Skip to main content

Encrypt Data for Developer, while Enabling Business to view Confidential/Sensitive Data

when working with sensitive and confidential data, there are situations where the customer may not be fully aligned to share their data even to the developers. In which case, it would be a better to have a configuration that would restrict the developer to view the actual data and make them see only the encrypted data, while when the same report viewed by business user would enable them to view the actual data instead of encrypted data. May be this could be something that can be linked to the User Account with some kind of security enabled only for the specific acount authorization to view the data. Additionally, this could only be an option configurable only when really required.

Status: Future Consideration1 comment

Log in to comment and vote

Comments1

  • John Munkberg

    Team•

    Aug 4, 2025

    Because the data is extracted as clear text, and loaded as clear text, the developer will have access to the data. Developers also need access to perform the PostLoad validation.

    Visibility in the UI is controlled via the Security settings on the Migrate reports, which is available today. Depending on the use case, it’s possible to have one version of a report without the sensitive data, or with Masked Data, and one version which exposes the data, but whitelisted only for the authorized users.

    As we continue to enhance the EXTRACT and LOAD tooling, and eliminate direct SQL access to the database, this will become a more seamless process in which we could implement this request because we would programmatically control the access to the Data via the UI and SKP APIs.