QuestionQ129

Secure Data Sharing and Consumption

A group of Data Analysts has been assigned the ANALYST_ROLE role. They require a Snowflake database in which they can create and modify tables, views, and other objects to load with their own data. The Analysts must not be able to grant Snowflake users outside their role access to that data.

How should these requirements be fulfilled?

Explanation

Managed access schemas prevent object owners from making grant decisions. Only the schema owner or a role with the global MANAGE GRANTS privilege can grant or revoke access to objects in such a schema. Having SYSADMIN own managed access schemas while granting ANALYST_ROLE the required object-creation privileges allows analysts to create and modify their data objects without being able to grant access outside their role.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!