The cloud warehouses offer the same three layers, role-based grants, row filters and column masks, as named policy objects that can be reused across tables (from documentation, not run here):
| Platform | Roles and grants | Row filters | Column masking |
|---|---|---|---|
| Snowflake | Role hierarchy, GRANT ... TO ROLE | Row access policies | Masking policies (Enterprise edition up) |
| BigQuery 1 | Cloud IAM on datasets and tables | CREATE ROW ACCESS POLICY | Policy tags, dynamic data masking |
| Redshift 24 | RBAC roles | CREATE RLS POLICY, attached to roles | Masking policies with priorities |
| Databricks 2,717 | Unity Catalog grants | SET ROW FILTER function | SET MASK function, tag-based ABAC |
| Fabric Warehouse | Workspace roles, T-SQL grants | Security policies (T-SQL RLS) | Dynamic data masking |
BigQuery's form shows the shared idea: CREATE ROW ACCESS POLICY apac_filter ON dataset1.table1 GRANT TO ("group:sales-apac@example.com") FILTER USING (region = "APAC"). Grant to groups from the identity provider, never to individuals, and audit who can change policies, since that right is equivalent to reading everything.