Immuta
Compare with…Immuta manages access policies in supported analytics platforms. Enforcement differs by integration, so a Snowflake masking policy should not be assumed to work identically in BigQuery or S3. [1]
Discovery & classification and Access governance [1]
Updated 5 sources
Store and control evidence
Read each documented action together with its limits.
Classify Snowflake data
Immuta runs regex and dictionary identification queries in Snowflake, returning column names and matching identifiers without raw values. Column-name identification uses metadata held in Immuta. [5]
Content identification generally covers text columns, with documented date and time exceptions. Competitive identifiers require a 90% sample match and queries time out after 15 minutes by default. Test sparse sensitive values and complex views. [5]
Mask sensitive columns in Snowflake
Immuta administers native Snowflake column-masking and row-access policies on registered objects. Users query Snowflake directly and receive policy-controlled results. [4]
The integration requires Snowflake Enterprise. User mapping and policy sync must be configured. Listed excepted users and roles bypass Immuta policies. Include those identities and views in the acceptance test. [4]
Data coverage
Read the scope beside each mark. Support for an environment does not establish every capability in every store.
- Microsoft 365
- Unconfirmed
- AWS
- Partial
Redshift uses policy-enforced views. S3 supports subscription policies but the comparison table does not list data-policy enforcement. [1]
- Google Cloud
- Partial
BigQuery uses policy-enforced views. The integration matrix limits sensitive-data discovery to column-name identification. [1]
- Snowflake and Databricks
- Full
Snowflake and Databricks integrations support native access policies. Verify feature parity for your integration mode. [1]
- On-prem shares
- Unconfirmed
- SaaS apps
- Unconfirmed
Unconfirmed means the reviewed sources do not establish coverage. How coverage is assessed
Deployment and cost
How it runs
In Snowflake, Immuta administers native row-access and column-masking policies on tables. [2] [3] [4]
- Query path
- Users query Snowflake directly while those policies are enforced.
- Connection setup
- The integration requires Snowflake Enterprise. An Immuta application administrator registers the connection. The Snowflake setup user needs CREATE DATABASE, CREATE ROLE and MANAGE GRANTS with grant option.
- Retained system access
- The generated script grants the system account CREATE ROLE, MANAGE GRANTS, APPLY MASKING POLICY and APPLY ROW ACCESS POLICY with grant option. Scope source USAGE and REFERENCES to the registered objects.
- Content access
- SELECT is required for identification or specialized masking that uses fingerprinting. Iceberg and external tables need grants for their own object types.
Pricing and operating workload are not published in the reviewed sources.
Questions for the vendor
- Show masking and row filtering through every query path used by your applications.
- What privileges remain after initial integration and how are policies removed safely?
- Measure warehouse compute and query latency with your actual policy set.