How to govern Snowflake
A step-by-step guide to governing Snowflake with Rencore: detect with 43 policies, review with 10 reports, and remediate with 1 automations.
Governing Snowflake means keeping its access, configuration, and lifecycle under continuous control rather than reacting after something breaks. Rencore governs Snowflake with 43 pre-built policies, 10 reports, and 1 automations, so teams can detect risk, review posture, and remediate with an audit trail. The steps below turn that coverage into a repeatable routine.
Steps
-
Inventory Snowflake
Connect Snowflake and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Snowflake to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Snowflake reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Recommended Snowflake policies
Grounded in the Rencore catalog. See the full Snowflake catalog on the Snowflake connector page.
-
Snowflake user is active
Active users are live identities that can authenticate, raising the likelihood that a weakness is exploited
Severity: Medium -
Snowflake warehouse is running
Running (STARTED) warehouses are in active use, raising the likelihood that a weakness manifests
Severity: Medium -
Snowflake stage is external
External stages are internet-facing data paths, raising the likelihood that a weakness leads to exfiltration
Severity: Medium -
Snowflake network policy is unrestricted
Unrestricted network policies expose a wide-open surface, raising the likelihood that a weakness is reachable
Severity: Medium -
Disabled Snowflake users with role grants
Detects disabled users that still have role grants assigned
Severity: High -
Snowflake users without MFA
Detects active users that do not have multi-factor authentication enabled
Severity: High -
Snowflake users not logged in for 90+ days
Detects active users who have not logged in for over 90 days
Severity: Medium -
Snowflake account with too many role grants
Detects accounts with more than 10 role grants
Severity: Medium -
Snowflake external volumes that allow writes
Detects external volumes configured to allow writes to external storage
Severity: Medium -
Snowflake stages with stored credentials
Detects stages that store inline credentials instead of using a storage integration
Severity: High -
Snowflake external stages without a storage integration
Detects external stages that do not use a storage integration
Severity: Medium -
Snowflake databases owned by ACCOUNTADMIN
Detects databases whose owning role is ACCOUNTADMIN
Severity: Medium