Database Activity Monitoring
SL-10Continuous, near real-time visibility into every query against a personal-data table — who ran it, from where, with what tool, and which classified columns it touched. Tamper-resistant, with administrative segregation so nobody can both configure monitoring and erase its output.
1 detection escalated to Breach Response
DAM-2026-1204 — Mass read / table dump on familyid-prod-01. 1.48 L rows across 6 classified columns.
Databases monitored
15
ViewNot fully monitoring
3
Classified columns
1.61 K
Children's data columns
359
Open detections
24
Critical
6
Query volume and flags
56.6 L queries observed today across 12 monitored instances.
Database engines
Coverage across the estate.
- PostgreSQL5
- Oracle3
- Microsoft SQL Server2
- MySQL2
- Snowflake1
- Databricks1
- MongoDB1
Detection types
Mass reads and export anomalies dominate, which is what you would expect if the control is working.
Highest-risk databases
Ranked by classified column count and open alerts.
- Criticalfamilyid-prod-01Oracle38 child cols214columns
- Criticalfamilyid-dr-oracleOracle38 child cols214columns
- Criticalanalytics-lakehouseDatabricks52 child cols203columns
- Highbeneficiary-warehouseSnowflake41 child cols187columns
- Criticalhealthcard-mysqlMySQL34 child cols112columns
- Highportal-prod-pgPostgreSQL12 child cols96columns
Active policies
Granularity down to the column, with sensitivity-based logging fidelity — full capture on personal-data tables, standard elsewhere.
- Mass read on citizen identifier tablestablecitizen.beneficiary, citizen.householdBaseline-driventerminate session6Active
- Any access to children's data columnscolumnwelfare.enrolment.student_name, student_dob, guardian_contactBreak-glass activealert41Active
- Privilege change on classified objectsinstanceAll production instancesalert14Active
- Service account outside its windowusersvc_* accountsBaseline-drivenblock user3Active
- Export to file from any classified tableschemacitizen.*, health.*, welfare.*quarantine9Active
- Attempt to disable auditinginstanceAll instancesalert2Active
3 databases are not fully monitored
analytics-lakehouse (degraded), forms-mongo (onboarding), familyid-dr-oracle (paused). Note that the DR replica of the Family ID registry is paused — it holds the same 214 classified columns as production and would be equally reportable if compromised.
Related
Monitored databasesEvery instance, its collection mode, overhead and tamper-protection status.Activity explorerThe query stream with full session context — statement, source host, client tool and affected objects.Identity resolutionWhich human is behind each service account, and how confident that mapping is.Audit reportsUser-centric, object-centric, privileged-user and change-tracking reports for an inquiry.