Snowflake
Rencore monitors Snowflake across 43 governance policies, 10 reports, and 22 inventories, detecting users without MFA, ACCOUNTADMIN-owned objects, unrestricted network policies, and costly always-on warehouses automatically.
Rencore Snowflake governance is a set of 43 policies, 10 reports, and 22 inventories that continuously audit Snowflake for weak authentication, over-privileged ACCOUNTADMIN ownership, unrestricted network access, and runaway warehouse cost. It detects users without MFA, objects owned by ACCOUNTADMIN, network policies with no IP restriction, and warehouses that never auto-suspend or exceed their credit budget.
See Snowflake in Rencore
Every Snowflake object Rencore discovers and inventories across your tenant.
The governance policies Rencore evaluates against Snowflake, with severity and category.
Built-in Snowflake reports and analytics views in Rencore.
Why govern Snowflake with Rencore
Enforce strong authentication
Detect users without MFA, users with password-only authentication, and service accounts using passwords. Flag open MFA bypass windows and OAuth secrets overdue for rotation before they are exploited.
Lock down privileged ownership
Find databases, warehouses, schemas, secrets, and stages owned by ACCOUNTADMIN, users defaulting to ACCOUNTADMIN, accounts with too many role grants, and orphan custom roles.
Secure network and data access
Identify network policies with no IP or network-rule restriction, outbound network rules, external stages without a storage integration, stages with stored credentials, and external volumes that allow writes.
Control warehouse cost
Flag warehouses without auto-suspend or a resource monitor, oversized running warehouses, warehouses unused in the last 30 days, high credit consumption, and databases with excessive Time Travel retention or large storage.
What Rencore discovers
Rencore automatically inventories these Snowflake object types.
How Snowflake governance works in Rencore
Rencore connects to Snowflake and inventories accounts, users, roles, role grants, warehouses, databases, schemas, network policies, network rules, password policies, secrets, stages, and integrations. Policies evaluate each object on every scan cycle and flag violations with severity and a recommended action.
The data-platform governance challenge
Snowflake stores some of the most sensitive data in the organization, yet its identity, network, and cost controls sit outside Microsoft 365 oversight. A user without MFA or a warehouse left running is invisible to Entra ID and Microsoft Purview. Rencore brings Snowflake governance into the same dashboard as your Microsoft 365 governance, applying consistent identity, access, and cost checks.
Who uses Snowflake governance
CISOs use the authentication and network policies to close data-exposure gaps. Heads of IT track ACCOUNTADMIN ownership and role sprawl. CIOs and CXOs use the warehouse cost reports to keep Snowflake credit consumption under control.
Getting started
Provide Rencore with Snowflake API access. All 43 policies activate on the first scan, covering users, roles, warehouses, network policies, and stages. Cost and usage reports populate as soon as the first inventory completes.
Policies
43 governance rules that detect violations and risks.
Need a rule that isn't listed? Rencore's Policy Builder lets you create custom policies tailored to your organization.
Reports
10 analytics views and dashboards.
Automations
1 automated remediation workflows.
Segments
12 data groupings for targeted filtering.
Frequently asked questions
What governance areas does Rencore cover?
What is Rencore governance?
How do Rencore policies work?
Related guides
Trusted by