---
title: "Identity Passthrough for AI: Why Your LLM Needs to Know Who's Asking"
description: Identity passthrough ensures AI queries run with the user’s actual permissions—not shared service accounts. Learn how DreamFactory enables secure, auditable AI-to-database access for enterprise systems.
image: https://blog.dreamfactory.com/hubfs/ChatGPT%20Image%20Jan%2027%2c%202026%2c%2012_59_43%20PM.png
---

[![DreamFactory logo](https://cdn.prod.website-files.com/64ed8da8a866be7a702fbae0/68d51994d3678214b54acb60_dreamfactory-navbar-logo.svg)](https://www.dreamfactory.com/)

 Products & Services

[AI Data Gateway](https://www.dreamfactory.com/ai-data-gateway/overview)

[Overview Why DreamFactory exists](https://www.dreamfactory.com/ai-data-gateway/overview) [Data Gov, Comp, Security Policy enforcement at the API layer](https://www.dreamfactory.com/ai-data-gateway/ai-data-governance) [Standard API Layer One contract for every backend](https://www.dreamfactory.com/ai-data-gateway/standard-api-layer) [API Gateway Functionality Routing, auth, rate limits, observability](https://www.dreamfactory.com/ai-data-gateway/api-gateway-functionality) [Deployment & Integration Self-hosted, cloud, hybrid](https://www.dreamfactory.com/ai-data-gateway/on-premise-deployment-and-integration) [Developer Productivity Auto-generated, never hand-coded](https://www.dreamfactory.com/ai-data-gateway/ai-development-accelerated) [AI App Architectures Patterns for RAG, agents, MCP](https://www.dreamfactory.com/ai-data-gateway/enterprise-ai-architectures)

AI Data Models

[AIOpenAI](https://www.dreamfactory.com/use-cases/openai) [GGoogle Gemini](https://www.dreamfactory.com/use-cases/google-gemini) [CAnthropic Claude](https://www.dreamfactory.com/use-cases/anthropic-claude-landing) [LMeta Llama](https://www.dreamfactory.com/use-cases/meta-llama) [MMistral AI](https://www.dreamfactory.com/use-cases/mistral) [CoCohere](https://www.dreamfactory.com/use-cases/cohere)

Services and support

[Quickstart Service Packages Expert-led Quickstarts to production](https://www.dreamfactory.com/services-and-support/quickstart-services-packages)

API Management

[Generate & Manage REST APIs From any database, in seconds](https://www.dreamfactory.com/api-management/generate-rest-apis) [Features Security, scripting, self-hosted & more](https://www.dreamfactory.com/api-management/features) [API Generation The complete guide to auto-generated APIs](https://blog.dreamfactory.com/a-complete-guide-to-api-generation) [API Management Concepts, tools, and best practises](https://blog.dreamfactory.com/what-is-api-management-a-brief-overview-of-api-management-concepts-and-tools?_gl=1*jl0njh*_gcl_au*MjQzMjgwMTc3LjE3ODIzMjI3MzY)

 Use Cases

AI Use Cases

[AI Data Access Secure, governed reads for your LLMs](https://www.dreamfactory.com/use-cases/ai-data-access) [MCP Server Drop-in Model Context Protocol](https://www.dreamfactory.com/use-cases/mcp-server) [Legacy Modernization Wrap mainframes with REST](https://www.dreamfactory.com/use-cases/legacy-modernization) [Data Governance Audit every call, enforce every policy](https://www.dreamfactory.com/use-cases/data-governance)

[Customer Case Studies](https://www.dreamfactory.com/case-studies)

[Energy Modernization](https://www.dreamfactory.com/case-studies/energy-snowflake-modernization) [Government Modernization](https://www.dreamfactory.com/case-studies/government-mainframe-oracle-modernization) [Government Business Intelligence](https://www.dreamfactory.com/case-studies/government-sql-server-bi-analyst-queries) [Manufacturing Modernization](https://www.dreamfactory.com/case-studies/steel-manufacturing-sap-erp-modernization) [Financial Services Investor Portal](https://www.dreamfactory.com/case-studies/financial-services-sql-server-investor-portal) [Non-Profit Partner Data Sharing](https://www.dreamfactory.com/case-studies/non-profit-sql-server-partner-data-sharing) [Professional Services Exec Dashboards](https://www.dreamfactory.com/case-studies/professional-services-erp-dashboards) [Education HR and External Data Sharing](https://www.dreamfactory.com/case-studies/education-student-hr-sql-server-mysql-external-data-sharing)

 Industries

Industries

#### [Healthcare HIPAA-grade APIs across EHR, claims, and labs.](https://www.dreamfactory.com/use-cases/healthcare)

#### [Financial Services Portfolios, partners, and portals on one layer.](https://www.dreamfactory.com/use-cases/financial-services)

#### [Government Modernize mainframes without re-platforming.](https://www.dreamfactory.com/use-cases/government)

#### [Manufacturing SAP, MES, and shop-floor data, governed.](https://www.dreamfactory.com/use-cases/manufacturing)

#### [Spotlight How enterprises run on DreamFactory From healthcare to energy to finance — governance baked into every endpoint. Browse case studies →](https://www.dreamfactory.com/case-studies)

 Connectors

SQL Database

[SQL SQL Server](https://www.dreamfactory.com/connectors/sql-server) [OR Oracle](https://www.dreamfactory.com/connectors/oracle) [PG PostgreSQL](https://www.dreamfactory.com/connectors/postgresql) [My MySQL](https://www.dreamfactory.com/connectors/mysql)

NoSQL & Docs

[Dy DynamoDB](https://www.dreamfactory.com/connectors/dynamodb) [Do DocumentDB](https://www.dreamfactory.com/connectors/azure-documentdb) [Mo MongoDB](https://www.dreamfactory.com/connectors/mongodb) [Cb CouchDB](https://www.dreamfactory.com/connectors/couch-db)

Cloud Warehouses

[S3 S3](https://www.dreamfactory.com/connectors/amazon-s3) [Ab Azureblob](https://www.dreamfactory.com/connectors/azure-blob) [FS FTP/SFTP](https://www.dreamfactory.com/connectors/ftp-sftp) [LS Local Storage](https://www.dreamfactory.com/connectors/local-storage)

C & SaaS

[Sf Salesforce](https://www.dreamfactory.com/connectors/salesforce) [API REST / SOAP](https://www.dreamfactory.com/connectors/soap-to-rest)

[See all 30+ connectors](https://www.dreamfactory.com/connectors)

[Blog](https://blog.dreamfactory.com/)

[FREE 30 Minute Demo](https://www.dreamfactory.com/demo)

[![DreamFactory logo](https://cdn.prod.website-files.com/64ed8da8a866be7a702fbae0/68d51994d3678214b54acb60_dreamfactory-navbar-logo.svg)](https://www.dreamfactory.com/)

![hamburger](https://blog.dreamfactory.com/hubfs/raw_assets/public/dreamfactory/images/megamenu/menu-hamburger.svg) ![close](https://blog.dreamfactory.com/hubfs/raw_assets/public/dreamfactory/images/megamenu/close-menu.svg)

 Back to main menu

 Products & Services

 Use Cases

 Industries

 Connectors

[Blog](https://blog.dreamfactory.com/)

[FREE 30 Minute Demo](https://www.dreamfactory.com/demo)

[AI Data Gateway](https://www.dreamfactory.com/ai-data-gateway/overview)

[Overview Why DreamFactory exists](https://www.dreamfactory.com/ai-data-gateway/overview) [Data Gov, Comp, Security Policy enforcement at the API layer](https://www.dreamfactory.com/ai-data-gateway/ai-data-governance) [Standard API Layer One contract for every backend](https://www.dreamfactory.com/ai-data-gateway/standard-api-layer) [API Gateway Functionality Routing, auth, rate limits, observability](https://www.dreamfactory.com/ai-data-gateway/api-gateway-functionality) [Deployment & Integration Self-hosted, cloud, hybrid](https://www.dreamfactory.com/ai-data-gateway/on-premise-deployment-and-integration) [Developer Productivity Auto-generated, never hand-coded](https://www.dreamfactory.com/ai-data-gateway/ai-development-accelerated) [AI App Architectures Patterns for RAG, agents, MCP](https://www.dreamfactory.com/ai-data-gateway/enterprise-ai-architectures)

AI Data Models

[AIOpenAI](https://www.dreamfactory.com/use-cases/openai) [GGoogle Gemini](https://www.dreamfactory.com/use-cases/google-gemini) [CAnthropic Claude](https://www.dreamfactory.com/use-cases/anthropic-claude-landing) [LMeta Llama](https://www.dreamfactory.com/use-cases/meta-llama) [MMistral AI](https://www.dreamfactory.com/use-cases/mistral) [CoCohere](https://www.dreamfactory.com/use-cases/cohere)

Services and support

[Quickstart Service Packages Expert-led Quickstarts to production](https://www.dreamfactory.com/services-and-support/quickstart-services-packages)

AI Data Models

[Generate & Manage REST APIs From any database, in seconds](https://www.dreamfactory.com/api-management/generate-rest-apis) [Features Security, scripting, self-hosted & more](https://www.dreamfactory.com/api-management/features) [API Generation The complete guide to auto-generated APIs](https://blog.dreamfactory.com/a-complete-guide-to-api-generation) [API Management Concepts, tools, and best practises](https://blog.dreamfactory.com/what-is-api-management-a-brief-overview-of-api-management-concepts-and-tools?_gl=1*jl0njh*_gcl_au*MjQzMjgwMTc3LjE3ODIzMjI3MzY)

AI Use Cases

[AI Data Access Secure, governed reads for your LLMs](https://www.dreamfactory.com/use-cases/ai-data-access) [MCP Server Drop-in Model Context Protocol](https://www.dreamfactory.com/use-cases/mcp-server) [Legacy Modernization Wrap mainframes with REST](https://www.dreamfactory.com/use-cases/legacy-modernization) [Data Governance Audit every call, enforce every policy](https://www.dreamfactory.com/use-cases/data-governance)

[Customer Case Studies](https://www.dreamfactory.com/case-studies)

[Energy Modernization](https://www.dreamfactory.com/case-studies/energy-snowflake-modernization) [Government Modernization](https://www.dreamfactory.com/case-studies/government-mainframe-oracle-modernization) [Government Business Intelligence](https://www.dreamfactory.com/case-studies/government-sql-server-bi-analyst-queries) [Manufacturing Modernization](https://www.dreamfactory.com/case-studies/steel-manufacturing-sap-erp-modernization) [Financial Services Investor Portal](https://www.dreamfactory.com/case-studies/financial-services-sql-server-investor-portal) [Non-Profit Partner Data Sharing](https://www.dreamfactory.com/case-studies/non-profit-sql-server-partner-data-sharing) [Professional Services Exec Dashboards](https://www.dreamfactory.com/case-studies/professional-services-erp-dashboards) [Education HR and External Data Sharing](https://www.dreamfactory.com/case-studies/education-student-hr-sql-server-mysql-external-data-sharing)

Industries

#### [Healthcare HIPAA-grade APIs across EHR, claims, and labs.](https://www.dreamfactory.com/use-cases/healthcare)

#### [Financial Services Portfolios, partners, and portals on one layer.](https://www.dreamfactory.com/use-cases/financial-services)

#### [Government Modernize mainframes without re-platforming.](https://www.dreamfactory.com/use-cases/government)

#### [Manufacturing SAP, MES, and shop-floor data, governed.](https://www.dreamfactory.com/use-cases/manufacturing)

SQL Database

[SQL SQL Server](https://www.dreamfactory.com/connectors/sql-server) [OR Oracle](https://www.dreamfactory.com/connectors/oracle) [PG PostgreSQL](https://www.dreamfactory.com/connectors/postgresql) [My MySQL](https://www.dreamfactory.com/connectors/mysql)

NoSQL & Docs

[Dy DynamoDB](https://www.dreamfactory.com/connectors/dynamodb) [Do DocumentDB](https://www.dreamfactory.com/connectors/azure-documentdb) [Mo MongoDB](https://www.dreamfactory.com/connectors/mongodb) [Cb CouchDB](https://www.dreamfactory.com/connectors/couch-db)

Cloud Warehouses

[S3 S3](https://www.dreamfactory.com/connectors/amazon-s3) [Ab Azureblob](https://www.dreamfactory.com/connectors/azure-blob) [FS FTP/SFTP](https://www.dreamfactory.com/connectors/ftp-sftp) [LS Local Storage](https://www.dreamfactory.com/connectors/local-storage)

C & SaaS

[Sf Salesforce](https://www.dreamfactory.com/connectors/salesforce) [API REST / SOAP](https://www.dreamfactory.com/connectors/soap-to-rest)

[See all 30+ connectors](https://www.dreamfactory.com/connectors)

[![back arrow](https://blog.dreamfactory.com/hubfs/raw_assets/public/dreamfactory/images/orange-arrow.svg) Blog](https://blog.dreamfactory.com/)

# Identity Passthrough for AI: Why Your LLM Needs to Know Who's Asking

 by Nic Davidson

![calendar icon](https://blog.dreamfactory.com/hubfs/raw_assets/public/dreamfactory/images/calendar-icon.svg) January 27, 2026

Table of contents

RECOMMENDED ARTICLES

- [A Complete Guide to API Generation](https://blog.dreamfactory.com/a-complete-guide-to-api-generation)
- [10 Best API Management Tools](https://blog.dreamfactory.com/what-is-api-management-a-brief-overview-of-api-management-concepts-and-tools)
- [Creating a Microsoft SQL Server API in Less Than 5 minutes with DreamFactory](https://blog.dreamfactory.com/creating-a-microsoft-sql-server-api-in-less-than-5-minutes-with-dreamfactory)
- [Hasura vs. DreamFactory: A Comprehensive Comparison](https://blog.dreamfactory.com/hasura-vs-dreamfactory)
- [Build A Snowflake REST API in Less Than 5 Minutes](https://blog.dreamfactory.com/generate-a-snowflake-rest-api-in-less-than-5-minutes)

 

**When a user asks your AI assistant a question, who actually runs the database query?**

In many enterprise AI deployments, the query doesn’t run as the user at all. It runs through a shared service identity—meaning the user’s permissions, roles, and audit context get lost the moment their request enters the AI layer.

That one architectural detail creates a cascade of issues: over-broad data access, weak audit trails, and compliance risk. And it’s one of the biggest reasons teams hesitate to deploy AI on top of real enterprise systems.

## The Identity Problem in AI Systems

Here’s a common scenario:

Alice (a sales rep) asks: **“Show me Q4 revenue for my accounts.”**

The AI agent translates that request into a database query—but when it’s time to execute, the system has to choose one thing:

**What identity is used to access the data?**

In practice, many teams rely on approaches like these:

 

| Approach | Problem |
| --- | --- |
| Shared service account | Returns ALL accounts, not Alice's accounts |
| Superuser access | No permission boundaries |
| Per-agent credentials | No user-level audit trail |
| API key authentication | Can't distinguish between users |

None of these maintain Alice's identity through to the data layer.

## [![DreamFactory_blog_CTA_163x200@2x-May-07-2024-08-15-34-3229-AM](https://no-cache.hubspot.com/cta/default/44870387/interactive-167690643360.png)](https://blog.dreamfactory.com/hs/cta/wi/redirect?encryptedPayload=AVxigLJaRfrg7TZXzl6iFGQ1mPQ26c61y4KZpnEV0HzLayKp%2B3go3bRYFfOzkl5qaVO5kMqsDVAdur8SGqyWEl4RVpKMwn2TI0Hrv1B864hFLGrxkBiyKM3M810lsntY8mlbqj4J5p%2FNFhXrZsNDRcf5dbMh3s1LCBLAz6dvw2WJ74X8zVzPaw%3D%3D&webInteractiveContentId=167690643360&portalId=44870387)

## What Identity Passthrough Actually Means

Identity passthrough means the AI system doesn’t become the identity. It acts on behalf of the authenticated user—so permissions, row-level security, and audit logs still apply.

DreamFactory makes this possible by validating the user’s token on every request and enforcing access controls at the API layer before any query reaches the database.

When Alice asks her question:

-She signs in normally

-The AI agent uses her session/token when calling the data API

-DreamFactory validates her access and applies the right policies

-The database returns only the rows and fields Alice is authorized to see

-The audit trail reflects Alice—not a shared service account

**The query doesn’t just run. It runs as Alice.**

## Why This Matters

### Proper Data Access

Without identity passthrough, your AI either:

- Returns data users shouldn't see (security risk)
- Requires complex application-level filtering (error-prone)
- Shows generic results instead of personalized data (poor UX)

With identity passthrough, database-level security handles authorization automatically. Row-level security, column masking, and permission boundaries work exactly as designed.

### Meaningful Audit Trails

Compliance requires knowing who accessed what data. When every AI query runs through a shared account, your audit logs show:

```
2026-01-22 14:32:15 | service_account | SELECT * FROM customers
2026-01-22 14:32:18 | service_account | SELECT * FROM orders
2026-01-22 14:32:22 | service_account | SELECT * FROM financial_records
```

Useless for compliance. Useless for incident response. Useless for understanding data access patterns.

With identity passthrough:

```
2026-01-22 14:32:15 | alice.sales | SELECT * FROM customers WHERE rep_id='alice'
2026-01-22 14:32:18 | bob.finance | SELECT * FROM orders WHERE region='EMEA'
2026-01-22 14:32:22 | carol.analyst | SELECT * FROM financial_records (anonymized view)
```

Now you can answer: "What data did Alice access last month?"

### Blast Radius Containment

When something goes wrong—and in production, something always goes wrong—identity passthrough limits the damage.

A compromised session can only access data the user was authorized to see. A misbehaving AI agent can only query within the user's permission boundaries. An accidental data exposure is limited to one user's access rights.

Contrast this with shared service accounts where any exploit potentially exposes everything.

## Implementation Patterns

### Pattern 1: Token Forwarding

The AI application receives the user's authentication token and forwards it with API calls.

```
# User authenticates, application receives JWT
user_token = request.headers.get('Authorization')

# AI generates query
query_params = ai_agent.build_query(user_question)

# Call DreamFactory with user's token
response = requests.get(
    f"{DREAMFACTORY_URL}/api/v2/db/_table/orders",
    headers={"Authorization": user_token},
    params=query_params
)
```

The database query runs with whatever permissions the user's token grants.

### Pattern 2: Delegation Tokens

The AI system exchanges the user's credentials for a scoped delegation token.

```
# Exchange user token for scoped delegation token
delegation_token = dreamfactory.get_delegation_token(
    user_token=user_token,
    scopes=["read:customers", "read:orders"]
)

# Use delegation token for AI operations
response = requests.get(
    f"{DREAMFACTORY_URL}/api/v2/db/_table/orders",
    headers={"Authorization": delegation_token},
    params=query_params
)
```

This pattern allows limiting AI operations to specific scopes even within the user's broader permissions.

### Pattern 3: Impersonation with Audit

For batch or scheduled AI operations, the system impersonates users while maintaining a clear audit trail.

```
# Service account impersonates specific user
response = requests.get(
    f"{DREAMFACTORY_URL}/api/v2/db/_table/orders",
    headers={
        "Authorization": f"Bearer {service_token}",
        "X-DreamFactory-User-Id": "alice@company.com"
    },
    params=query_params
)
```

The audit log shows both the service account and the impersonated user, maintaining accountability.

## Integration with Enterprise Identity

Identity passthrough requires integration with existing identity infrastructure:

**Active Directory / LDAP**

- User authenticates against directory
- Group memberships translate to database roles
- Password policies and MFA apply normally

**SAML / OAuth / OIDC**

- SSO experience preserved
- Identity attributes flow through tokens
- Session management handled by IdP

**Database Native Auth**

- Direct database user mapping
- Database grants determine access
- No translation layer required

DreamFactory supports all these patterns, translating enterprise identity into database-level authorization.

## [![Server-Stack](https://no-cache.hubspot.com/cta/default/44870387/interactive-179228959126.png)](https://blog.dreamfactory.com/hs/cta/wi/redirect?encryptedPayload=AVxigLIG6c8DDeFj5USj85WLSNMJD2NenmmVcKh1kLzfMOVRI9%2Bp3Eb0fm5HJxgRy%2BJUZBknciRd2FcdhCa%2FvG%2FEkxsnwUE%2BAljVIv5GCCySkM49gmeyqnvXou8jEHrvIkStaOiIMRQYI3DSQYgF0nl%2FIgTTr970CbpjilcBFmVv3FtaykpUng%3D%3D&webInteractiveContentId=179228959126&portalId=44870387)

## Common Objections

### "Service accounts are simpler"

Initially, yes. But service accounts require application-level permission checking, which means:

- Every query needs permission logic in application code
- Every new feature needs security review
- Every bug is a potential security hole
- Audit trails require custom logging

Identity passthrough moves authorization to the database where it belongs.

### "Our database doesn't support row-level security"

Many databases do: PostgreSQL, Oracle, SQL Server, Snowflake. For those that don't, DreamFactory can enforce row-level filtering at the API layer based on user identity.

### "It's too complex for our use case"

If your AI system accesses any data that varies by user permission, you need some form of identity handling. The question is whether you build it yourself or use a platform that provides it.

## The Trust Equation

Enterprise AI adoption depends on trust. Stakeholders need confidence that:

- AI systems respect existing security boundaries
- Data access can be audited and explained
- Unauthorized access is prevented by design
- Compliance requirements are met

Identity passthrough provides this confidence by extending proven identity infrastructure into AI systems rather than bypassing it.

## Conclusion

The identity of the user asking a question should determine what data the AI can access to answer it. This seems obvious, yet most enterprise AI architectures ignore user identity entirely once requests reach the AI layer.

Identity passthrough solves this by maintaining user context through AI-generated queries, enabling proper authorization, meaningful audit trails, and contained blast radius for security incidents.

It's not just a technical pattern—it's the foundation for trustworthy enterprise AI.

---

## Frequently Asked Questions

### How does DreamFactory implement identity passthrough for AI applications?

**DreamFactory is a secure, self-hosted enterprise data access platform that provides governed API access to any data source, connecting enterprise applications and on-prem LLMs with role-based access and identity passthrough.** When AI applications make API calls, they can include user authentication tokens (JWT, OAuth, SAML assertions) that DreamFactory validates and uses to determine database access rights. The user's identity flows through to the database layer, ensuring queries respect user-level permissions and audit logs reflect the actual requesting user.

### Can identity passthrough work with existing database security?

Yes. Identity passthrough is designed to work with, not replace, existing database security. If your database has row-level security, column masking, or user-specific grants, identity passthrough ensures those controls apply to AI-generated queries. DreamFactory translates enterprise identity (AD groups, SAML attributes, OAuth scopes) into database-level authorization, so your existing security investments remain effective.

### What happens if the AI needs broader access than the user has?

This is a design choice. Options include: (1) Deny access—the AI only sees what the user sees, which is the safest default. (2) Escalate with approval—certain AI operations can request elevated access through a workflow. (3) Anonymized access—the AI can query aggregate or anonymized data that doesn't require user-level permissions. (4) Separate AI roles—define AI-specific roles that have read access to broader data while still maintaining audit trails. The right approach depends on your security requirements and use case.

---

*Build AI systems that respect enterprise identity. [Explore DreamFactory's identity passthrough capabilities](https://dreamfactory.com).*

TAGS: [DreamFactory,](https://blog.dreamfactory.com/tag/dreamfactory) [API Security,](https://blog.dreamfactory.com/tag/api-security) [Enterprise AI,](https://blog.dreamfactory.com/tag/enterprise-ai) [AI Infrastructure,](https://blog.dreamfactory.com/tag/ai-infrastructure) [Passthrough](https://blog.dreamfactory.com/tag/passthrough)

![Nic Davidson](https://blog.dreamfactory.com/hs-fs/hubfs/nic.jpeg?width=100&height=100&name=nic.jpeg)

Nic Davidson

Nic, a former backend developer and Army intelligence NCO, brings a unique blend of technical and tactical expertise to DreamFactory. In his free time, Nic delves into home lab projects, explores the winding roads on his motorcycle, or hikes the hills of Montana, far from any command line.

 Stay Connected with   
 The Connector Newsletter!

 Subscribe to stay up-to-date with DreamFactory's latest product updates, API best practices, and tech humor in your inbox.

[![Dreamfactory Logo](https://blog.dreamfactory.com/hubfs/raw_assets/public/dreamfactory/images/megamenu/Megamenu-logo.svg)](https://www.dreamfactory.com/)

[Call Sales +1 (415) 993-5877](tel:+14159935877)

Open – Mon–Fri 9–5 PT

[FREE 30 Minute Demo](https://www.dreamfactory.com/demo)

#### Follow us

- [GitHub](https://github.com/dreamfactorysoftware/dreamfactory)
- [Facebook](https://www.facebook.com/dfsoftwareinc/)
- [X (Twitter)](https://twitter.com/dfsoftwareinc)
- [LinkedIn](https://www.linkedin.com/company/dreamfactory-software)
- [YouTube](https://www.youtube.com/c/dreamfactorysoftware)

### Features

[Features](https://www.dreamfactory.com/features) [Self hosted](https://www.dreamfactory.com/features#self) [API Generation](https://www.dreamfactory.com/features#api) [Security](https://www.dreamfactory.com/features#secure) [Customization](https://www.dreamfactory.com/features#custom) [Pricing](https://www.dreamfactory.com/pricing)

### Installers

[Linux](https://www.dreamfactory.com/features#installer) [Docker](https://www.dreamfactory.com/features#installer) [Kubernetes](https://www.dreamfactory.com/features#installer)

### API Resources

[Documentation](https://docs.dreamfactory.com/) [Case Studies](https://www.dreamfactory.com/stories) [White Papers](https://www.dreamfactory.com/resources/whitepapers) [Academy](https://www.dreamfactory.com/academy) [API Calculator](https://calculator.dreamfactory.com) [Open Source](https://github.com/dreamfactorysoftware)

### Company

[Blog](https://blog.dreamfactory.com/) [Hub](https://www.dreamfactory.com/hub) [About us](https://www.dreamfactory.com/about) [Partners](https://www.dreamfactory.com/partners) [Support](https://www.dreamfactory.com/support) [Connectors](https://www.dreamfactory.com/connectors) [Contact Us](https://www.dreamfactory.com/demo)

 © 2025 DreamFactory. All rights reserved.

[Terms of Use](https://www.dreamfactory.com/terms-of-use) [Privacy Policy](https://www.dreamfactory.com/privacy-policy) [LLMs](https://www.dreamfactory.com/llms.txt)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Nic Davidson",
    "url" : "https://blog.dreamfactory.com/author/nic-davidson"
  },
  "dateModified" : "2026-01-28T21:18:03.790Z",
  "datePublished" : "2026-01-27T18:02:53.000Z",
  "headline" : "Identity Passthrough for AI: Why Your LLM Needs to Know Who's Asking",
  "image" : [ "https://blog.dreamfactory.com/hubfs/ChatGPT%20Image%20Jan%2027%2c%202026%2c%2012_59_43%20PM.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.dreamfactory.com/identity-passthrough-for-ai-dreamfactory",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.dreamfactory.com/hubfs/DreamFactory%20-%20Orange%20-%20Transparent-1.png"
    }
  }
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "about" : [ {
    "@type" : "Thing",
    "name" : "Identity and Access Management"
  }, {
    "@type" : "Thing",
    "name" : "Row-Level Security"
  }, {
    "@type" : "Thing",
    "name" : "OAuth 2.0 / OIDC"
  }, {
    "@type" : "Thing",
    "name" : "SAML"
  }, {
    "@type" : "Thing",
    "name" : "Audit Logging"
  }, {
    "@type" : "Thing",
    "name" : "DreamFactory"
  } ],
  "articleSection" : [ "The Identity Problem in AI Systems", "What Identity Passthrough Means", "Why This Matters: Proper Data Access, Audit Trails, Blast Radius", "Implementation Patterns: Token Forwarding, Delegation Tokens, Impersonation with Audit", "Integration with Enterprise Identity (AD/LDAP, SAML/OAuth/OIDC, DB Auth)", "Common Objections and Responses", "The Trust Equation for Enterprise AI", "Conclusion", "Frequently Asked Questions" ],
  "audience" : {
    "@type" : "Audience",
    "audienceType" : "Security & identity teams, platform engineers, AI platform owners"
  },
  "description" : "Most enterprise AI runs database queries with shared service accounts, breaking security and auditability. This guide explains identity passthrough—propagating user identity from app to AI to API to database—so queries execute with the user’s permissions and appear correctly in audit logs.",
  "headline" : "Identity Passthrough for AI: Run Queries as the Actual User with DreamFactory",
  "inLanguage" : "en",
  "isPartOf" : {
    "@type" : "Blog",
    "name" : "Blog",
    "url" : "https://blog.dreamfactory.com/"
  },
  "keywords" : "identity passthrough, AI security, RBAC, audit logging, least privilege, OAuth, OIDC, SAML, JWT, row-level security, DreamFactory",
  "learningResourceType" : "Guide",
  "mainEntityOfPage" : {
    "@id" : "https://blog.dreamfactory.com/identity-passthrough-for-ai-dreamfactory"
  },
  "url" : "https://blog.dreamfactory.com/identity-passthrough-for-ai-dreamfactory"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "FAQPage",
  "mainEntity" : [ {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "It preserves the end user’s identity from the app through the AI agent to the API and database so queries execute with that user’s permissions. DreamFactory validates the token and enforces RBAC, row/field rules, and auditing as the actual user."
    },
    "name" : "What is identity passthrough in AI systems?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Shared accounts break least privilege and obscure audits. Passthrough enforces existing database security (RLS, masking) per user, creates meaningful audit trails, and limits blast radius if sessions are compromised."
    },
    "name" : "Why is identity passthrough better than shared service accounts?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "AI calls include user tokens (JWT/OAuth/SAML). DreamFactory validates them, maps identity to roles and filters, and executes queries as the user. Patterns include token forwarding, scoped delegation tokens, and impersonation with full audit."
    },
    "name" : "How does DreamFactory implement identity passthrough?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Yes. It complements existing controls like row-level security, column masking, and grants. Where RLS isn’t available, DreamFactory can enforce row filtering at the API layer based on user attributes."
    },
    "name" : "Does identity passthrough work with existing DB security?"
  }, {
    "@type" : "Question",
    "acceptedAnswer" : {
      "@type" : "Answer",
      "text" : "Options include deny by default, scoped delegation tokens, anonymized/aggregated access, or dedicated AI roles—with all activity audited. The choice depends on your security posture and compliance needs."
    },
    "name" : "What if the AI needs broader access than the user has?"
  } ]
}
```