Skip to main content

Product Ideas Pipeline

1170 Ideas

Enhanced Access Management for PI ExtractorGathering Interest

Though many companies are pretty liberal with read access on tags within a PI Data Archive, some out there need to control access at a more granular level. (Often driven by the need to protect intellectual property.) Only certain groups of users should be able to see data for certain tags.In our case, we would like our access model with respect to PI data in CDF to mimic what’s in PI. In a PI Data Archive, this is governed by the datasecurity metadata field. Unfortunately, the PI extractor seems to strip off this metadata on ingestion. Without that, we’re looking at a workaround solution in which we maintain this mapping in CDF and use something like a Cognite function to apply a security category that mimics the PI tag’s data access. However, this does come with some headaches:We’ll have to maintain a separate mapping of PI tags to the right level of access (that would otherwise be present in that datasecurity metadata field). The PI tag data can’t be secured before that security category is applied.I provide all this background information in the hopes that it’s useful for developing features that are useful for this need. But if I had to make a concrete ask:Provide an option for the PI extractor to not strip off “internal bookkeeping attributes in PI” from incoming PI tags. Provide a means to apply a security category during the extraction process, itself. (Similar to how the file extractor does.)Thank you for your attention and looking forward to discussing more!