Ketch and Oracle Database

Run discovery and rights fulfillment through a separation-of-duties model, with a Transponder image built specifically to speak Oracle's own client protocol.

Oracle DB

About Oracle Database

Oracle Database often anchors some of the largest, longest-running systems in an enterprise, with schemas and access patterns that have accumulated over years. Connecting to it also requires the Oracle Instant Client, a real technical dependency most generic database tools don't ship with by default.

Ketch's Oracle integration accounts for both the access-control side and this specific technical dependency.

Capabilities

How Ketch works with Oracle Database

The Ketch Oracle integration covers Discovery and Rights Orchestration for both Right to Access and Right to Delete.Two things set Oracle's setup apart from Ketch's other database integrations. First, Oracle connections require a dedicated Transponder container image, `transponder-oracle`, which bundles the Oracle Instant Client; the standard Transponder image doesn't include it. Second, rather than a single service account, Oracle uses a two-user model: a Ketch Provisioner, created directly by the DBA, holds the privileges needed to create and manage a separate Ketch User, including granting that user read, update, or delete access on specific tables. The Ketch User is the one that actually runs

Discovery

Scans information schema and column-level metadata using read-only `SELECT` access. Fulfills rights requests. This separation of duties means the account capable of granting access isn't the same account actually using it.

Rights Orchestration

Requires `UPDATE` and `DELETE` access granted on top of that.

With Ketch, teams can

  • Run Discovery and rights fulfillment through a Provisioner/User model that matches Oracle's own separation-of-duties conventions
  • Choose exactly which grants (`SELECT`, `UPDATE`, `DELETE`) the Ketch User receives, matching precisely what discovery versus execution actually requires
  • Connect using a Transponder image purpose-built with the Oracle Instant Client already included, rather than assembling that dependency separately

The gap

The problem this integration solves

A long-lived enterprise Oracle instance creates real governance and technical challenges that a generic approach doesn't handle well:

01. A single account holding both the ability to grant access and the ability to use that access blurs a separation of duties many Oracle shops already practice elsewhere

02. The Oracle Instant Client is a real prerequisite for connecting to Oracle at all, and a generic database tool that doesn't ship with it creates avoidable setup friction

03. Manually assembling the correct roles, grants, and client libraries for a new privacy integration introduces real setup risk

Ketch resolves the first with a genuine two-tier role model, and the second by shipping a dedicated container image with the Oracle Instant Client already built in.

Why Ketch

Why teams choose Ketch for Oracle Database privacy compliance

Permissioning infrastructure that governs Oracle Database the same way it governs every other system in your stack — not a one-off connector bolted onto a banner.

  • Separation of duties, not a single broad account

    The Provisioner grants access; the User runs Discovery and rights execution. Neither role does both jobs.

  • Built for Oracle's actual connection requirements

    A dedicated Transponder image bundles the Oracle Instant Client, rather than requiring that dependency to be assembled separately.

  • Backed by enforcement precedent

    Regulators increasingly expect businesses to prove technical enforcement, not just describe it on paper, the same underlying expectation that applies to knowing what personal data a database holds and controlling exactly what's in scope.

Questions about the Oracle Database integration

Integrations

Pre-built APIs with 1,000+ systems, apps, and models

Ketch ships connectors and SDKs so consent, rights, and policy flow into your CDPs, warehouses, ad platforms, and AI stack — without a custom data pipeline.

Browse All Integrations

See Oracle Database permissioning running end to end

Book a demo to walk through rights, consent, and preference orchestration on your stack — or start free and connect Oracle Database yourself.

Get Started Free

Get started in less than 5 min