How to govern Sprawl in Snowflake
A step-by-step guide to governing Sprawl in Snowflake with Rencore: detect, review by owner and severity, and remediate with an audit trail.
Governing Sprawl in Snowflake means finding where it goes wrong, reviewing the findings by owner and severity, and remediating with an audit trail. Rencore covers this concern for Snowflake with the pre-built controls below, so it becomes a repeatable check rather than a one-off cleanup. The steps that follow apply the same detect, review, remediate loop to Sprawl.
Steps
-
Inventory Snowflake
Connect Snowflake and let Rencore build a continuous inventory of its resources, owners, and configuration, so governance starts from what exists rather than a stale export.
-
Detect with policies
Turn on the pre-built policies that cover Sprawl in Snowflake to surface oversharing, sprawl, and misconfiguration on the first scan, before writing a single custom rule.
-
Review by owner and severity
Use the Snowflake reports to review findings by owner, category, and severity, and to share them with stakeholders who do not have a seat in the platform.
-
Remediate and automate
Apply automations to fix findings at scale, route sensitive changes through approvals, and keep every action reversible and logged for the audit trail.
Snowflake controls for Sprawl
Grounded in the Rencore catalog. See the full Snowflake catalog on the Snowflake connector page.
-
Snowflake users not logged in for 90+ days
Detects active users who have not logged in for over 90 days
Severity: Medium -
Suspended Snowflake warehouses
Detects warehouses that are currently suspended and may be unused
Severity: Low -
Disabled Snowflake API integrations
Detects API integrations that are disabled and may be obsolete
Severity: Low -
Disabled Snowflake notification integrations
Detects notification integrations that are disabled and may be obsolete
Severity: Low -
Disabled Snowflake catalog integrations
Detects catalog integrations that are disabled and may be obsolete
Severity: Low -
Snowflake orphan custom roles
Detects custom roles that are not assigned to any user
Severity: Low -
Snowflake transient databases
Detects transient databases (no Fail-safe) that may be forgotten scratch space
Severity: Low -
Disabled Snowflake Users
Shows Snowflake user accounts that are disabled
-
Suspended Snowflake Warehouses
Shows warehouses that are currently suspended
-
Disabled Snowflake API Integrations
Shows API integrations that are disabled
-
Snowflake Orphan Custom Roles
Shows custom roles that are not assigned to any user