Keymate's native OpenMetadata integration enables catalog-aware authorization, DSAC classification enforcement, and seamless visibility across your data & IAM layers.
Metadata-Driven Authorization with Classification-Aware Policies
Enterprise IAM systems often lack visibility into data context. But access control without understanding data classification (like PII, Confidential, or Public) is incomplete.
With Keymate's OpenMetadata integration:
Key Components:
OpenMetadata holds data tags, domains, classifications. Keymate syncs metadata events into its internal DSAC tagging engine. Tags are mapped into the policy engine and/or token claims. Policies like "deny if tag == restricted and user.clearance != high" become possible. Any change in metadata is streamed and enforced live.
Use cases include:
Key Components:
Continuously sync tags and classifications via OpenMetadata events
Apply data sensitivity rules using metadata tags like "PII" or "Restricted"
Tags and domains are accessible in Keymate's DSL or OpenFGA models
Classification context is injected into access tokens
OpenTelemetry-powered visibility across tag ingestion and decision paths