Is it possible to disable Snowflake users to view ANY metadata on other USERS or ROLES that exists?

Viewed 277

Even though it is possible to disable snowflake users from running SHOW USERS and only view their own query history, I am not able to and I even think it does not seem possible to:

  • Disable users from running SHOW ROLES & disabling them from seeing the ROLES tab in the Snowsight UI
  • Disable users from SEEING the full list of users when they use the users dropdown list in the query history tab.

Did anyone manage to accomplish this? We need this functionality as we have the need to separate some users groups from each other / they should not know of their existence and we do not want to use the organisations feature to make this possible. If this indeed is not possible we do see this as a security risk as someone having information about other users / roles potentially has more attack point info...

1 Answers

If the user is assigned a custom role then the "Roles" tab will not be displayed when the user logs in to Snowflake UI.

For the 2nd point, it is currently not possible to hide the User's drop-down or limit it to the users who are in the same privilege level or under same roles as the logged-in user.

For eg:

create role customrole;

grant customrole to newuser;

Now, login as newuser and you will not be seeing the "Roles" Tab from the UI.

Edit: P.S on new UI this is expected behavior where in the Role tab is not hidden even if custom roles are assigned to user.It is something that the team is working to change.

Related