Snowflake connector
Discovery, enforcement (including Dynamic Data Masking), access intelligence, migration import and grant drift.
Before you start
- A dedicated service user and role for Trinitis.
- Authentication by service-account user and password, or key-pair.
- Enterprise Edition if you want Trinitis to enforce column masking.
- An administrator who can create users and roles and run the grants below.
What Trinitis reads
- Database, schema, table, view and column metadata
- Existing roles and grants
- Query history from the SNOWFLAKE database, for access intelligence and migration import
Trinitis stores metadata only. It never copies data values out of Snowflake.
What Trinitis writes
- Tags and masking policies in a GOVERNANCE.PUBLIC schema
- Grants and role membership for approved policies
- Platform groups (roles), using SECURITYADMIN
Trinitis writes only policies you have approved, into Snowflake's own native controls.
Required privileges
Grant only what you need for the capabilities you plan to use.
Discovery
- USAGE ON WAREHOUSE <warehouse>
- USAGE ON DATABASE <database>
- USAGE ON SCHEMA <schema> (each governed schema)
- SELECT ON ALL TABLES / FUTURE TABLES
- SELECT ON ALL VIEWS / FUTURE VIEWS
- USAGE ON ALL FUNCTIONS / FUTURE FUNCTIONS
- READ ON ALL STAGES / FUTURE STAGES
Access intelligence and migration import
- IMPORTED PRIVILEGES ON DATABASE SNOWFLAKE
- ENABLE_UNREDACTED_QUERY_SYNTAX_ERROR = TRUE
Optional — lower access-intelligence latency
- MONITOR ON WAREHOUSE <warehouse>
Enforcement (Enterprise Edition)
- A GOVERNANCE.PUBLIC schema with CREATE TAG and CREATE MASKING POLICY
- Account-level APPLY MASKING POLICY
- Account-level APPLY TAG
Platform groups
- SECURITYADMIN
About the SELECT privilege
This platform exposes no metadata-only option, so the SELECT privilege that reveals column metadata is the same privilege that can read rows. Trinitis reads only schema and column metadata and stores no row values, but the credential is capable of reading data and should be evaluated on that basis.
See Security for how this compares across platforms.
Steps
- Create the Trinitis service user and role, and grant the privileges above for the capabilities you want.
- Sign in at app.trinitis.ai and open Connections → Add Connection → Snowflake.
- Enter the connection details for the service user, authenticating with a password or key-pair.
- Click Test Connection. A green banner means Trinitis has full visibility; a yellow banner means access is limited and lists the privileges to add.
- Click Scan Now. Discovered objects appear under Resources, with sensitive columns tagged automatically from their names.