FAQ

Which Tables Does Sifflet Access, and How Does It Use Them?

Sifflet accesses various tables in your Snowflake account to provide a complete user experience. Restricting access to some of those databases, schemas, or tables reduces the features Sifflet can provide.

Accessed tableUsage
SNOWFLAKE.ACCOUNT_USAGE.ACCESS_HISTORY
Only for Snowflake Enterprise (or higher).
Data usage computation, SQL transformation and lineage computation
SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORYData usage computation, SQL transformation and lineage computation
SNOWFLAKE.ACCOUNT_USAGE.DYNAMIC_TABLE_REFRESH_HISTORYData usage computation, SQL transformation and lineage computation
SNOWFLAKE.ACCOUNT_USAGE.OBJECT_DEPENDENCIESLineage computation
SNOWFLAKE.ACCOUNT_USAGE.TABLESData usage computation
SNOWFLAKE.ACCOUNT_USAGE.TAG_REFERENCESRetrieving Snowflake tags
Any allowed [DB].[SCHEMA]Connection test
Any allowed [DB].[SCHEMA].[TABLE]Execution of any user-defined monitors and column-level AI suggestions
Any allowed [DB].INFORMATION_SCHEMA.TABLESEvaluate the freshness (Update Time Gap) of the tables in the defined [DB] database.

Why Do My Latest SQL Transformations or Tags Not Appear After a Refresh?

Snowflake declares a range of data latency times due to the process of extracting the data from Snowflake’s internal metadata store.

Overall, for ACCOUNT_USAGE tables, expect a latency of up to 3 hours from Snowflake. For more detailed information, see the "Data latency" section of the Snowflake Account Usage documentation.

My Snowflake Source on Sifflet Indicates That Some Permissions Are Missing, Why?

When using the Test Connection feature or when refreshing a source, Sifflet checks that required permissions are correctly configured. The Integration guide of the Snowflake page describes the required permissions.

To troubleshoot missing permissions, you can use the command SHOW GRANTS TO ROLE $role_name (or SHOW FUTURE GRANTS TO ROLE $role_name for future permissions), to check whether the role has the correct privileges on the correct objects.

You may be connected to Snowflake with your personal user, using the Sifflet role, and still be able to query objects that the Sifflet role should not have access to. This is because of the Snowflake Secondary roles feature, which adds all of the roles granted to the user to the context to determine the available permissions. If you want to run queries using only the Sifflet role, use the following query to disable the Secondary roles feature: USE SECONDARY ROLES NONE. After troubleshooting, you can run USE SECONDARY ROLES ALL to re-enable the feature.


Did this page help you?