CHOps Pro - SSO and Audit

Single sign-on and audit logging for the ClickHouse® database

Regulated and enterprise teams need to know who did what, and to gate access behind their identity provider. CHOps Pro adds single sign-on and a tamper-evident audit log on top of the open-source core, so every action on your ClickHouse® database clusters is authenticated and accountable.

Single sign-on (SSO)

Route CHOps login through your existing identity provider instead of local passwords. Users authenticate with your organization's SSO, so access follows your central joiner and leaver process. Revoke a user once, in one place, and their CHOps access to every ClickHouse® cluster is gone.

Tamper-evident audit log

Every DDL, DML, and login event is recorded in an audit trail with 50 or more action types. The log is searchable by user, action, and time, so you can answer who changed a grant, who ran a destructive statement, and when a node was restarted, long after the fact.

Export for compliance

Export the audit trail as a verified PDF for auditors and compliance reviews. Retention policies keep the record for as long as your regulatory requirements demand, without you managing log files by hand.

Built on the open-source core

SSO and audit logging layer onto everything in the free Community edition. The SQL editor, monitoring, RBAC, backups, and dashboards work exactly the same. Pro adds the enterprise controls without changing how your team works day to day.

Who it's for

Enterprises and regulated industries running the ClickHouse® database. Security and compliance teams that need identity-based access and a defensible audit trail. Organizations standardizing access behind a single sign-on provider.