What was said
What this says
Current to 10 Oct 26Nadia Osei, IT Security Lead, confirmed in the second review session that SSO and SCIM are Enterprise only, so Growth has manual leaver removal. Several answers remain open and she gave no sign-off date.
What happened: Hannah Lowe walked Nadia Osei through access control. She confirmed that SSO and SCIM are not available on Growth and that leavers are removed manually by an admin.
Customer view: Nadia said capacity providers expect named accounts tied to the identity provider. She wants two labelled positions, Growth today and Enterprise, and will not give a sign-off date until providers have seen the pack.
Commercial: Hannah described the Enterprise gap and the upgrade without pressing it. The review is a real driver for Enterprise, but Nadia is treating the gap and the sale as separate.
Watch: Ten open items remain, including MFA enforcement, log retention, role change logging and the number of admins. Unanswered items could stall the review.
Themes
Current to 9 Oct 26Who was there
BB-Demo
Them
Follow-up
Next steps
Current to 9 Oct 26- Hannah Lowe to send the covering email listing provider documents, the two-position description and the compensating control wording.
- Hannah Lowe to get answers from the security lead on MFA, log retention, role change logging and connector credentials.
- Hannah Lowe to get the admin count from Daniel Okafor for the follow-up.
Risks
Current to 9 Oct 26- Growth has no SSO or SCIM, and leavers keep access until an admin removes them manually.
- Ten open items, including MFA enforcement and log retention, are unanswered and could delay sign-off.
- Nadia Osei gave no sign-off date and waits on the capacity providers.
Opportunities
Current to 9 Oct 26- Moving to Enterprise would bring SSO and SCIM and close the leaver gap the capacity providers care about.
- A clear two-position write-up could support an upgrade case without a hard sell.
Transcript
- Hannah Lowe NoneMorning, Nadia. Can you hear me alright?
- Nadia Osei NoneGood morning, Hannah. Yes, clearly. Can you hear me? My headset has been temperamental this week.
- Hannah Lowe NoneLoud and clear. How was the weekend that wasn't, I mean, how's the week ended up?
- Nadia Osei NoneHa. Fine, thank you. Rather a lot of questionnaires, I imagine similar to yours. Shall I begin with the open items from last time?
- Hannah Lowe NonePlease do. I've got my copy next to me.
- Nadia Osei NoneThank you. From session one I have five. One, the written statement on the model path. Two, confirmation of what operational information BB-Demo receives. Three, the backup wording. Four, the enlarged key on the diagram. Five, support access, which was deferred to today. I received the revised diagram and the table of responsibilities, and the key is larger, so item four is closed.
- Hannah Lowe NoneGood. On one to three, I did get answers, and they're in the document I sent over earlier this week. Would you like me to take them in order, or would you rather read them first and come back with questions?
- Nadia Osei NoneI've read them, and I have questions, but I'd like them walked through so they're on the recording. I can't sign off a control on a verbal answer, but I want the verbal answer to match the paper.
- Hannah Lowe NoneThat's sensible. So, the model path. The short answer is that the processing stays within the boundary described in the note, and the longer answer is in the note itself, which I'd ask you to treat as the authority rather than anything I say now. I'm going to read you only what the note says, so there's no drift.
- Nadia Osei NonePlease. And I'd ask that you say so if there is anything the note doesn't cover.
- Hannah Lowe NoneOf course. The note describes what is sent, where it's processed, and what is retained. It's explicit about the retention part. What it doesn't cover is the detail of the model provider's own internal arrangements, which are described in the provider's documentation rather than ours. I've said that in the note, because I'd rather you see the limit of what we can evidence.
- Nadia Osei NoneThat's the correct approach, though it does mean I will need the provider's documentation in the pack. Can you tell me which documents to request?
- Hannah Lowe NoneI'll list them by name in a covering email and I'll put that in writing today, so you have it before the next session.
- Nadia Osei NoneThank you. Items two and three?
- Hannah Lowe NoneTwo is counts and status, so whether a connector loaded and how many records were indexed. Not the content. That's confirmed by our security lead. Three, backups, is as I said last time. The data and the index are objects in your account, so recovery depends on your Snowflake configuration. We hold the deployment definition and can redeploy. We don't hold a copy of your content.
- Nadia Osei NoneGood. I'll close two and three subject to receiving them as signed statements rather than as a note. I'll need that in the questionnaire as a formal response.
- Hannah Lowe NoneUnderstood, I'll get the statements on the right template. Shall we go on to access control? That's today's subject, and I know SSO is the one you've been waiting for.
- Nadia Osei NoneIt is, yes. Let me put my numbered questions again. One, how do individual users authenticate. Two, how are roles defined and who can change them. Three, what happens when someone leaves. Four, can you evidence who asked what, and when. Five, and I suspect this is the sensitive one, what is the position on single sign-on at the tier we are currently on.
- Hannah Lowe NoneRight, thank you. Straight to the last one first, because it shapes the rest, and I'd rather be direct. Single sign-on and SCIM provisioning are part of the Enterprise tier. On Growth, which is where you are today, accounts are managed in the brain directly. So no, you don't have SSO today.
- Nadia Osei NoneThank you for being direct. That does matter, because our capacity providers expect named accounts to be tied to our identity provider. May I ask what the position is for leavers on Growth?
- Hannah Lowe NoneTo be precise, it's a manual step. Someone with the admin role removes the user. There's no automatic de-provisioning from your identity provider, because that's what SCIM does, and that arrives with Enterprise.
- Nadia Osei NoneUnderstood. So today a leaver continues to have an account until an administrator removes it. How many administrators do you have in the brain at present?
- Hannah Lowe NoneI don't have the figure in front of me, and I'd rather not guess. I'll ask Daniel Okafor, who looks after the account, and put it in the follow-up. It's a fair question, because the number of admins and who they are is part of the control.
- Nadia Osei NonePlease. For the audit trail, I need to be able to say who holds that role.
- Hannah Lowe NoneYes. Now let me answer your first question properly, authentication. On Growth, users sign in to the brain with credentials managed in the brain. On Enterprise, they would sign in through your identity provider, and you control the multi-factor policy there, which I think is the main attraction for you.
- Nadia Osei NoneIt is. May I ask about multi-factor authentication on Growth, where there is no identity provider? Is it enforced, or is it optional?
- Hannah Lowe NoneI'm going to stop there, honestly, because I don't want to overstate it. I know what the product does by default, but I'm not certain I can state the enforcement position for the tier as a control. I'll check with our security lead and put the answer in the pack. I'd rather say that than hand you something you can't rely on.
- Nadia Osei NoneThat's acceptable, and I would add it as open item six. Please can you also tell me whether the answer differs by tier?
- Hannah Lowe NoneYes, I'll cover both tiers in the same answer so you can see them side by side.
- Nadia Osei NoneThank you. Roles, then. Question two.
- Hannah Lowe NoneSo there are a small number of roles in the brain, and then there's the underlying Snowflake layer, which is yours. I want to keep those two apart, because people blur them. The brain's roles decide what a person can do in the brain, so who can see which pages, who can build dashboards, who administers connectors. The Snowflake roles decide what the brain's service can read in your account at all. The second sets the outer limit, and the first works inside it.
- Nadia Osei NoneThat's a helpful framing. So if my team restricts a table in Snowflake, the brain cannot show it, regardless of what a brain role says?
- Hannah Lowe NoneThat's the design, yes. Access you haven't granted to the brain's service is not something a brain role can create. I'll document that with an example, because it's the sort of statement that's much stronger with a worked case.
- Nadia Osei NonePlease use something from our own world. Submissions with restricted claims information, for example, where only some people should see them.
- Hannah Lowe NoneGood, I'll use that. I'll need to be careful about it not looking like we've seen your real data, so I'll describe it generically, a table of claims information that your team has chosen to restrict.
- Nadia Osei NoneQuite right. Who can change a role? That was the second half of question two.
- Hannah Lowe NoneAdmins in the brain. Which comes back to the number of admins, and to the point that on Growth it's a manual process with no approval workflow around it. That's something I'd say plainly in the pack rather than leave you to find. If you want a record of role changes, that's your fourth question, the logging.
- Nadia Osei NoneYes, go on. What is logged, and for how long?
- Hannah Lowe NoneThe questions people ask are recorded, that's how we measure usage. What I can't give you from memory is the retention period, nor whether role changes are logged in the same place. I'll put both as questions to our security lead. Don't let me gloss that.
- Nadia Osei NoneI won't. So item seven, retention period and the scope of the log. And item eight, whether role changes appear in it. I'll write them down.
- Hannah Lowe NoneThanks. While you write, I'll say one thing about the Enterprise side, so it's on the record. Moving up would bring SSO and SCIM, which closes the leaver gap and ties authentication to your identity provider. It also brings an executive sponsor on our side. I'm not telling you that to sell, only because it answers the gap I've just described.
- Nadia Osei NoneI understand, and I'm grateful that you described the gap before the solution. I'm treating them as separate things. The gap exists today on Growth, and the review should say so.
- Hannah Lowe NoneAgreed. It will say so.
- Nadia Osei NoneNow, a question about timing, because the business keeps asking. If SSO is the control our capacity providers want, does the review wait on the upgrade?
- Hannah Lowe NoneThat's your call and your capacity providers' call, not mine. What I can do is describe the control as it stands today and as it would stand under Enterprise, as two clearly labelled positions. Then you can show them whichever is relevant, or both.
- Nadia Osei NoneTwo positions would be the most honest presentation. I'll ask for that. And for the avoidance of doubt, I still won't give a date for sign-off until the providers have seen the pack.
- Hannah Lowe NoneUnderstood. I haven't asked for one. Daniel mentioned the end of the year as the timeline on our side, but that's a commercial plan, and I'd keep it separate from your review.
- Nadia Osei NoneGood. I'll keep it separate too. Right, back to leavers. Is there anything between manual removal and SCIM, like a report of inactive users, that I could use as a compensating control until we decide?
- Hannah Lowe NoneThat's a smart thing to ask. I'm not certain that exists as a report, and I'm not going to claim it does. What I can offer is that your admins can see the list of users, so a periodic review against your leavers list is possible, and I can describe that as a procedure. It isn't automatic, though, and I'd label it as a manual compensating control.
- Nadia Osei NoneA manual compensating control, clearly labelled, is something I can work with. Please add a sample frequency suggestion if you're comfortable, but make it a suggestion, not a requirement.
- Hannah Lowe NoneI'll suggest it without prescribing it. Is there anything else on access?
- Nadia Osei NoneOne last point, on service accounts. The connectors, the brain's own service. What credentials do they use to read our source systems, and where are they kept?
- Hannah Lowe NoneAnother one I want to answer in writing, because it touches how secrets are stored. I'll bring it to the next session with the answer from our security lead, rather than give you half of it now.
- Nadia Osei NoneItem nine. Thank you. Let me read back the open items, so we agree what is outstanding.
- Nadia Osei NoneCarried from session one, one to three, awaiting signed statements. New from today, six, multi-factor enforcement by tier. Seven, log retention and scope. Eight, whether role changes are logged. Nine, connector credentials and where they're kept. And the number of admins, which I'll call ten. Have I missed anything?
- Hannah Lowe NoneNo, that matches mine. I've also got the covering email listing the provider documents, the two-position description of access control, and the compensating control wording. I'll send all of that, with the open items marked as pending where I don't yet have answers.
- Nadia Osei NoneThank you. Session three, next Friday?
- Hannah Lowe NoneNext Friday, yes. I'll confirm the topic by email so you can pass it to whoever else needs to join. Thanks for your patience on the ones I couldn't answer today, Nadia.
- Nadia Osei NoneNot at all, that's what makes the pack usable. Kind regards, Hannah. Speak next week.
- Hannah Lowe NoneThanks, Nadia. Bye for now.