Cloud Warehouse Access

Role-Based Access in Cloud Warehouses

The cloud warehouses offer the same three layers, role-based grants, row filters and column masks, as named policy objects that can be reused across tables (from documentation, not run here):

Access controls in the cloud warehouses
Platform Roles and grants Row filters Column masking
Snowflake Role hierarchy, GRANT ... TO ROLE Row access policies Masking policies (Enterprise edition up)
BigQuery 1 Cloud IAM on datasets and tables CREATE ROW ACCESS POLICY Policy tags, dynamic data masking
Redshift 24 RBAC roles CREATE RLS POLICY, attached to roles Masking policies with priorities
Databricks 2,717 Unity Catalog grants SET ROW FILTER function SET MASK function, tag-based ABAC
Fabric Warehouse Workspace roles, T-SQL grants Security policies (T-SQL RLS) Dynamic data masking

BigQuery's form shows the shared idea: CREATE ROW ACCESS POLICY apac_filter ON dataset1.table1 GRANT TO ("group:sales-apac@example.com") FILTER USING (region = "APAC"). Grant to groups from the identity provider, never to individuals, and audit who can change policies, since that right is equivalent to reading everything.