LDAP + local users
Use centralized identity with LDAP while preserving local accounts for platform administration and break-glass access.
DBAegis provides edition-controlled access, encrypted stored secrets, restore authorization, and audit-ready recovery workflows in a self-hosted deployment.

Use centralized identity with LDAP while preserving local accounts for platform administration and break-glass access.
Role-based access control separates admin and read-only responsibilities and supports group mapping for cleaner governance.
Terminate the DBAegis web interface behind HTTPS and use verified TLS for database and LDAP connections where supported by the target tools.
Connection passwords and sensitive credentials are stored encrypted, with secret-key rotation called out as a security practice.
Enterprise webhook delivery validates destinations, restricts unsafe targets, protects sensitive headers, and records delivery outcomes.
Password re-authorization, restore reason capture, dry runs, and typed confirmation help prevent accidental or unauthorized restores.
Capture who initiated restore, which artifact was used, what target was selected, when the action occurred, and why the restore was needed.
System snapshots protect DBAegis metadata and configuration so the control plane itself can be recovered after server or deployment issues.
Use the product security policy for private vulnerability reports. For production evaluations, review identity, TLS termination, database credentials, restore authorization, webhook destinations, audit evidence, backup encryption, and control-plane recovery against your environment.