Securing Enterprise Database Access Agents & Static NHIs
A comprehensive technical guide for institutional financial customers to govern legacy static service accounts and autonomous AI agents: SCIM 2.0 user sync, Zanzibar ReBAC modeling, passive agent discovery, mandatory management owner assignment from SCIM, MCP query gating, Three-Clock real-time governance, and automated certification campaigns.
Step-by-step UI onboarding wizard with live Aiven PostgreSQL and SpiceDB ReBAC query gating, HMAC masking, and sub-50ms kill switches.
1. Dual-Track Architecture & Lifecycle Overview
Financial enterprises operate with two distinct categories of Non-Human Identities (NHIs) accessing core data warehouses (Databricks Unity Catalog, Snowflake, AWS Redshift, PostgreSQL). AuthHub unifies both under a single governance and attestation plane:
Scheduled ETL pipelines (Airflow, dbt, Spark), database service accounts (authorization_mode: standalone). Require 4-role ownership, dual-secret overlapping rotation, dependency graphs, and SOX recertification.
Text-to-SQL bots, quant research assistants, ad-hoc scenario workers (authorization_mode: dynamic_jit). Require passive SPIFFE discovery, MCP query gating, sub-50ms kill-switches, and deterministic PII masking.
2. Enterprise Identity Sync: SCIM 2.0 Ingress
Enterprise customer directory sync occurs via the SCIM 2.0 Ingress endpoint (/scim/v2/Users and /scim/v2/Groups). AuthHub translates IdP directory attributes directly into SpiceDB relations.
Every SCIM-synced employee receives an immutable AuthHub subject identifier (e.g. usr-scim-alex-quant). These identities form the authoritative pool from which all agent and service account managers are drawn.
When an employee departs the firm, the IdP sends a SCIM deactivation (active: false). AuthHub immediately triggers self-repair workflows and suspends database query agents supervised by that departed individual.
3. Fine-Grained SpiceDB ReBAC Schema & Tuples
AuthHub models enterprise data assets as a three-tier securables hierarchy (catalog β database_schema β table) while enforcing non-human identity (NHI) isolation and Material Non-Public Information (MNPI) boundaries.
definition user {}
definition trading_desk {
relation compliance_officer: user
relation desk_member: user
}
definition nhi {
relation supervisor: user
relation certified_by: user
relation assigned_desk: trading_desk
}
definition catalog {
relation data_owner: user
}
definition database_schema {
relation parent_catalog: catalog
relation schema_reader: user | nhi
}
definition table {
relation parent_schema: database_schema
relation data_steward: user
relation delegated_desk_reader: nhi
relation mnpi_restricted: user
// Autonomous agent can SELECT if granted delegated desk reader
// or schema-level reader, provided table is not MNPI restricted.
permission select = (parent_schema->schema_reader + delegated_desk_reader) - mnpi_restricted
permission export_data = data_steward
}Tuple Ingestion via Management API
To authorize the autonomous agent quant-alpha-bot-01 to query trade_executions, the enterprise backend issues an atomic tuple write:
{
"writes": [
{
"resource": {
"objectType": "table",
"objectId": "trade_executions"
},
"relation": "delegated_desk_reader",
"subject": {
"objectType": "nhi",
"objectId": "quant-alpha-bot-01"
}
}
]
}4. Static NHI Governance: Service Accounts & Legacy Pipelines
Enterprise financial firms possess hundreds of long-lived database accounts, ETL credentials (Airflow, dbt, Spark), and cron jobs. Governed as authorization_mode: standalone, AuthHub enforces lifecycle governance to eradicate unmonitored shadow credentials.
Declare static database accounts with their environmental risk tier (0 for core settlement / general ledger, 1 for trading desk datamarts) and data classification (mnpi, restricted):
{
"name": "etl-settlement-ingest",
"actorType": "service_account",
"environment": "production",
"tier": 0,
"dataClassification": "restricted",
"authorizationMode": "standalone",
"attestationWindowDays": 30,
"businessContext": {
"purpose": "Daily trade settlement sync to Snowflake warehouse",
"criticality": "high"
}
}When rotating static database credentials via POST /api/v1/tenant/nhis/:id/credentials/rotate, AuthHub provisions an overlapping validity window (72 hours for Tier 0, 24 hours for Tier 1). The previous credential remains active during this window so long-running ETL batches never fail. Once the window elapses, the credential_overlap worker auto-revokes the old secret.
AuthHub models both upstream database assets and downstream consumer microservices (POST /api/v1/tenant/nhis/:id/dependencies). Before an engineer revokes a static credential, the Dependency Engine performs impact analysis to prevent accidental outages in trade settlement pipelines.
5. Dynamic Agent Discovery & Authoritative Adoption
Quantitative researchers frequently spin up ad-hoc AI agents locally or in development Kubernetes clusters. AuthHub provides passive traffic discovery that intercepts and fingerprints agent connections without requiring intrusive local software agents.
When an unmanaged bot requests an OAuth token exchange (RFC 8693) or issues a tool call to the Model Context Protocol (MCP) gateway, AuthHub captures its SPIFFE identity, cloud authority (AWS IAM / Azure Managed Identity), and requested database scopes. Target tables containing MNPI automatically push the score above 75, triggering immediate Quarantine.
To permit queries, the discovered agent must be formally adopted via POST /api/v1/tenant/discovery/:id/adopt. This transactionally registers the agent in the NHI database, assigns its initial Technical Owner, and links identity lineage.
6. Mandatory Management Ownership Assignment (SCIM Users)
pending_acceptance and cannot be recertified.Lead Quant / MLOps Engineer
Responsible for SQL model logic, prompt evaluation, schema migrations, and credential rotations.
Trading Desk Head / Portfolio Manager
Holds business accountability, validates query need under FINRA/SEC rules, and attests campaigns.
Backup Qualified Reviewers
Mandatory bench depth of at least two deputies. Prevents attestation gridlock when primary owners are out of office.
Chief Risk Officer / VP Engineering
Automatically notified by the ownership_escalator worker if assignments are unaccepted after 7 days.
Owner Assignment API: Binding SCIM Identities
Assign the Business Owner and Deputies using their SCIM-synchronized user IDs (usr-scim-*):
{
"role": "business_owner",
"assigneeType": "user",
"assigneeId": "aaron.barlow@authhub.cloud",
"assigneeEmail": "aaron.barlow@authhub.cloud",
"orgId": "org-equities-trading",
"priority": 1
}{
"role": "deputy",
"assigneeType": "user",
"assigneeId": "abby.nguyen@authhub.cloud",
"assigneeEmail": "abby.nguyen@authhub.cloud",
"priority": 1
}{
"role": "deputy",
"assigneeType": "user",
"assigneeId": "adam.atkins@authhub.cloud",
"assigneeEmail": "adam.atkins@authhub.cloud",
"priority": 2
}Owner Acceptance Workflow & Management Status Activation
Ownership is not assumedβit must be formally accepted by the assigned human:POST /api/v1/tenant/nhis/:id/owners/:ownerId/accept
Once both the Technical Owner and Business Owner have accepted, AuthHub transitions the agent's managementStatus to healthy. The agent is now eligible for certification campaigns.
7. Enterprise Cloud Database Registration API (Zero-Filesystem Onboarding)
https://api.authhub.cloud/api/v1/tenant/database-connections.Step 1: Register Cloud Database (e.g. Aiven PostgreSQL / AWS RDS / Snowflake)
View in OpenAPI Explorer βAuthHub performs a live connectivity test with the target host, auto-introspects available tables across all schemas (e.g. market_data, confidential, settlement), verifies that owners are valid SCIM identities from Connection n9, and issues an isolated Assigned Gateway URL.
{
"name": "aiven-market-data-prod",
"database_type": "postgres",
"host": "pg-authhub1-authhub-poc1.f.aivencloud.com",
"port": 10952,
"database": "defaultdb",
"user": "avnadmin",
"password": "β’β’β’β’β’β’β’β’β’β’β’β’",
"ssl": "require",
"governance": {
"technical_owner": "Hanif@NiloDevelopments.onmicrosoft.com",
"business_owner": "aaron.barlow@authhub.cloud",
"deputies": [
"abby.nguyen@authhub.cloud",
"adam.atkins@authhub.cloud"
],
"escalation_contact": "Hanif@NiloDevelopments.onmicrosoft.com"
},
"security_controls": {
"max_rows_per_query": 50,
"prohibited_keywords": ["DROP", "TRUNCATE", "ALTER", "DELETE"],
"pii_masking": true,
"require_where_clause": true
}
}{
"status": "success",
"connection": {
"id": "8f700688-46fb-40a2-a05e-a6119f6f6004",
"name": "aiven-market-data-prod",
"assigned_gateway_url": "https://api.authhub.cloud/api/v1/tenant/database-connections/8f700688-46fb-40a2-a05e-a6119f6f6004/query",
"discovered_tables": [
"market_data.trade_executions",
"market_data.portfolio_summary",
"confidential.mnpi_deal_records",
"settlement.settlement_batches"
],
"created_at": "2026-09-21T11:45:00.000Z"
}
}Step 2: AI Agent & Workload Query Execution via Gateway URL
AI agents and workload pipelines dispatch queries strictly to the assigned gateway URL (/api/v1/tenant/database-connections/:id/query). AuthHub checks SpiceDB ReBAC permissions, applies AST safety controls, streams the query to the backend database, and applies deterministic HMAC PII masking in-flight.
{
"sql": "SELECT trade_id, trader_account, symbol, execution_price FROM market_data.trade_executions",
"agent_id": "nhi-market-analyst-agent-01",
"user_id": "Hanif@NiloDevelopments.onmicrosoft.com",
"action": "query"
}Step 3: Clock-1 Emergency Kill Switch (<50ms Isolation)
In an active breach or anomalous data exfiltration incident, security operators can sever all agent and pipeline traffic to the database gateway instantaneously without restarting backend servers.
{
"active": true,
"reason": "Abnormal velocity: 100 queries/sec detected from unverified prompt",
"operator_id": "Hanif@NiloDevelopments.onmicrosoft.com"
}8. Real-Time MCP Gateway & Query Gating
The AI agent communicates with upstream database systems through the standardized Model Context Protocol (MCP). AuthHub functions as an OAuth 2.1 Resource Server (MCP Gateway) that inspects and authorizes every SQL query invocation inline.
No Token Passthrough
The agent never possesses raw database credentials. The agent token only authorizes the hop to the MCP Gateway. If authorized, the Gateway injects ephemeral database secrets to dispatch the query.
Table-Level Authorization
Authorization is enforced per-table. An agent permitted to query portfolio_summary receives a strict 403 Forbidden if its generated SQL references mnpi_deal_records.
Deterministic PII Masking
Before query results return to the LLM context, customer account numbers, IBANs, and trader IDs are dynamically masked with deterministic HMAC hashes (PSEUDO:...).
9. Three-Clock Dynamic Governance
Static permissions are inadequate for autonomous bots capable of issuing thousands of queries per second. AuthHub synchronizes policy enforcement across three distinct operational clocks:
Machine Speed (< 50ms)
Streaming telemetry tracks query volume, row count velocity, and compute cost. If an agent scans >50,000 records or exceeds its hourly budget, AuthHub pushes a kill-switch over WebSockets (/ws/enforcement) terminating the connection instantly.
Business Speed (Human Review)
Suspended agents cannot self-reinstate. A Compliance Officer reviews the flagged query trace in the Console, provides a regulatory justification under FINRA/SEC guidelines, and attests the reinstatement.
Admissibility Boundary
Dynamic policy evaluation enforces operational boundaries: market close embargo windows, trading desk schedules, and schema migration freeze periods inline at evaluation time.
10. Setting Certification Tasks & Recertification Campaigns
Now that every agent and service account is bound to verified SCIM owners, the Chief Risk Officer and Compliance Leads launch periodic Attestation Campaigns. Tasks are routed directly to the assigned owners' queues.
POST/api/v1/tenant/nhis/campaigns
Chief Risk Officer ActionSet up a recertification campaign by defining the target scope filter (e.g. all Tier-0 production accounts), the completion threshold, and the compliance deadline:
{
"name": "Q3 2026 Tier-0 Production Database Access Recertification",
"scopeFilter": {
"environment": "production",
"tier": 0
},
"deadline": "2026-10-31T23:59:59.000Z",
"completionThreshold": 100.0
}When launched, matching accounts transition to pending_attestation, and review tasks populate the SCIM Business Owners' attestation queues.
The SCIM Business Owner confirms continued business necessity and sets a new expiration timestamp:
{
"nhiId": "nhi-quant-alpha-bot-01",
"newExpiresAt": "2027-01-31T00:00:00Z"
}If an algorithm is retired, the owner revokes it with an immutable regulatory audit rationale:
{
"nhiId": "nhi-old-alpha-model",
"reason": "Decommissioned in favor of Quant-v2 model"
}Zero-Delay Compliance Enforcement
AuthHub's scheduled worker (campaign_deadlines) executes every 10 minutes under distributed database leasing. If a campaign passes its deadline, any account remaining in pending_attestation is auto-transitioned to expired.
The spicedb_gc worker automatically deletes the associated relationship tuples in SpiceDB, terminating warehouse access without human delay.
Immutable Merkle Audit Trail
HSM: Paid Add-OnEvery campaign creation, human attestation, and deadline revocation is appended to a SHA-256 hash chain and anchored with RFC 3161 timestamps using standard ECDSA P-256 signatures. For organizations requiring dedicated FIPS 140-2 Level 3 physical key protection, an optional Thales Luna Cloud HSM dedicated partition (Paid Enterprise Add-on) is available.
Ready to implement in your enterprise?
Explore the dedicated API references for Non-Human Identities (NHI), real-time governance signals, and autonomous policy revisions:
