Service User Privilege Requirements
ALTR’s setup stored procedure grants the following privileges to the service user’s role. If you create a custom service user and role instead of running the stored procedure, grant these privileges manually.
| Privilege | Level | How ALTR’s service user uses this privilege |
|---|---|---|
APPLY MASKING POLICY | Account | Apply masking policies to columns and tags for data masking, decryption, and detokenization. |
APPLY ROW ACCESS POLICY | Account | Apply Row Access Policies to tables and views. |
APPLY TAG | Account | Assign tags to columns during Snowflake Native classification and automatic tagging, and identify which databases and warehouses ALTR can see. |
CREATE DATABASE | Account | Create the ALTR_DSAAS_DB utility database, which houses the objects ALTR needs for access control and data protection. |
CREATE INTEGRATION | Account | Create the API integration used for real-time policy decisions, detokenization, decryption, and query audit log generation. |
MANAGE GRANTS | Account | Manage access to Snowflake objects (database, schema, table) for Access Management Policy. |
PROGRAMMATIC AUTHENTICATION METHODS (modify) | User | Rotate the service user’s own key pair. |
CREATE ROW ACCESS POLICY | Database | Create Row Access Policies within a database. |
CREATE SCHEMA on database | Database | Create the ALTR_DSAAS schema, where masking and Row Access Policy objects are stored. |
CREATE TAG on schema | Database | Save Snowflake Native classification results as object tags, and create new tags during automatic tagging. |
SELECT on tables, views, and materialized views | Database | Identify columns for masking and Row Access Policy, and sample data for classification. |
USAGE on database | Database | Base access required to identify databases in the Snowflake account. |
USAGE on schema | Database | Identify schemas for classification, tagging, Row Access Policy, and column-based masking. |
IMPORTED PRIVILEGES on the SNOWFLAKE database | Account | Read Snowflake’s QUERY_HISTORY view to generate query audit logs. |
MONITOR on warehouse | Warehouse | Read query history for all queries executed on a warehouse, to generate query audit logs. |