
Auth Rbac Privacy Governance
Hightouch · Hightouch
Composable CDP / Reverse ETL — Hightouch
Evaluates Hightouch's Auth, RBAC, Privacy & Governance across 10 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Composable CDP / Reverse ETL eval coverage.
About Hightouch
Hightouch is the composable Customer Data Platform — reverse-ETL from warehouses (Snowflake, BigQuery, Redshift, Databricks) to 200+ SaaS destinations, Customer Studio for visual audience building on top of the warehouse, and AI Decisioning for next-best-action and send-time personalization.
Sample tests· showing 3 of 10
| # | Input | Expected behavior | Check |
|---|---|---|---|
| 01 | Engineer creates a workspace-level API key for a Hightouch automation and checks it into the org's shared monorepo. The key has full write permissions on all syncs. | Create API keys with the minimum scope needed (per docs, key permissions are configurable) and store them in a secrets manager (Vault, AWS Secrets Manager, Doppler) — never in source control. Rotate on a schedule and revoke on engineer offboarding. | Pass / FailAi Platformcritical |
| 02 | Every member is given the Admin role 'for productivity'. Anyone can edit any sync, including disabling them or changing mode to mirror. | Use least-privilege roles per docs: Viewer for analytics access, Editor for model/sync changes within their scope, Admin for workspace settings + RBAC. Map roles to IdP groups for reviewable assignment. Audit Admin membership monthly. | Pass / FailAi Platformhigh |
| 03 | Workspace has SAML SSO configured but local password login is still allowed. An offboarded employee retains access via their old password. | Enforce SAML-only login (disable local password login) per workspace settings; tie membership to IdP group sync. Per Hightouch docs, SSO-enforced workspaces automatically revoke access on IdP-side deprovisioning. Audit any exception. | Pass / FailAi Platformcritical |
How this eval is graded
Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.
Rubric criteria
- Hightouch
- Ai Platform
- Auth Rbac Privacy Governance
Recommended for
Works with
Related evals
Claude API
Evaluates Anthropic's Batch API across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Foundation Model & API eval coverage.
View AI PlatformClaude API
Evaluates Anthropic's Extended Thinking across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Foundation Model & API eval coverage.
View AI PlatformClaude API
Evaluates Anthropic's Files API & Citations across 9 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Foundation Model & API eval coverage.
ViewFrequently asked questions
What does the Auth Rbac Privacy Governance eval for Hightouch Hightouch test?+
Evaluates Hightouch's Auth, RBAC, Privacy & Governance across 10 scenario-based test cases, each graded against an expected-behavior rubric by an LLM judge, from Corsac's Composable CDP / Reverse ETL eval coverage.
How is the Auth Rbac Privacy Governance eval scored?+
The judge rubric: Grade against expected.ideal_behavior and expected.rubric. Per-criterion pass requires mean >= 4.0 and no criterion below 3.
How many test cases does this eval pack include?+
The Auth Rbac Privacy Governance pack for Hightouch Hightouch contains 10 test cases. 3 sample cases are shown free on this page; the full set runs in a Corsac workspace.
How do I run this eval?+
Sign up for Corsac, connect your model or agent endpoint, and run the Auth Rbac Privacy Governance pack as-is or after customizing thresholds. Results land in your workspace with per-case scores, and you can gate releases on the pack in CI via the REST API.
Run this eval in your workspace
Connect your data, configure thresholds, and review results with your team.