Simplifying Multiple Snowflake Accounts Management, Security & Governance
Simplifying Multiple Snowflake Accounts Management, Security & Governance
By Ben Herzberg | Chief Scientist
December 9, 2021
Reasons For Having Multiple Snowflake Accounts
Testing and Staging Environments
When developing software, it is important to keep a separation between development, testing, and staging environments. This is done to minimize the impact of bugs on the production environment. A part of healthy DataOps is to do the same for data infrastructure and introduce changes first on a staging environment, and only then on production.
In Snowflake, this can be achieved in several ways. Some organizations put their staging databases on the same account as their production data. This is typically done to reduce overheads in managing multiple environments. However, this is often a shortcut that comes at the expense of a more complete staging environment... having a separate account where changes are made first, and once verified, are applied to production.
Early Access
Another reason for having separate accounts... is an environment where Snowflake early access is enabled. As Snowflake is a SaaS product that continuously changes, it makes sense to take into account changes introduced by Snowflake.
Multiple Business Units
In many companies, Snowflake is used across multiple business units... Some organizations are solving these challenges within a single account. However, this is not always the case, and some organizations decide to simplify the separation, by having several Snowflake accounts and distributing them to their different business units.
Regional Accounts
For regulatory and compliance reasons, data from specific regions must be stored within a certain geographic region. Certain restrictions specific to these regions must be imposed...
B2B Multiple Accounts
Some businesses are managing data for other businesses in Snowflake. In some cases, the best way to separate the data of different customers is to use a separate account for each one of them.
Different Cost Plans
Organizations occasionally store different types of data with different requirements, where certain data may require higher account tiers.
Simplifying Account Creation With ORGADMIN
In the past, managing multiple accounts was done using support tickets. However, it is now possible to manage multiple accounts by using the ORGADMIN role. For example, to span a new account, you can use the following command:
| CREATE ACCOUNT stage2 ADMIN |
| d_NAME = stageadmin ADMIN_PASSWORD = 'Aa123456' /* not this password :) */ FIRST_NAME = stage LAST_NAME = admin MUST_CHANGE_PASSWORD = TRUE EMAIL = 'dataops@acme.corp' EDITION = standard REGION = aws_us_east_1; |
Managing Multiple Snowflake Accounts
Opening new accounts is one thing. However, managing them at scale, especially from a security, data governance, and privacy point of view, is not trivial.
| The Challenge | With Satori | Alternatives |
| Discovering Sensitive Data | Continuous discovery | |
| Data Inventory for all accounts | Periodic data classification scans | |
| Auditing & Monitoring | Audit across all data platforms | Effort when audit is actually required ETLs to prepare logs |
| Access Control | Simplified access control across any number of accounts | Orchestration, or data engineering effort |
| Distributed Data Stewardship | Simplified data stewardship including classification and authorization across accounts | Orchestration, or data engineering effort |
Discovering Sensitive Data Across Multiple Snowflake Accounts
The Challenge
Knowing where sensitive data is across accounts to place security controls and generate compliance reports.
With Satori
Satori continuously discovers sensitive data across all accounts... You can manage the classifications from a centralized location...
Alternative Solutions
An alternative may be to scan each account for sensitive data... performing periodic scans may be ineffective in a data-driven environment.
Auditing & Monitoring For Multiple Snowflake Accounts
The Challenge
You require a data access log for security and compliance reasons. This data is kept per account, adding operational overhead and complicating finding answers to security and compliance requirements.
With Satori
With Satori, all data access is logged... You can analyze the data in its entirety...
Alternative Solutions
You can do nothing different and require reporting/querying of logs in your accounts... creates significant overhead.
Access Control Across Multiple Snowflake Accounts
The Challenge
Managing access control can be challenging for multiple accounts due to varying knowledge in data engineering and security...
With Satori
Satori enables security management to be separated from the data infrastructure...
Alternative Solutions
Your data engineering team can write scripts to automate projects across accounts... distracting teams from core business value.
Distributed Data Stewardship Across Multiple Accounts
The Challenge
Distributing data stewardship across multiple accounts can create delays in data accessibility...
With Satori
With Satori, datasets can be defined for specific data stewards... applying controls without data engineering resources.
Alternative Solutions
An alternative is building your own solution or using an orchestration solution... building your own can be complicated with hidden costs.
Conclusion
Splitting your Snowflake Data Cloud to separate accounts is a valid decision. Satori provides advantages to keep your security, governance, and privacy requirements at bay without excessive data engineering resources.