Governance guide

How to govern Inventory in Snowflake

A step-by-step guide to governing Inventory in Snowflake with Rencore: detect, review by owner and severity, and remediate with an audit trail.

Definition

Governing Inventory in Snowflake means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Snowflake with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Inventory.

Steps

  1. Inventory Snowflake

    Connect Snowflake and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.

  2. Detect with policies

    Turn on the pre-built policies that cover Inventory in Snowflake to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.

  3. Review by owner and severity

    Use the Snowflake reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.

  4. Remediate and automate

    Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.

Snowflake controls for Inventory

Grounded in the Rencore catalog. See the full Snowflake catalog on the Snowflake connector page.

  • Snowflake Account

    Snowflake accounts that are configured to be scanned

  • Snowflake User

    Users with access to the Snowflake account

  • Snowflake Role

    Roles defined in the Snowflake account

  • Snowflake Role Grant

    Role grants assigned to users and roles in the Snowflake account

  • Snowflake Warehouse

    Virtual warehouses (compute resources) in the Snowflake account

  • Snowflake Database

    Databases in the Snowflake account

  • Snowflake Network Policy

    Network policies controlling IP access to the Snowflake account

  • Snowflake Cortex Search Service

    Cortex Search services that provide semantic retrieval over indexed data

  • Snowflake Schema

    Schemas contained within a Snowflake database

  • Snowflake Database Role

    Database-scoped roles defined within a Snowflake database

  • Snowflake Network Rule

    Network rules defining allowed or blocked network identifiers within a Snowflake schema

  • Snowflake Password Policy

    Password policies defining password requirements within a Snowflake schema

  • Snowflake Secret

    Secrets storing sensitive credentials within a Snowflake schema

  • Snowflake Tag

    Tags used to classify and govern Snowflake objects within a schema

  • Snowflake Stage

    Stages defining locations for loading and unloading data within a schema

  • Snowflake Pipe

    Pipes that continuously load data into tables within a schema

  • Snowflake External Volume

    External volumes referencing cloud storage locations used by the Snowflake account

  • Snowflake API Integration

    API integrations enabling the Snowflake account to call external HTTPS endpoints

  • Snowflake Notification Integration

    Notification integrations enabling the Snowflake account to send or receive messages from external queues

  • Snowflake Catalog Integration

    Catalog integrations connecting the Snowflake account to external table catalogs

Explore the full Snowflake governance catalog | All guides

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern