "status": "success",
  "connection": {
    "id": "8f700688-46fb-40a2-a05e-a6119f6f6004",
    "name": "aiven-market-data-prod",
    "assigned_gateway_url": "https://api.authhub.cloud/api/v1/tenant/database-connections/8f700688-46fb-40a2-a05e-a6119f6f6004/query",
    "discovered_tables": [
      "market_data.trade_executions",
      "market_data.portfolio_summary",
      "confidential.mnpi_deal_records",
      "settlement.settlement_batches"
    ],
    "created_at": "2026-09-21T11:45:00.000Z"
  }
}

Step 2: AI Agent & Workload Query Execution via Gateway URL

AI agents and workload pipelines dispatch queries strictly to the assigned gateway URL (/api/v1/tenant/database-connections/:id/query). AuthHub checks SpiceDB ReBAC permissions, applies AST safety controls, streams the query to the backend database, and applies deterministic HMAC PII masking in-flight.

POST/api/v1/tenant/database-connections/:id/query
{
  "sql": "SELECT trade_id, trader_account, symbol, execution_price FROM market_data.trade_executions",
  "agent_id": "nhi-market-analyst-agent-01",
  "user_id": "Hanif@NiloDevelopments.onmicrosoft.com",
  "action": "query"
}

Step 3: Clock-1 Emergency Kill Switch (<50ms Isolation)

In an active breach or anomalous data exfiltration incident, security operators can sever all agent and pipeline traffic to the database gateway instantaneously without restarting backend servers.

POST/api/v1/tenant/database-connections/:id/kill-switch
{
  "active": true,
  "reason": "Abnormal velocity: 100 queries/sec detected from unverified prompt",
  "operator_id": "Hanif@NiloDevelopments.onmicrosoft.com"
}
Phase 8

8. Real-Time MCP Gateway & Query Gating

The AI agent communicates with upstream database systems through the standardized Model Context Protocol (MCP). AuthHub functions as an OAuth 2.1 Resource Server (MCP Gateway) that inspects and authorizes every SQL query invocation inline.

M8 Security Principle

No Token Passthrough

The agent never possesses raw database credentials. The agent token only authorizes the hop to the MCP Gateway. If authorized, the Gateway injects ephemeral database secrets to dispatch the query.

Per-Resource Control

Table-Level Authorization

Authorization is enforced per-table. An agent permitted to query portfolio_summary receives a strict 403 Forbidden if its generated SQL references mnpi_deal_records.

Data Privacy

Deterministic PII Masking

Before query results return to the LLM context, customer account numbers, IBANs, and trader IDs are dynamically masked with deterministic HMAC hashes (PSEUDO:...).

Phase 9

9. Three-Clock Dynamic Governance

Static permissions are inadequate for autonomous bots capable of issuing thousands of queries per second. AuthHub synchronizes policy enforcement across three distinct operational clocks:

Clock 1: Signals

Machine Speed (< 50ms)

Streaming telemetry tracks query volume, row count velocity, and compute cost. If an agent scans >50,000 records or exceeds its hourly budget, AuthHub pushes a kill-switch over WebSockets (/ws/enforcement) terminating the connection instantly.

Clock 2: Attestation

Business Speed (Human Review)

Suspended agents cannot self-reinstate. A Compliance Officer reviews the flagged query trace in the Console, provides a regulatory justification under FINRA/SEC guidelines, and attests the reinstatement.

Clock 3: Execution

Admissibility Boundary

Dynamic policy evaluation enforces operational boundaries: market close embargo windows, trading desk schedules, and schema migration freeze periods inline at evaluation time.

Phase 10

10. Setting Certification Tasks & Recertification Campaigns

Now that every agent and service account is bound to verified SCIM owners, the Chief Risk Officer and Compliance Leads launch periodic Attestation Campaigns. Tasks are routed directly to the assigned owners' queues.

POST/api/v1/tenant/nhis/campaigns

Chief Risk Officer Action

Set up a recertification campaign by defining the target scope filter (e.g. all Tier-0 production accounts), the completion threshold, and the compliance deadline:

create-campaign.json
{
  "name": "Q3 2026 Tier-0 Production Database Access Recertification",
  "scopeFilter": {
    "environment": "production",
    "tier": 0
  },
  "deadline": "2026-10-31T23:59:59.000Z",
  "completionThreshold": 100.0
}

When launched, matching accounts transition to pending_attestation, and review tasks populate the SCIM Business Owners' attestation queues.

Attest & Extend Lease
POST .../campaigns/:id/certify

The SCIM Business Owner confirms continued business necessity and sets a new expiration timestamp:

{
  "nhiId": "nhi-quant-alpha-bot-01",
  "newExpiresAt": "2027-01-31T00:00:00Z"
}
Explicit Revocation
POST .../campaigns/:id/revoke

If an algorithm is retired, the owner revokes it with an immutable regulatory audit rationale:

{
  "nhiId": "nhi-old-alpha-model",
  "reason": "Decommissioned in favor of Quant-v2 model"
}
Automated Deadline Sweep: CampaignDeadlineProcessor

Zero-Delay Compliance Enforcement

AuthHub's scheduled worker (campaign_deadlines) executes every 10 minutes under distributed database leasing. If a campaign passes its deadline, any account remaining in pending_attestation is auto-transitioned to expired.

The spicedb_gc worker automatically deletes the associated relationship tuples in SpiceDB, terminating warehouse access without human delay.

Immutable Merkle Audit Trail

HSM: Paid Add-On

Every campaign creation, human attestation, and deadline revocation is appended to a SHA-256 hash chain and anchored with RFC 3161 timestamps using standard ECDSA P-256 signatures. For organizations requiring dedicated FIPS 140-2 Level 3 physical key protection, an optional Thales Luna Cloud HSM dedicated partition (Paid Enterprise Add-on) is available.

Ready to implement in your enterprise?

Explore the dedicated API references for Non-Human Identities (NHI), real-time governance signals, and autonomous policy revisions: