Skip to main content

Community

Add ability to apply snowflake tags to columns

Answered

Please sign in to leave a comment.

Comments

2 comments

    Hi John,

    Thanks for reaching out and sharing this suggestion! Handling PHI securely is very important, so I completely appreciate why you're looking for a smooth way to automate this across your tables and Quickstart views.

    Do your authorized Snowflake users actually need to view the unmasked, plain-text PHI, or are these columns primarily used for joining records / not needed for analytics at all? 

    Best,

    some snowflake users can see PHI and some cannot.  It's based on their snowflake role. 

    We use snowflake masking policies which automatically hide PHI data,  based on column tags and the user roles.   

    We have one tag that we apply to PHI columns in any database.  Users with PHI access have a special role they can use that will show PHI data.  For anyone else, the masking policies replace the actual values with blanks or hashed values.

    Our problem is if we tag columns in tables created by fivetran syncs, or views create by fivetran transformation,  those tags get lost if fivetran drops & recreates tableview when doing a resync.