TRAILOX FOR BIGQUERY

Connect principals to the jobs and tables they touch

Connect principals and applications to jobs, datasets, tables, and query activity. Detect behavioral changes and investigate historical activity across every project.

Trailox BigQuery access overview

Native telemetry used

Trailox reads Google Cloud Audit Logs (Data Access logs) and INFORMATION_SCHEMA.JOBS, which together capture every query job run against your BigQuery datasets.

What access Trailox can see

Every query job, the datasets, tables, and columns it referenced, bytes processed, and job status.

Identity and application attribution

Trailox resolves every job to the IAM principal that ran it, a user or service account, and to the calling application where identifiable, the console, the API, a client library, or a BI tool.

Trailox BigQuery identities, resolved to principal

Behavioral detections for BigQuery

  • A principal accessing a dataset or table for the first time
  • Query jobs processing an unusually large number of bytes
  • New service account activity against production datasets
  • Query activity outside a principal's established pattern
  • Sudden expansion into new datasets or projects

Investigation capabilities

Search historical job activity by principal, dataset, or table, and reconstruct a table's complete access history over time.

How Trailox connects

A read-only IAM role with access to Cloud Audit Logs and BigQuery job metadata. No datasets or jobs are modified.

Start with proof,
not a pitch.

Scoped read-only role, 30-day lookback, results in 48 hours.