Governance guide

How to govern Snowflake

A step-by-step guide to governing Snowflake with Rencore: detect with 43 policies, review with 10 reports, and remediate with 1 automations.

Definition

Governing Snowflake means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Snowflake with 43 pre-built policies, 10 reports, and 1 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.

Steps

  1. Inventory Snowflake

    Connect Snowflake and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Snowflake to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Snowflake reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Recommended Snowflake policies

Grounded in the Rencore catalog. See the full Snowflake catalog on the Snowflake connector page.

  • Snowflake user is active

    Active users are live identities that can authenticate, raising the likelihood that a weakness is exploited

    Severity: Medium
  • Snowflake warehouse is running

    Running (STARTED) warehouses are in active use, raising the likelihood that a weakness manifests

    Severity: Medium
  • Snowflake stage is external

    External stages are internet-facing data paths, raising the likelihood that a weakness leads to exfiltration

    Severity: Medium
  • Snowflake network policy is unrestricted

    Unrestricted network policies expose a wide-open surface, raising the likelihood that a weakness is reachable

    Severity: Medium
  • Disabled Snowflake users with role grants

    Detects disabled users that still have role grants assigned

    Severity: High
  • Snowflake users without MFA

    Detects active users that do not have multi-factor authentication enabled

    Severity: High
  • Snowflake users not logged in for 90+ days

    Detects active users who have not logged in for over 90 days

    Severity: Medium
  • Snowflake account with too many role grants

    Detects accounts with more than 10 role grants

    Severity: Medium
  • Snowflake external volumes that allow writes

    Detects external volumes configured to allow writes to external storage

    Severity: Medium
  • Snowflake stages with stored credentials

    Detects stages that store inline credentials instead of using a storage integration

    Severity: High
  • Snowflake external stages without a storage integration

    Detects external stages that do not use a storage integration

    Severity: Medium
  • Snowflake databases owned by ACCOUNTADMIN

    Detects databases whose owning role is ACCOUNTADMIN

    Severity: Medium
Explore the full Snowflake governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern