Connect Snowflake to Black Cat SSPM
Connect your Snowflake account so Black Cat can review users, multi-factor coverage, roles and grants, network policies, authentication policies and outbound shares.
≈ 15 min · audit access · write-capable permissions are flagged below
What Black Cat reads, and why
| Permission | What it lets Black Cat do | Status |
|---|---|---|
ACCOUNTADMIN or SECURITYADMIN | Lets Black Cat review users, roles and grants, network and authentication policies, and outbound shares. The write side of this permission is not used. | Required Write (write-capable permission) |
What you'll need
- Account identifier Required — Your Snowflake account locator, for example acme-eu_west_1.
- Service username Required — The read-only Snowflake user you create for Black Cat.
- Warehouse name Required — A small warehouse the read-only user may run its queries on.
- Private key (PEM) — Optional — use it when the service user signs in with a key pair.
- OAuth client identifier — Optional — use it when the service user signs in through OAuth instead of a key pair.
- OAuth client secret — Optional — issued with the OAuth client identifier.
- OAuth token URL — Optional — the address your identity provider issues OAuth tokens from.
- Snowflake role — Optional — the role the service user takes on; it uses its own role when left empty.
Where to create it
- Setup guide (Snowflake) ↗ (opens in new tab)
- Developer documentation (Snowflake) ↗ (opens in new tab)