Governance guide

How to govern Sprawl in Snowflake

A step-by-step guide to governing Sprawl in Snowflake with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Sprawl in Snowflake means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Snowflake with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Sprawl.

Steps

  1. Inventory Snowflake

    Connect Snowflake and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Sprawl in Snowflake to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Snowflake reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Snowflake controls for Sprawl

Grounded in the Rencore catalog. See the full Snowflake catalog on the Snowflake connector page.

  • Snowflake users not logged in for 90+ days

    Detects active users who have not logged in for over 90 days

    Severity: Medium
  • Suspended Snowflake warehouses

    Detects warehouses that are currently suspended and may be unused

    Severity: Low
  • Disabled Snowflake API integrations

    Detects API integrations that are disabled and may be obsolete

    Severity: Low
  • Disabled Snowflake notification integrations

    Detects notification integrations that are disabled and may be obsolete

    Severity: Low
  • Disabled Snowflake catalog integrations

    Detects catalog integrations that are disabled and may be obsolete

    Severity: Low
  • Snowflake orphan custom roles

    Detects custom roles that are not assigned to any user

    Severity: Low
  • Snowflake transient databases

    Detects transient databases (no Fail-safe) that may be forgotten scratch space

    Severity: Low
  • Disabled Snowflake Users

    Shows Snowflake user accounts that are disabled

  • Suspended Snowflake Warehouses

    Shows warehouses that are currently suspended

  • Disabled Snowflake API Integrations

    Shows API integrations that are disabled

  • Snowflake Orphan Custom Roles

    Shows custom roles that are not assigned to any user

Explore the full Snowflake governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern