Okera Data Access Governance
Okera is a data access and governance platform acquired by Databricks in May 2023 that provides fine-grained authorization and compliance control across hybrid and multi-cloud data environments.
Publisher review
Okera is a data access and governance platform acquired by Databricks in May 2023 that provides fine-grained authorization and compliance control across hybrid and multi-cloud data environments. Founded in 2016 by engineers who previously worked on Apache Parquet, the San Francisco-based company built a unified platform to solve the access-control fragmentation created by modern analytics stacks: a single policy engine that dynamically enforces row-level, column-level, and cell-level permissions across Snowflake, Databricks, Amazon EMR, and cloud object storage without rewriting rules for each tool. The platform targets enterprises managing large-scale sensitive data—financial services, healthcare, retail—where regulatory pressure (GDPR, CCPA) meets the operational friction of managing access across dozens of data systems.
Okera's no-code policy interface lets data stewards author rules without SQL, then audits every access request. The acquisition by Databricks signals consolidation in the data governance space, with Okera's capabilities being integrated into Databricks' Unity Catalog. As a Databricks subsidiary product, Okera faces pressure from both open-source alternatives (Apache Ranger, Delta Lake native governance) and established competitors like Immuta, Privitar, and Altr, which offer overlapping policy-based access control at the data lake level. The key trade-off: Okera excels at cross-platform consistency for hybrid environments, but now carries Databricks' ecosystem lock-in rather than being platform-agnostic.
How it works
-
Fine-grained access control
Row, column, and cell-level permissions enforced dynamically based on user roles, attributes, and contextual conditions across cloud and on-premises systems.
-
Unified policy engine
Single policy definition that runs consistently across Amazon EMR, Databricks, Snowflake, and S3 data lakes without separate rule configuration per platform.
-
No-code policy authoring
Data stewards create and manage access policies via point-and-click UI without writing SQL or code, including row-level filtering and de-identification rules.
-
Data discovery and classification
Automatic identification and categorization of sensitive data across data lakes and warehouses, with integration into enterprise data catalogs.
-
Self-service access request portal
Centralized interface for users to request data access with built-in approval workflows and audit trails for compliance visibility.
-
Comprehensive audit and compliance reporting
Complete logs tracking who accessed what data, when, and for what purpose, supporting GDPR, CCPA, and HIPAA regulatory obligations.
Strengths and trade-offs
Strengths
- Unified policy enforcement across heterogeneous platforms (Snowflake, Databricks, EMR) eliminates manual duplication of access rules.
- No-code interface dramatically reduces time-to-deploy for non-technical data stewards compared to SQL-based competitors.
- Dynamic, request-time enforcement ensures zero stale permissions; users automatically see only authorized data without replication or view materialization.
Trade-offs
- Post-acquisition by Databricks (May 2023), the product road map is now tightly coupled to Databricks strategy; standalone deployment for customers on other platforms is uncertain.
- Pricing is custom/opaque with no public tier transparency; TCO estimates (15–20% of subscription cost) make budgeting difficult without direct sales contact.
- Limited third-party integration outside Databricks ecosystem; customers relying on Apache Spark on Kubernetes or on-prem Hadoop may find Databricks integration a forcing function.
Pricing context
Okera operates on a subscription model with custom pricing based on data sources, user count, and volume; no public pricing tiers are advertised. SelectHub estimates total cost of ownership at 15–20% of the initial subscription cost annually, covering software, maintenance, and training. A free trial is available upon request. The acquisition by Databricks in May 2023 suggests future pricing may be bundled with Databricks' unified analytics platform rather than sold standalone.
Alternatives
User reviews
No user reviews yet. Be the first to write one.
Sources
Reporting on this tool draws on these publicly available sources.
- cloudwars.com — Company founding (2016), headquarters location (San Francisco), funding ($30M), CEO Nong Li background, core technology (policy-based dynamic enforcement), platform integrations (EMR, Databricks, Snowflake)
- www.crunchbase.com — Databricks acquisition date (May 3, 2023), Okera founding details, venture funding raised ($29.6M), CEO Nong Li, Apache Parquet history
- www.selecthub.com — Key features (dynamic access control, policy management, data discovery, auditing, self-service requests), pricing model, TCO estimates (15–20% of subscription), customer use cases (financial services, healthcare, retail)
- www.prnewswire.com — Fine-grained access control announcement for both structured and unstructured data on S3 data lakes, no-code policy authoring capability