Governed database access for DBA teams.
Browser database shells for PostgreSQL, MySQL, MariaDB, SQL Server, and ClickHouse — with per-command ACLs and ready-made database read-only and mutating SQL sets, encrypted credential vaulting, session recording and replay, and syslog/CEF export to your SIEM. Least-privilege in practice, not just policy.
Shared credentials, unaudited queries, and least-privilege on paper.
Shared database credentials are the norm
Production databases often sit behind one shared account used by several DBAs and developers. When a destructive query runs, pinning it on an individual means hand-correlating timestamps across tools — and rotating that shared credential is a coordinated event that rarely happens.
Production queries run without oversight
Ad hoc queries against production data happen in personal clients, with no recording and no audit. An engineer can run a DELETE without a second reviewer, with no evidence of what ran.
Least-privilege is too coarse to enforce
Database roles grant access at the object level, not at the statement level. An engineer who needs to SELECT across production tables often ends up with INSERT and DELETE access too — because the alternative is weeks of role negotiation.
Database access is outside the broader audit trail
Server and cloud sessions may flow through a central access platform, but database sessions live in separate clients with no SIEM integration. Database access is an audit blind spot.
Database access under the same governance as every other session.
MisterShell brings database shells into the same access platform used for SSH, Kubernetes, and cloud sessions — with the same session policy, the same recording pipeline, and the same syslog/CEF audit trail. DBAs get a fast, capable browser shell; security teams get an attributable audit record for every query.
Governed database shells for every engine.
Remote workers, enterprise sign-in, high availability, and audit export to your SIEM come with the Pro edition; policy engines, session recording, and automation ship with Enterprise; IDS, syslog collection, and external access are licensed add-ons. See pricing.
Browser database shells — 5 engines
Full database shell sessions for PostgreSQL, MySQL, MariaDB, SQL Server, and ClickHouse, governed per command — in the browser, or from your own SSH client when you would rather stay in a terminal.
Per-command ACLs with ready-made SQL sets
Per-command ACLs ship with ready-made database read-only and mutating SQL sets. ACLs are named pattern lists — glob or regex — that admins extend with their own, so a SELECT-only DBA is enforced at the shell level, not just in database role grants.
Encrypted credential vaulting
Store shared or per-user database credentials in the platform vault. Credentials are masked in the UI and stored encrypted — no connection strings in shell history or session logs. Where a shared database account is unavoidable, keep it in a team vault shared by role: several DBAs use the same login, and the audit trail still records which person used it.
Session recording and replay
Database sessions are recorded and replayable under your Recording Policy, and recordings are immutable operational evidence — deleting a resource, user, or worker never deletes them, and they live in an object store you control. Each recording is SHA-256 hashed at capture, the hash held apart from the recording, and replay verifies it — so you can show it has not been altered since. When a query needs review or an incident needs investigation, replay exactly what ran — SQL, output, and timing — with no reconstruction required.
Durable per-command audit trail
Recorded sessions carry a command timeline, and session-policy decisions are logged per rule — so database actions are attributable to an individual, not a shared account.
Audit to SIEM via syslog/CEF (Pro edition)
Security audit events export to your SIEM via syslog/CEF. Database sessions appear in the same audit stream as server, cloud, and cluster sessions — no separate integration required.
Firewall-style session policy
Allow/deny rules — with notify and log flags — at connection time, scoped by location, resource type, tag, and role. Control which engineers can open sessions to which databases — least-privilege at the access layer, not just the schema layer. For production, a rule can require a second person to approve before a session opens, with a grant that expires on its own and every request and decision kept as evidence (Enterprise edition).
Live collaboration
Bring a colleague into a live database session — sessions are truly shared. For oversight, an admin can observe the live session read-only from Review → Sessions.
Your databases, on the same platform as everything else.
Database sessions share the fabric that governs servers, clusters, and network — so the audit blind spot closes without a separate integration.
Security’s policy engine speaks SQL here
The same per-command ACLs that govern SSH ship with ready-made database read-only and mutating SQL sets — a destructive query is stopped by guardrails the security team maintains, not ones you had to build.
One audit trail, beside every other team’s
Because DBAs, sysadmins, and network engineers all record to one pipeline, your per-statement actions are attributable alongside everyone else’s — in the trail compliance already trusts.
Automation and AI across the estate
Health events, config changes, and alerts on your databases feed the same event playbooks and AI agents the platform team runs everywhere else — no database-only tooling.
Get in Touch
Want a guided demo, or a trial license to evaluate Pro or Enterprise on your own infrastructure? Tell us — we'd love to hear from you.