Not defending people accessing PII, but just saying there are legitimate reasons why someone could have access.
Not defending people accessing PII, but just saying there are legitimate reasons why someone could have access.
See the docs -> https://docs.aws.amazon.com/redshift/latest/dg/r_GRANT.html
Perhaps some people have legitimate reasons to access some sensitive info, perhaps not. But not _everyone_ needs that access anyways.
Anyone who can access that database can _probably_ deploy code too. If you can deploy code, you can sneak in whatever you want.
The reality is that some people are going to need wide-reaching access. You could monitor for certain problematic access patterns, like someone who is supposed to be doing primarily aggregate queries doing a lot of specific ones, and I'm sure that'd be a good thing to do, but to be honest there are probably much higher priorities since employees who need sensitive access are probably going to be able to avoid that type of detection.
Read access to production data is only necessary in very few cases and can be heavily audited.