How ZS democratized secure ad
This blog post is co-written with Kiran Dhamane, Abhishek I S, and Mayur Ghodekar from ZS Associates
Organizations in regulated industries face a persistent tension: give developers the agility they need for ad-hoc analytics, or lock down the environment to meet compliance requirements. In this post, we explore how ZS built a security-hardened Amazon SageMaker environment that balances developer agility with strict governance. The platform now serves 1,000+ daily active users across 200+ SageMaker domains. We walk through the technical architecture, custom domain implementations, and the measurable business impact of democratizing machine learning (ML) access across the organization.
Building a healthcare-grade ML platform
ZS selected Amazon SageMaker Studio as their foundation for enterprise ML operations. The team implemented a comprehensive security framework that integrated their unique security standards directly into the developer experience. This approach let data scientists and analysts across the organization access ML capabilities while maintaining compliance with healthcare sector requirements.
The solution architecture runs in internet-free mode by default, with deployments operating without direct internet access. Amazon Virtual Private Cloud (Amazon VPC) endpoints provide controlled communication with required AWS services. For package management, ZS integrated JFrog Artifactory with upward repository linking and real-time package scanning to prevent unauthorized or tampered code from entering the environment.
The platform uses a multi-tenant architecture with separate Amazon SageMaker domains per tenant. Each domain maintains isolated Amazon Elastic File System (Amazon EFS) volumes, distinct AWS Identity and Access Management (IAM) roles, and controllable network settings. This design provides strong isolation that supports granular cost tracking and access control.
Figure 1: Secure multi-tenant SageMaker Studio domain architecture
ZS implemented a three-tier IAM role structure: Domain Execution Roles serve as defaults for users, Studio User Roles override domain defaults for fine-grained control, and Space Execution Roles govern shared workspaces. This hierarchy applies the principle of least privilege throughout the platform and maintains operational flexibility.
For data protection, the team enabled AWS Key Management Service (AWS KMS) encryption by default across resources. Amazon EFS volumes, Amazon Simple Storage Service (Amazon S3) buckets, Amazon Elastic Container Registry (Amazon ECR), and AWS CodeCommit repositories inherit encryption automatically (ZS’s CodeCommit deployment predates the service’s closure to new customers in July 2024.). The platform integrates CrowdStrike for OS-level threat detection and Splunk for log aggregation, with AWS CloudTrail logging all API calls to support audit trails.
Driving measurable business impact
ZS successfully rolled out the platform to most application team members, establishing Amazon SageMaker as their primary ad-hoc analytics tool. The solution delivers several quantifiable benefits:
SageMaker domain custom implementations
Standard SageMaker gave ZS a strong foundation, but running it as the primary ad-hoc analytics platform for a regulated, multi-team organization surfaced gaps that out-of-the-box features didn’t address: resilient backups for user work, tight cost guardrails on interactive sessions, safe package installation without internet access, and self-service access to data and infrastructure without opening the console. Rather than compromise on security or push that burden onto users, ZS built a set of targeted customizations on top of SageMaker to close each gap. The following sections walk through these implementations and the specific problem each one solved. Together, they turned SageMaker into a self-service analytics platform that hundreds of users rely on daily while ZS retains centralized governance.
The following figure shows backup files stored in the Amazon S3 bucket, organized by Space name and timestamp.
Figure 2: Space backup files in Amazon S3, organized by Space and timestamp
The following figure shows the available Glue kernels in the SageMaker JupyterLab launcher, so data engineers can select PySpark or Spark environments directly. After a kernel is selected, the Glue interactive session launches with the pre-configured default settings, which keeps resource allocation consistent across all users.
Figure 3: Glue PySpark and Spark kernels in the SageMaker JupyterLab launcher
The following figure shows a successful pip installation routed through JFrog, confirming that packages come from the approved repository rather than the public internet.
Figure 4: A pip installation routed through JFrog Artifactory
The following figures show the Streamlit application home page and the Amazon EMR cluster provisioning interface, which guides users through configuration options including software release version, node type, and worker count. Additional interfaces include the Amazon Redshift cluster start/stop tool and the DuckDB Amazon S3 query application, which displays query results in a table directly within the SageMaker environment.
Figure 5: Streamlit application for Amazon EMR cluster provisioning
Figure 6: Streamlit Amazon Redshift cluster start/stop dashboard
Figure 7: DuckDB application querying Amazon S3 data in SageMaker
The following figure shows the custom CloudWatch dashboard displaying Space-level metrics across the SageMaker environment.
Figure 8: Custom SageMakerStudio/JupyterLab namespace in the CloudWatch metrics console
Detailed CPU, memory, and disk utilization metrics are visualized per Space, so administrators can identify resource-constrained environments and optimize allocation.
Figure 9: Per-Space CPU, memory, and disk utilization in the CloudWatch dashboard
Building on this production foundation, ZS continues enhancing the platform with additional capabilities. The team is exploring Amazon SageMaker Feature Store for centralized feature management and Amazon SageMaker Model Registry for ML lifecycle governance. These additions will further streamline ML operations and maintain the security posture that enabled initial adoption.
The firm is also evaluating Amazon SageMaker Pipelines for workflow orchestration and Amazon SageMaker Model Monitor for production model oversight. These services will extend governance controls into production ML workloads, completing the end-to-end ML platform vision.
ZS’s journey demonstrates that democratizing access to advanced analytics and maintaining rigorous security controls are achievable together. With 200+ SageMaker domains deployed across AWS accounts and 1,000+ daily active users, the platform has become the primary ad-hoc analytics tool for the majority of ZS application teams. Monthly SageMaker spend exceeds $50K, and ZS offsets roughly $10K of that spend with Savings Plan discounts, reflecting both the scale of adoption and the cost discipline built into the architecture. The result is a production platform that proves developer agility and strict governance can coexist, and it serves as a replicable model for healthcare and life sciences organizations facing similar challenges.
To learn more about implementing secure ML platforms, visit the Amazon SageMaker documentation or contact your AWS account team to discuss your requirements.
Related Stories
Technology
What's Going On With Marvell Technology Stock Tuesday?
1 hour ago
Technology
How the NFL uses customer journey technology
1 hour ago
Technology
Feature Article: Biometrics at the Border
2 hours ago
Technology
Are you going to make that green light? A new, Kitchener
3 hours ago
Technology
Here's what's been breaking OC Transpo fare readers
4 hours ago
Technology
Whatfix cofounder and CEO Khadim Batti passes away
4 hours ago
Technology
Nigeria’s Defence Tech Star Talks Sovereignty
4 hours ago
Technology
Whistleblower raises concerns about untested USPS election technology
4 hours ago