In today’s data-driven economy, enterprises are struggling to find a balance between making data readily accessible and ensuring its security and compliance. Traditional data management approaches often fail to deal with siloed storage, security vulnerabilities, and ever-evolving regulatory requirements. These challenges not only create friction in data access but also expose organizations to significant operational and compliance risks.
Data marketplaces are emerging as a transformative solution to these challenges, enabling organizations to seamlessly share data assets without compromising security or compliance. By facilitating controlled data exchange between producers and consumers, these platforms help enterprises unlock the full potential of their data while avoiding costly governance and security issues.
Join experts from KuppingerCole Analysts and Immuta as they explore how data marketplaces can enhance secure data sharing, streamline governance, and foster innovation — all while reducing the risks of data breaches and unauthorized exposure.
Alexei Balaganski, Lead Analyst at KuppingerCole Analysts, will present an overview of the risks associated with multi-cloud data management, highlighting strategies to reduce data friction while maintaining security and compliance in an increasingly complex regulatory landscape.
Carsten Bruns, Senior Solutions Architect at Immuta, will share insights into best practices for implementing data marketplaces, real-world use cases, and how Immuta’s Data Security Platform enables organizations to manage data sharing efficiently and in full compliance with regulatory requirements.
Well, hello, and welcome to another KuppingerCole webinar. My name is Alexei Balaganski. I'm the lead analyst at KuppingerCole. Our topic for today is Unleash Data Governance, How Data Marketplaces Enable Seamless and Secure Sharing. And my guest for today is Carsten Bruns, who is a Senior Solution Architect at Immuta.
Welcome, Carsten. Hello, thanks for welcoming me.
Okay, great. Before we jump into the webinar, we have a few housekeeping rules to discuss. First of all, every attendee is muted, so you don't have to worry about the microphone. We are actually not running any polls today. Sorry about that misleading bit of information. But we will definitely have a Q&A, a questions and answer session later in this webinar. Before that, just stay with us and enjoy the show. We are recording the entire webinar and the video and the actual slide decks will be published on our website tomorrow.
And every registered person will receive an email with all the links and information. Our agenda for today is as usual for any KuppingerCole webinar.
First, I will start with a general introduction of the quote-unquote problem field and explain why we are actually in dire need of better data tools. And then I will give the stage to Carsten, who will provide you a deeper technical dive into specific solutions. And he will even show you one in action in a demo. And as I mentioned earlier, in the end, we will have time for questions and answers. So at any time during the webinar, do not hesitate to submit your questions into the questions box within the Livestorm platform.
And let me start by saying that, well, what a time to be alive, especially if you are in IT security. With all those crazy technologies available for modern businesses nowadays, clouds, mobile devices, software as a service, and of course, generative AI, we have been somehow overwhelmed with choices. There are so many opportunities, there are so many technical possibilities, and yet we are still struggling with issues. Why?
Well, of course, to an extent, we have the rest of the world to blame, if you will, the politicians, the somewhat downward economic curve in recent times, many things to consider. But the challenges we had have been there all the time, data breaches, business continuity issues, compliance failures, they are on every IT security person's mind, on every business person's mind nowadays. And of course, we have to forget that, especially in somewhat difficult times like now, efficiency is the key to survival. When you have to abandon everything just to stay afloat, security goes away pretty early.
So yeah, we are, if you will, living in very interesting times. And it's kind of ironic to know that this comic strip was actually published exactly 30 years ago, but oh well, how relevant it is for our today's situation. It's like a six-year-old dream come true. But yet we are in IT, we are in IT security, so we have to focus on the more specific questions. How do we survive? How do we turn profit in these challenging times? And of course, for digital businesses, the most important question is, how do we provide our business colleagues with data efficiently, quickly, and securely?
Of course, when we are talking about the modern hybrid and multi-cloud world, we have to consider many, many additional challenges. Each cloud is a silo, or in fact many silos, because if you consider that AWS alone has 20-plus different database engines available for you as a customer, as well as a lot of SaaS services and hosted solutions and whatnot, there are so many conflicting security stacks and disjointed tools. There are so many regulations and new appear all the time. It all leads to an explosion in complexity.
And explosion in complexity leads to wasted money and time, to a lot of human errors, and of course to a shortage in resources. And when we are talking about resources, we are primarily actually talking about humans now, people. Because as soon as you start to grow, as soon as you want to scale, people just cannot keep up, and what you are looking for is automation.
Well, how do we deal with all this mess, especially when it comes to data? And one thing I wanted to address before everything else is this notorious myth about the crown jewels. You probably heard this term a lot every time someone is talking about a digital business, whether it's your customer-sensitive data or your IP, like your secret Coca-Cola recipe, or your financial transactions, it's somehow your crown jewels. I would argue it's a very wrong and misleading term. First of all, you cannot obviously put your data into a safe and forget about them.
You have to make your data work for you all the time, because data usually does not have any intrinsic, no intrinsic monetary value, and it only becomes useful, it only generates value when it's being transformed. And some of the data can even be toxic, and you better not store it at all, rather than waste additional resources on handling it properly.
So I would argue that data is actually the new air, and by the way, I actually used my own photos, or being a hobby diver myself, I very well know the difference between having enough air to breathe and enjoy your underwater scenery, and having not enough air and gasping for it desperately, and in the worst case scenario, just expiring completely. And when organizations are in this situation, when they experience this data friction, that lack of air, lack of data to operate their daily business processes, they would abandon everything else.
They would bypass critical security controls, they would expose themselves to data breaches, compliance risks, and this is especially relevant for this whole generative AI craze, where you've probably seen it yourselves, are years of careful education by governments and by analysts like us, that you have to protect your data, you have to organize all the processes around it very carefully. They were all forgotten overnight, as soon as CHPT was released.
Now, what are the real business-oriented challenges about digital data? As you might probably observe, there is no word security on this slide. As I mentioned earlier, security goes away pretty early. The most important questions every business is asking themselves is, how do I make data earn money for me? How do I derive value from data?
And also, how do I fight data sprawl? How do I deal with tons of silos of structured and unstructured data across multiple clouds, multiple systems? How do I make sure that my workers can actually get the data quickly and efficiently? And how do I reduce the data friction? How do I make sure that every pipe the data, my data, is flowing through the business is big enough and there are no obstructions?
And of course, yes, there is always compliance, there is always there are always different aspects of confidentiality and availability, but a lot of companies do not realize that it's actually our job as IT security specialists to ensure those, you know, the notorious CIA principle, the triad of protecting your data, is still relevant and it's still our primary job. And of course, you have to understand that data does not exist in a vacuum. Data moves all the time. Data is being transformed.
And on this slide, I tried to illustrate just a small part of your usual data lifecycle flowing through different parts of your business, or maybe even your partner's business, or your cloud service provider's infrastructure, or an external generative AI provider.
The data is being moved around, it's being transformed, and there is a lot of technology involved at different stages of this flow, which sometimes we call data protection technologies, sometimes we call them identity and access management, sometimes we even call them like API security or data virtualization, which have actually actually very little to do with things traditionally associated with data protection. And yet, all of those technologies, all of those capabilities are equally important.
And if there is one takeaway I want you to have from this slide, is that it actually has nothing to do with looks more like a processing cycle for uranium ore, maybe. It is mind-bogglingly complicated, it is extremely expensive, and it is very easy to get something wrong and cause a catastrophe. And you are lucky if it's just a regulatory non-compliance, it could lead to a massive data breach, it could lead to a grinding halt of your critical business processes, and so on.
And of course, on top of all those technology challenges, we have to remember about people, stakeholders, your line of business people, your technology people, your ops people, and your security people. They all have their different interests, they speak different languages, they use their own tools, and those tools unfortunately do not work very well together because of lack of orchestration and automation.
And all this again leads to increasing friction, meaning your data, your precious hay in the cart stays at the same place no matter how many people are trying to pull this cart in different directions. So how do we deal with all this mess? Where are we even supposed to look for a solution which could somehow address all these challenges? Well I would argue we have to be looking for a data security platform.
Again, it might sound a little bit counterintuitive, but we should not consider data security like an obstacle. Instead, if we start thinking about it as a potential business enabler, as a foundation for making sure that your business processes that involve sensitive data are properly configured, automated, optimized, and maintained in real time, that's exactly what data security platforms essentially do, at least the good ones.
And at this point I would like to use the opportunity to promote a leadership compass, a market overview report I just published recently, which covers quite a few relevant solutions in this market, and I've listed a few key findings on this slide. We don't have to discuss them now, but feel free to ask questions about it. I just wanted to highlight that in our leadership compass we focused on eight different capabilities, like primary functional areas we believe an ideal data security platform should provide.
They cover a lot of different things from data protection in place, like encryption or masking, vulnerability assessment and attack prevention, meaning protecting your underlying infrastructure from hackers, monitoring and analytics, of course just knowing what's going on across all those infrastructures, discovery and classification, or you have to know what you're protecting, what you even have, what kinds of data, access management, obviously, this is probably the most important one because without having access to your data you cannot produce value from that, audited compliance, yes, you have to know what's going on, you have to keep auditors happy, and finally it has to provide you enough scalability and performance to scale with your data, to scale your business processes with your data.
But again, you don't have to always look for a jack-of-all-trades, you don't need a solution which can do everything. Today we are talking specifically about data governance, so you probably need a solution which is good at implementing options two, six and seven, ideally number eight as well. And this is exactly what we are actually talking about today because Immuta and their solution was also taking part in this report and I have a lot of interesting findings about the solution in that report.
I recommend you reading it after this webinar and the links are of course available, they will be included in the slide deck you will get tomorrow. Okay, where are we now?
Again, as I mentioned earlier, a data security platform is not usually understood as a business enabler and I would argue again that this is a wrong and a misleading point of view because a data security platform, when it's properly established and configured for your business, is a natural foundation for any kinds of additional business relevant and productivity enhancing services. And one of those services is a data marketplace.
Carsten will be explaining the concept in detail on his part, but basically a data marketplace is the way to package your data sources into business-oriented products. Instead of dealing with thousands of file shares and database tables and whatnot, you combine them in a logical, sensible, business relevant unit. For example, all the financial data in our German department for whatever kind of customers you have.
And whenever you have a business intelligence analyst or a finance guy or just a person creating an executive presentation for the next meeting, they would easily, hopefully with one click, get access to this package and then can use that data for whatever purposes they need and stay ensured that this data is safe or they only get as much as they are allowed to see. The sensitive parts are masked out and everything they are doing with data is properly monitored, audited, and recorded for later analytics. And another thing on top of that is, of course, automation and scalability.
Everyone is now talking about AI and co-pilots. I found this funny picture.
Yeah, not everyone is happy to work with a co-pilot, but an AI co-pilot can actually offer a lot of opportunities to make your work much easier. And, of course, it can vary from fairly simple and obvious things like using AI to classify your sensitive data more kind of semantically relevant for your business.
So it's not just secret versus top secret, but you can actually know that a specific document is related to a specific business department, a customer, a time period, and whatnot, and you will be able to not just find that data much easier, but you can apply fine-grained access policies to that information later. And, of course, if you can ask an AI to create a policy for you just by explaining what you want it to do, that is a huge improvement over current situations where you have to learn a simple policy.
Even better, if an AI can recommend you how to make your existing policy better by combining that collected intelligence from your data and just understanding it semantically, it would be able to give you recommendations how to make your policies faster, stronger, better, providing better coverage, and so on. And, of course, you can delegate some parts of your future decision-making to these solutions.
For example, whether a specific user should keep their access for the next year or whether they should be automatically revoked because they have not been using that data for a long time, and so on. So these are all the capabilities which I would be looking in a quote-unquote next generation data security platform, because even though you might not think that they have anything to do with security, they are, in fact, very relevant to all those capabilities I mentioned earlier.
And building on top of those strong access management, data protection, and auditing capabilities, you can expect a vendor to deliver you even more advanced and sophisticated productivity-enhancing capabilities in the future. And, by the way, if you want to know more about that specific solution in mutual data security platform, again, kind of a shameless plug, I just published a detailed review on the website. It's published today. The link is included in the slide deck. I can only recommend checking it out after the webinar. And with that, I think I am done with my part.
Karsten, the stage is yours. Please give us information about the solution. Many thanks, Alexey, for setting the scenes and talking a lot about data and data security. I will just go and share my screen that we can see. I have got some slides as well, but that's just to set the scenes, explain a little bit. And afterwards, we will see everything live in action.
So, bear with me if something goes wrong because it's a live demo. Yeah, I think it will work. It is very stable.
So, we're here to talk about a platform to put your data to work because especially this is what Alexey was mentioning and we want to do it safely and we do want to do it very quick. Therefore, I brought a little story to you.
So, that's all about the data access dilemma. Imagine you're working in a company as a data analyst here on the right side and your CEO is coming to you and asking something like, hey, Mike, I urgently need a report. Best till tomorrow. What's going on in your head?
So, of course, you're saying, Matt, I will create the reports as fast as possible. So, what's going on in your head? Imagine this. Maybe you're not sure where to find the correct data. Maybe you need a ticketing system to create a request for everything and you're not sure how to use it, how to phrase it, how to say, hey, I need access to that particular table and maybe another one, but I'm not sure.
And, yeah, the last point for sure, hoping that you get access in the next day to create the report that the CEO gets all the data he needs. And therefore, yeah, if it takes two weeks or longer, you might struggle with it. But why could it take so long? Because if you imagine a world, a legacy world like role-based access control is in place everywhere.
So, you assign groups to roles. And if you don't have the right group or role in place, you have to create it. And that might take time because you have a lot of dependencies like departments, IT department, creating groups in your identity and access management system. The data team is creating the roles and stuff like our data breaks or whatsoever data platform you're using. And then you have to combine it. And that might take time.
So, that's our story. But why are we talking about this at the moment?
So, we figured out that nearly everyone is now becoming a data consumer. So, in the past, there was maybe just a business analyst and the data scientists in the company. But for now, everyone else is also getting a data consumer because you want to get more profit out of your data.
And so, the product managers are dealing with the data as well as operations management, like HR departments or something like this. All are putting the data into data lake systems. And they need to consume the data. And that's the reason why we think that everyone is becoming a data consumer for now. Coming to the next point, which is the data marketplace.
So, Alexei was mentioning it. The data marketplace is a place where you give granular control to someone who could have access.
So, we're not talking about birthright accesses, which you're getting through default policies, through global policies or stuff like this. We're talking about someone who's requesting access because he could have access to particular data. How is this happening?
So, talking about the personas which are involved, we have on the left hand the data product owner. He's or she is the one who's hosting the, who's publishing data products and who's maybe in charge of the data.
So, she or he knows about the data and how to publish it. But first of all, what is a data product?
So, that's always the question I get. So, you're talking a lot about data products, but what is a data product? A data product can contain different things like tables, views, it can this is not hosted in just one platform. It is hosted on different platforms. It is hosted maybe by AWS and S3 buckets or it is hosted on Snowflake tables or Databricks tables whatsoever. And we combine it into one data product where the data consumer just easily can search for it and discover the data and sending out the request.
Hey, I need this data product because it contains everything what I need. I don't have to search a category system with all the tables in it and say, yeah, maybe I need this table and this table and this table and maybe I need this dashboard as well. I'm not sure, but I'm requesting much more than I need because then I'm pretty sure that my report will run. But that's not the least privileged concept behind it. It is the concept of getting as much as I can. And that's maybe not the best decision.
And therefore we have, of course, the data stewards and the data governors who are in charge of defining the approval process and also who are in charge of that we have a least privilege model in place. So, and we combine it in the data marketplace where you just easily can search for the data and request the access. But bringing it down to a little bit more what I just talked.
So, we have a lot of tools out there. Alexei was mentioning it as well.
So, we have our business applications. We have different identity and access management tools like an octal, like a ping, like a same point whatsoever you have out there. That's pretty good. They are doing identity and governance and you can request access to your platform, but you can't access the data.
So, therefore most identity governance systems are struggling because you have to deal with a lot of groups. You have to deal with a lot of roles and that's not scalable at all. And that's the difference between data governance and identity governance because the data governance is taking care of the data you are hosting and the access to the data. The identity governance is taking care of the access to the application itself, requesting the application. Can we combine it?
Yes, for sure. Then we have some discovery tools and cataloging tools as well. And if we break it down to our personas we are just discussing, we have got the data product owner. He or she is dealing with the catalogs and of course with all the data platforms you have in place. We have the data consumer who's working in the ticketing system to requesting everything. He or she is searching the data and the catalog.
The data steward who answers the request and then is going to the cataloging or marketplace tool whatsoever and is approving the request and afterwards the data consumer can access it and the data governor needs access to your data security platform to audit everything. Is everything set up correct? Who is accessing which data etc. And you need a lot of things. Everyone has not really access to one platform so we need to figure out how this works.
The key to success is just to ask to some critical questions and I will just go through them and ask them so that you have them in mind if you are looking for something like a provisioning, a data provisioning workflow. So first of all is have we exposed and cataloged the data sheets our analyst team requires. The next one is for sure can we easily handle exceptions to the policies. So if you have first right policies in place what about exceptions? Think about it. The next topic is can we process the volume of data requests in time or do we need a lot of time?
And the last one and very important one is do we know who is accessing what kind of data? When and why? And most important can we recertify that access easily? Because I know identity governance systems are strong in recertification. Are you doing it as well? Combining this we are coming back to our picture and imagine a world where you can just do this in one place. And this is where we come to our product which I'd love to show you right now in my demo. If you have any questions let me know. I'm happy to answer them as well if I'm demoing.
So I try to do it live so that you have the ability to just ask questions if something is unclear. I brought a little scenario with you to setting the scenes. So I have got a data analyst. Imagine Mike. He's trying to search and find data requesting access and he has to accept maybe a data usage agreement because this is something you might have in place in your environment as well. And on the other hand we have got a data owner. So the data owner is just approving the request after he or she thinks everything is okay. So before I go into my demo, we will have two different browser tabs.
The first browser tab which is this one, the blue one, will cover all stuff for the data analyst. The other tab is the right tab. The red one will cover everything what the data owner is doing. So let's go into our demo. And as you can see we are copying a code. So I am a data analyst as I described and I can see all my data products. I can use identity providers to log into my marketplace if I want. And the most important thing is I can see data and I can search for data.
So in this case imagine you want some credit assessment with some customer details and you want to search for it because I'm not sure where to find it. So maybe I search just for credit.
Wow, that's a lot. No, that's too much. So I want my customer data in it as well. So maybe there's some kind of data product and oh yes, look, this is what exactly our CEO was asking for. So I will click on this data product. I can see a little description and I can see my data sources in it. So I have different data sources assigned to it so I can see different technologies. In that case, some from Databricks, some from Snowflake. So support of multiple environments like hybrid clouds, like whatsoever, multi-cloud environments are supported as well.
And as you can see, I have some tables where I have already access to. So these are my bus ride access policies which are covering this and I can see, oh, I have currently access. So I just need access to that one because this is approved if I just request the access. And then there's another one which is access prevented. So even if I request access to this data product, that one will be prevented. Now the question is why?
Yeah, because of my bus ride policies, for sure. But they can, for example, contain something like you've not done your GDPR training right now. This is the reason why you can't access this data. At the moment, we can't show it right here. We are working on it to give the user an overview why this is happening, but the governor will see it why this happens.
So yeah, well, that's exactly what I want to have. So let's just quickly request the access. So that's a nice one because I can request access for myself or in behalf of someone else. But why do I need this?
Yeah, so imagine a world where Alexei was talking about Gen AI and machine learning, etc. And therefore, you need a lot of agents and machines and systems. So service principles, for example, where they need access as well.
For sure, we can work with birthright access policies there as well. But maybe sometimes you want to assign more than just the birthright policies to the service principles. And therefore, you can just easily go to the marketplace and request it for someone on behalf. So for non-human identities, for example. I just quickly type in a reason why I need access. So Mike was asking for the report, so I just type it in. But I can't request it.
Yes, that's because I have got a data usage agreement, which I can just open right here. And this is customizable. We bring some with us, but every customer has their own things. But sometimes the default is enough. And for sure, I've read this whole document, and I agree on the terms and conditions and submit my request. That's it.
And now, what's going on? So I can see the request is pending for this. And as well, if I click over here, I can see all my pending requests at the moment. So I'm not lost. I can exactly see what I'm requesting, which data product, and what is my status. So if I just clean out the pending, you will see that we have some approved earlier this date for another data product. That's the one hand. And on the other hand, we have got the data owner. So the one who owns the data, who's responsible for the data. And this is what we're going to see in the next step. So you will see exactly the same.
This makes it really good for the look and feel for everyone. And here we have got, if we go to the access requests, a lot of pending requests. So some from my colleagues, some from me, and that one from the data analyst as well. So I just click on that one and go to the access request. There we go. So the question is, oh, I need to approve that. That's it. My work is done. So that was exactly what the data owner was doing. And his work is nearly done. So we just will figure out what's going on with my request. And let's see. So I will just quickly refresh that one.
And that user knows exactly that one is approved. I go back to my data product. And what I can see right now, customer. Now the access status changed to currently access out of the one where the access is prevented due to password policies. Any questions?
We have, in fact, a question from the audience now, but it's a little bit kind of different from the current focus. Would you still respond to it now? Because it's asking how do you create new data products and whether it's possible to automate it, for example, through an API? Yeah. So that's a little bit out of scope, but no worries. I can just cover it. So coming back to our data owner and who's in charge of all the data products. And for sure, we have got one little button over here where we just easily can create a new data product. So we put it into a domain like finance.
It is an easy click through. So everything what is in our finance can be just used over here like this one. And I can as well switch for my data sources because if I have more than just maybe nine or something in it, then you might want to switch for data tables. And then it's also straightforward. Just type in a name like test. Enter a description. Subject meta expert is someone who is responsible for the data. And just in case it is not the data owner, it might be someone else.
Then you can just say, hey, if you have any questions about this data product, please ask that guy and you will have an email address to ask him. And then we can just see what is the request policy. So do we need an approval for this or is it just publicly available data? Then we can just go to no and everyone can assign just the data to themself. And do we need a data usage agreement? Yes or no. And afterwards, just click on publish and we're done. So it's pretty easy and simple to create. But if you're talking about a lot of data products because you have seen a lot of data products in here.
So we have got 42 right now in a production environment might get up to 1000 or more. And therefore we provide an API. So we can automate this as well so that this works at scale. And by the way, as you were defining a product, you never actually had to specify an S3 bucket or a database table because you were dealing with logical things already. Where do those come from? I would imagine the platform was able to find and discover them automatically, right? So now we are going really a little bit more deeper, but no problem at all. We define everything in our underlying platform.
So there we have some native connections to the data lakes, data warehouses, et cetera. So to AWS Redshift, to Lake Formation, Snowflake, Google BigQuery, you name it. And so there we define everything. We put everything into domains and then you can just read it in clear text so that it is really easy for data owner to understand how to create and publish a data product. Because most of the data owners don't understand all the languages which are used in the different systems. All right. I think it kind of goes and resonates a lot with what I have said in my part earlier.
Like imagine if you were only building a data marketplace, but you never had a data security platform before. How much extra work you would have to do just to support all those capabilities? Since you already have the foundation, all the business relevant things on top come naturally. You just have to come up with a great business idea and you can build it because you have all the capabilities already in place.
I think it indicates very well that kind of data security platform and their concept are the things you should not ignore because it enables you to do things you were simply unable to do without it. Yeah. Okay. Awesome. I think we have a next question from the audience already. Can you explain what are birthright policies anyway and how do you configure them? Yeah. So I talked a lot about birthright policies and this is the underlying platform. So there we can define global policies.
We can define fine grained access like masking, like row level filtering so that you can just see data which is belonging to your country or for countries you're responsible for. Or if you maybe want to clean out every PII and PCI data for everyone who has not done any training. And these birthright policies are hosted in the underlying platform. And with our data marketplace, there is not a must. You can use this. You can use your existing policies and just do the exceptions with our marketplace. Or you can do both. Or you can do just the birthright.
So it's split into separate parts, but the birthright policies are living in the underlying system. And yeah. Is it by the way where the AI copilot comes to a system?
Yes, exactly. I will cover this in around 10 minutes, I guess. Okay. Let's continue. And let's continue. So I'm going back to my slides. The outcomes. So it's much faster. You've seen it. I've not accessed any ticketing system or something like this. It was easy to just search the data. It was really good. And it reduced the effort by just using one single platform. So I'm just in one tool, see everything what I want and was just clicking through it and the work is done. Going back to Mike and Matt. So he's now really happy. It was pretty easy and he made it in time.
So talking about non-human identities. So I covered it a little bit in my demo, but we have also AI in place. So you were just mentioning our immediate copilot. We have a little bit more in place which is coming, which is already there. So we have also a data discovery. We have policy recommendations. So for example, if we are talking about our birthright policies, because it was just a question, we have recommendations like, hey, you've already something similar in place. Like you mentioned the policy about GDPR trainings.
So if you've not done your GDPR training, you are not able to see any PII or PCI data. And the next data owner thinks, I need a policy because we have these awesome security awareness training. And if you've not done this, we will not show you PII data. And our platform will just do recommendations like, hey, there's a similar policy. And if you just add the attribute to this policy, it will match. So maybe this is a good idea to not create a new policy.
Otherwise, just create that, just edit that existing policy. It makes more sense. Talking about these policies, Immuta has one thing in birthright policies, which is pretty awesome because it's all done in native language. So in plain language, it's understandable. The policies are readable. There's no SQL code in it, what you have to learn, et cetera. So everything, single data governor could easily create policies. And then we have also our Immuta co-pilot. And for sure, we talked about the recertification.
So, yeah, why not do this with a kind of intelligence? And exactly this belongs to all identities we are accessing. So even if these are non-human identities like service principles, or if these are data consumers like everyone in the company, we will address it by birthright policies and data marketplace where you can just easily set up the workflow to request access for someone else. But the question about co-pilot is how does it look like? And I just brought a picture. So this is our easy policy builder. And now we've got our co-pilot, which helps you just to create policies.
So you can just type in, hey, I want a policy doing this, and you get a policy recommendation. Then you can think about the policy and say, yeah, that's exactly what I want. Or maybe I need to just do some adjustments. And by the way, Carsten, you mentioned earlier that you can do it in a natural language, but does it imply English only, or can we do it like in German, for example? At the moment, only English. Okay. Sorry for that.
But yeah, as you can see on the screenshot, you can use a plain language. If you want to do something more advanced, you can also do advanced stuff. But in normal cases, most of our customers are using plain language. And that's it from my side. Okay. We still have time left for questions. Let's just kind of switch back to my slides, because I have a couple of things to show, too. And in the meantime, please keep those questions coming. We still have time. Right. So before we continue, just another quick shameless plug.
Kupin and I will have our flagship event in about a month, where we will be discussing a lot of the topics similar to this. If you are around Berlin, or just kind of in Europe, or even willing to travel slightly longer to see our team and to talk to the best experts in all these fields, you are very welcome. I hope to see at least some of our attendees maybe later in person in Berlin. And we already have the next question. And I guess it kind of, again, goes back to the question of scalability. Can you support multiple business units?
I imagine, like, if you are deploying the solution in a really large international company with probably, like, tons of mergers and acquisitions in history, can you actually separate them logically and manage them in different business units? Yeah. So when it comes to business units, I recommend the use of domains, which I quickly showed during the data products. So we have the concept of domains supported in Yuta as well.
So you can just create a domain which contains all the finance data for, or your HR data, or even if it contains a whole new acquisition, like a company or something like this, you can create a domain for that. And then you can easily check your existing tables, new tables. And by filtering the text, you can easily just bring them by rules to the domain so that the data tables automatically will be published in that domain. So this works as well at scale. Can you still define global policies across different domains?
Yes, we can. Okay, that's great. That's how you deal with scalability issues, right? You just give the customer the opportunity to design it the way they want.
Okay, awesome. I have another coming question in the chat.
Okay, so the question basically was, imagine you already have a data product, but somehow the consumer isn't happy, something's missing, something's not right. Is there a way to modify, upgrade, expand an existing product, or how do you deal with those situations?
Well, that's pretty easy. You can just click on edit and add more to your data product. You can change the data usage agreement, or if you need it later, you can just edit that one as well so that you now need one or just remove it because it's obsolete. Or you want to just add more tables or less tables because we know data is always moving. Data is alive. And therefore, we need something which is configurable and that you can edit existing data products.
For sure, as well, if you have in your CICD pipeline, you can use APIs for that as well. So everything is possible. Can you somehow automate this internally, or does it rely on external signals to do it, that the data has changed? Or maybe you can just explain a little bit how the discovery classification process works. Is it like a one-time process? Does it repeat on a schedule? Does it influence the product?
Yes, yes, and no. So it's depending on where the classification happens. So we can integrate with existing cataloging tools to import the metadata, and we can do it on our own.
Therefore, we can set up a schedule, and the schedule can be done more twice a day, three times a day, whatsoever, and then we get all the updates. Does this make sense?
And then, basically, a data owner can create a new product or an existing one. Okay, okay. So other than the UI and the API, are there any other ways to interact with the platform?
Like, do you offer some third-party integrations with other security tools, or do you plug into existing cloud service providers' infrastructures? We have a lot of native integrations to cataloging SIAM identity and access management systems, and, of course, all the underlying data platforms, snowflake, Databricks, etc.
And, for sure, we can also work with webhooks, etc. And if needed, we can also integrate with an existing ticketing system. So if you have a gyro in place, we use a lot of deep links in our data marketplace and use these deep links into your existing environment, and so we can integrate with that as well. And we have out-of-the-box integrations, AndroID and Okta.
Okay, sounds good to me. Right, we still have a couple minutes left and no further questions so far, so last opportunity for our audience to ask one. In the meantime, let me kind of remind you that we have some related research published at Copenhagen Call. Leadership Compass covers a lot of vendors in this space, including Immuta, and, of course, we have a report focusing specifically on the solutions. If you want to know more about the capabilities, feel free to check our website. The links will be in the slide deck, and the slide deck you will get tomorrow.
And there are always some related other publications and webinars as well. If we do not have any questions and we don't, Karsten, any closing words from your side? Thanks a lot for your time. If you want, reach out to us and we are happy to schedule a demo appointment with you. Absolutely, and, of course, the same applies to me. If you have any questions to Cognitive Core Analysts, feel free to contact us as well. And with that, thank you very much for all the live attendees and all the future people watching this as a recording. Thank you for being with us.
Hope to see you in another upcoming webinar or, as I said, personally this May in Berlin, Germany, at the EIC conference. And have a nice day. Goodbye. Goodbye.
See All Locations
See All Locations