M ManySignal
MS
SF
Integration

Snowflake Integration

Monitor Snowflake data access for insider threats and exfiltration.

What this integration does

Snowflake meets agentic SOC

Snowflake is the enterprise data cloud where the most sensitive business data resides. ManySignal ingests Snowflake access history, login events, and query telemetry to detect anomalous data access patterns, mass exports, unusual query behaviour, and account compromise — critical for data loss prevention and compliance.

ACCESS_HISTORY ingestion for full data lineage visibility

Login and authentication event monitoring

Large result set and COPY INTO export detection

Data collected

  • ACCESS_HISTORY queries and tables accessed
  • LOGIN_HISTORY authentication events
  • QUERY_HISTORY for large result sets and exports
  • GRANT_USAGE role and privilege changes

Actions supported

  • Disable Snowflake user
  • Revoke Snowflake role from user
  • Set network policy to block IP
  • Force password reset
  • Abort running query

Getting started

Set up in minutes

  1. 1

    Create a Snowflake service account

  2. 2

    Configure the connector

  3. 3

    Set query polling interval

Snowflake Integration: frequently asked questions

Why is there a 2-3 hour delay in Snowflake access data?

Snowflake populates ACCESS_HISTORY with a 2–3 hour lag from query execution. This is a Snowflake platform constraint. Near-real-time detection is possible through login events and query events, which are available within minutes.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.