Ketch and CockroachDB

Discover not just which tables hold personal data, but how they relate to each other, in a distributed SQL database built for resilience across regions.

CockroachDB

About CockroachDB

CockroachDB runs distributed, horizontally scalable SQL workloads, often for applications that need resilience across regions. Discovery here goes beyond tables and columns: it maps constraints and relationships between tables too, which matters because personal data is often reachable through a foreign key relationship even when it isn't in the table a request first lands on.

Ketch connects to CockroachDB through a Ketch Transponder to support both discovery and, where authorized, direct execution.

Capabilities

How Ketch works with CockroachDB

The Ketch CockroachDB integration covers Discovery and Rights Orchestration for both Right to Access and Right to Delete.

Discovery

Scans databases, schemas, tables, columns, and, distinctively, constraints and relationships between tables.

Rights Orchestration

Requires `UPDATE` and `DELETE` access granted on top of read access, scoped to specific tables within a schema, with default privilege configuration available so newly created tables inherit correct access automatically.

With Ketch, teams can

  • Discover not just which tables hold personal data, but how tables relate to each other through constraints and foreign keys
  • Grant rights-execution privileges separately from Discovery, deciding independently whether and when to authorize direct deletion and update
  • Rely on default privilege configuration so future tables in a schema inherit the correct Ketch access automatically

The gap

The problem this integration solves

A distributed SQL database still needs personal data actually located and reachable, and relationships between tables matter as much as the tables themselves:

01. Discovery that only maps columns, without relationships, can miss that personal data is reachable through a related table even when a specific table looks clean on its own

02. Without default privilege configuration, newly created tables can silently fall outside the Ketch service account's granted access

03. Fulfilling a deletion request against a database has historically meant a manually written query, slow and hard to prove complete

Ketch resolves the first by mapping constraints and relationships as part of discovery, not just columns, and the second by supporting default privilege grants so new tables inherit correct access without a manual step.

Why Ketch

Why teams choose Ketch for CockroachDB privacy compliance

Permissioning infrastructure that governs CockroachDB the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Maps relationships, not just columns

    Discovery includes constraints and relationships between tables, surfacing where personal data is reachable through a related table, not just a table's own fields.

  • Default privileges keep new tables covered

    Configuring default grants at the schema level means newly created tables inherit correct Ketch access automatically.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a database holds.

Questions about the CockroachDB integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See CockroachDB permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect CockroachDB yourself.

Get Started Free

Get started in less than 5 min