Row-level security, granular access, SSO, and a complete audit trail — so sensitive mappings are seen and changed only by the right people, and every action is provable.
Derive each user's access from a control registry — by division, location, or any column. One dataset, scoped per person.
One view of who can access which project, gridmap, and registry — and whether it's direct or inherited.
Point gridmap at a control registry — a table of users and the values they're allowed to see — and each person's row access is derived automatically, by division, location, or any column. Sync it from your data warehouse on a schedule and access stays current as your team changes. One dataset, scoped per person, instead of duplicate "filtered" copies.
With shared drives and folders, it is hard to limit who sees finance codes, customer segments, and pricing rules.
Knowing who changed reference data, when, and what the previous value was can be difficult — especially during audits.
Granting and revoking access through folders is time-consuming and hard to keep consistent as teams change.
Database connection details are sensitive. A dedicated platform stores them encrypted and manages access centrally.
Users only see the rows they are authorized for — enforced at the database level, not by spreadsheet tabs.
Import your access table from Snowflake, SQL Server, or Fabric. Permissions update when the source changes.
Organize users into groups with defined permissions. Add or remove a user once and it applies everywhere.
Who accessed what, who changed which value, who granted access. Exportable, searchable, always available.
Credentials are encrypted at rest with Fernet. Connections use TLS — no plaintext secrets, ever.
Single sign-on with Microsoft Entra ID or Google Workspace. MFA enforced at the tenant level.
Row-level security means each user only sees the rows in a registry that they are authorized to see — even when multiple teams share the same registry. For example, the finance team sees cost center codes while operations sees product codes. Access is enforced at the data level, not by creating separate files or spreadsheet tabs. It works automatically once configured.
gridmap uses role-based access control with user groups. You assign users to groups (e.g., "Finance editors", "Operations viewers") and set permissions at the project, registry, or row level. Changes take effect immediately. You can also import permissions automatically from your data warehouse user tables.
The audit log records every action in the platform: who viewed what, who changed which value, who granted or revoked access, and when. Every row change includes the previous value and the new value. The log is searchable, filterable, and exportable for compliance reviews.
All database connection credentials are encrypted at rest using Fernet symmetric encryption. Connections use TLS. No plaintext secrets are stored or logged anywhere in the platform.
Yes. gridmap integrates with Microsoft Entra ID and Google Workspace for single sign-on. Domain-based auto-provisioning means new users from your organization are automatically onboarded. Multi-factor authentication is enforced at the tenant level. No shared passwords.
You connect gridmap to any supported database and point it at a table with email and permission columns. gridmap reads that table and applies row-level security automatically — users with multiple rows get access to all their permitted values. Sync permissions on a schedule so access stays current as your team changes.
gridmap stores data in EU-based infrastructure (Sweden Central on Azure). All data at rest is encrypted. Access is logged and auditable. Row-level security ensures data is only accessible to authorized users. For specific compliance requirements, contact us for details on our data processing agreements.
Join the early access list — we'll reach out as spots open.
See pricing →