This article helps you:
Easily prevent users from accessing sensitive or restricted information in Amplitude
Enterprise-level organizations often collect data that can include revenue data, personally identifiable information (PII), and other sensitive information. Amplitude’s data access control (DAC) feature enables these organizations to easily manage access to these categories of data, in a way that prevents unauthorized users from gaining access to it, and that helps prevent the data from inadvertently leaking out.
DAC works within Amplitude’s Groups framework. Admins grant or restrict access to PII, revenue data, and sensitive information to all members of a group. From there, they can add or remove users from these groups as access requirements change, either on an individual or organizational level.
For example, when an unauthorized user tries to view a chart that includes restricted information, Amplitude blocks the chart from loading on the user’s screen. Those users are also unable to create new charts that might include restricted data. This is true not only for charts, but also for cohorts, dashboards, notebooks, and user sessions.
Organization admins always have access to all data classifications, regardless of any DAC restrictions.
When a user encounters a chart they’re unable to view because of the presence of restricted data, Amplitude specifies the properties or cohorts DAC has blocked.
The user can then exclude the restricted data and view the chart (or cohort, dashboard, notebook, or user session) without it.
Setting access levels is a two-stage process. First, classify your data. When that’s complete, you can set up permissions.
DAC applies only to properties. It doesn’t apply to definitions or metadata.
Thanks for your feedback!
September 12th, 2024
Need help? Contact Support
Visit Amplitude.com
Have a look at the Amplitude Blog
Learn more at Amplitude Academy
© 2024 Amplitude, Inc. All rights reserved. Amplitude is a registered trademark of Amplitude, Inc.