Access Control

Honeydew enforces governance through your warehouse - not around it.

Every query, whether from BI or AI, is compiled with your existing access rules, identities, and data policies built in.

Governance by Design

Domains in Honeydew are scoped layers of governance that define who sees what and how.

They combine semantic logic with access policies - applying security, filters, and overrides before any query is compiled.

Governance by design illustration a domain bundling security

Built on Your Data Cloud

Honeydew doesn’t reinvent access control - it compiles into it.

Your warehouse is the execution environment and the enforcement point for RLS policies and access roles. Honeydew ensures every query respects those controls automatically.

Built on your data cloud illustration showing warehouse nati

User identity propagation

Honeydew connects directly to your identity provider for unified authentication and authorization.

When an authenticated user runs a query - through a dashboard, an API endpoint, or an MCP interface - Honeydew compiles it using their data warehouse identity, propagating their identity end-to-end.

User identity propagation diagram across data and bi tools

Your infrastructure, your security

All processing done by Honeydew is on your premises: in your cloud data warehouse, using your LLM provider, your Git provider and your authentication provider.

Your infrastructure your security illustration data stays in
Soc 2 type ii certified badge

Honeydew's commitment to security

At Honeydew, we prioritize security from the start to ensure that your data is always protected. Honeydew is SOC 2 Type II compliant. We maintain industry-leading privacy standards, technology, and practices.