Skip to content

Halcyon

Health data

Row-level permissions that hold outside the warehouse

A regulated dataset meant most people could not be given a query tool at all. Permissions now carry through to every answer.

0

permission exceptions written

SOC 2

Type II, reviewed annually

Stack

BigQuery, Looker, Jira, Notion

The problem

Halcyon’s clinical data carries row-level restrictions. Any tool that kept its own copy of permissions was a second thing that could be wrong, so most teams simply had no access.

What changed

Sable runs every query under the asking person’s identity, so the policies already enforced in BigQuery apply without a second configuration.

Where they are now

No bespoke permission rules were written for Sable. Access reviews cover one system instead of two.

Security signed off in one meeting. The answer to every question was that our own policies apply.

Ruth Abeyta, CISO, Halcyon

Create a free website with Framer, the website builder loved by startups, designers and agencies.