Data GovernanceCommand Center
Snowflake NativeZero Data MovementLive MetadataVisual LineagePolicy AutomationLeast-Privilege AccessSnowflake NativeZero Data MovementLive MetadataVisual LineagePolicy AutomationLeast-Privilege Access
Stop guessing. Start governing.

Know ExactlyWhat's Happening InsideYour Snowflake Data

Discover risk, trace lineage, enforce policy, and prove control coverage with one live view of your Snowflake governance posture.

Launches from Snowsight · No separate password · No data copied
Snowflake Native Zero data movement Role-aware access

Put least-privilege access into practice

Create and manage users and account roles, grant or revoke role relationships and object privileges, and review access from one governed workspace.

RBAC, UBAC, privilege grants, and access reviews

Protect sensitive data with native policies

Create and apply Snowflake masking, row access, projection, aggregation, and join policies with the required primitive and privilege visible before execution.

Reusable, role-aware protection at the data layer

Find sensitive data and keep it classified

Run classification on tables and views, create reusable classification profiles, and automatically apply recommended system tags to discovered sensitive data.

Manual classification, profiles, inclusion, and exclusion controls

Turn metadata into enforceable governance

Create governed tags and allowed values, assign tags to objects or columns, add governance comments, and bind masking policies directly to tags.

Consistent tags, ownership context, and policy binding

Route sensitive data to accountable owners

Review classified columns, steward contacts, and masking coverage in one queue, then assign data stewards and access approvers to the right objects.

Contact catalog, assignments, and protection decisions

See impact before you change data

Trace native Snowflake lineage upstream or downstream at object and column level, control traversal distance, and connect external OpenLineage paths.

Native GET_LINEAGE plus connected external lineage

Measure data quality continuously

Create Data Metric Function associations, define expectations and schedules, and review current measurements and pass/fail results from a live visualization board.

DMF coverage, latest values, expectations, and schedules

Prioritize the security work that matters

Bring violations, detections, scanner coverage, sensitive-data controls, authentication readiness, and AI security posture into one operational view.

Current findings, severity context, and control coverage

Strengthen every path into Snowflake

Create network rules and policies, enforce MFA and authentication policies, and manage account password and session controls through explicit Snowflake actions.

Network, MFA, authentication, password, and session policy controls

Share governed data without losing control

Promote secure views, create shares, grant approved objects, add consumer accounts, and preserve governance context with share comments.

Secure views and controlled cross-account sharing

Govern who can use Snowflake AI

Grant AI Functions through approved roles, manage Cortex database-role access, revoke it when needed, and use allowed tags to constrain AI-enabled data.

Role-based Cortex access and AI allowed-tag controls
Platform

Everything your data team needs.

Governed operationsExecute Snowflake-native controls with primitives and required privileges shown first.

End-to-end lineageTrace upstream, downstream, column, and connected external data movement.

Continuous assuranceMonitor data quality, Trust Center findings, and protection coverage.

Solutions

Built for your whole organization.

Governance teamsClassification, ownership, stewardship, quality, and policy workflows.

Security teamsAccess reviews, masking, authentication policy, and risk findings.

Data engineeringImpact analysis and dependable lineage before every change.

Enterprise security

Secure by architecture.

Zero data movementGovern metadata where it already lives—in your Snowflake account.

Native OAuthAuthenticate with Snowflake and keep access bound to the approved role.

Explicit privilegesEach operation identifies its Snowflake primitive and required privilege.