Datablare is a governed Snowflake MCP server: connect a Snowflake database once — with your own warehouse, role and a key-pair service user — and Claude, ChatGPT, Cursor, VS Code or Claude Code can answer questions from it through one project link. Every query is checked, runs in a session that is always rolled back, is limited to the tables and columns you choose, and is recorded.
The Snowflake-specific risks
Snowflake already has strong role-based access, but an AI agent changes the shape of the risk:
- No read-only session. A role that can write lets the agent write; autocommit makes it stick.
- Credits. An agent looping on large scans burns warehouse time you pay for.
- SYSTEM$ functions. Some cancel queries or change account state, and they run inside an ordinary
SELECT. - Over-broad roles. Connecting as a person’s default role often means
SYSADMINor worse. - Who asked? Query history shows the user, not which colleague’s question triggered the query.
How Datablare protects Snowflake
- Guard first. Only a single
SELECT,WITHorVALUESstatement is accepted. DDL, DML,SYSTEM$functions and account-identity functions such asCURRENT_ACCOUNTare refused. - Rolled-back sessions. Every connection runs with autocommit off and is rolled back before closing, so a data change cannot survive.
- Your role, your warehouse. You choose the role and warehouse Datablare uses. The connection test flags
ACCOUNTADMIN,SYSADMIN,SECURITYADMINandORGADMIN. - Tables and columns you choose. Hidden columns are refused even when named directly.
- Every query attributed. Datablare’s Audit names the person who asked, the question and the SQL; in Snowflake the same queries carry the tag
datablare.
Results pass through to the agent and are never stored. Datablare is hosted in India and helps you meet DPDP · GDPR · HIPAA · CCPA/CPRA · PDPL obligations for data your agents read. More on security and how it works.
Snowflake notes
Warehouses and roles
Warehouse and database are required; role is optional (the user’s default role otherwise) and schema is optional (every schema in the database is listed either way). Give Datablare its own extra-small warehouse with auto-suspend and a resource monitor so agent usage has a ceiling.
One database per source
A Snowflake source points at one database. Tables are listed as SCHEMA.TABLE in the case Snowflake stores them — unquoted names are upper case. For a query with bare names, Datablare opens the session on the schema those names were matched in. Need two databases? Add two sources.
Key-pair sign-in
Key pair is the default and recommended option: create a TYPE = SERVICE user with an RSA public key and paste the matching unencrypted PKCS#8 private key into Datablare, where it is stored encrypted. If your account uses a network policy, allow the IP shown on the setup screen.
Create a read-only login first
CREATE ROLE DATABLARE_READER;
CREATE WAREHOUSE DATABLARE_WH
WAREHOUSE_SIZE = XSMALL AUTO_SUSPEND = 60 AUTO_RESUME = TRUE
STATEMENT_TIMEOUT_IN_SECONDS = 60;
CREATE RESOURCE MONITOR DATABLARE_MONITOR
WITH CREDIT_QUOTA = 20 FREQUENCY = MONTHLY START_TIMESTAMP = IMMEDIATELY
TRIGGERS ON 80 PERCENT DO NOTIFY ON 100 PERCENT DO SUSPEND;
ALTER WAREHOUSE DATABLARE_WH SET RESOURCE_MONITOR = DATABLARE_MONITOR;
GRANT USAGE ON WAREHOUSE DATABLARE_WH TO ROLE DATABLARE_READER;
GRANT USAGE ON DATABASE ANALYTICS TO ROLE DATABLARE_READER;
GRANT USAGE ON ALL SCHEMAS IN DATABASE ANALYTICS TO ROLE DATABLARE_READER;
GRANT SELECT ON ALL TABLES IN DATABASE ANALYTICS TO ROLE DATABLARE_READER;
GRANT SELECT ON ALL VIEWS IN DATABASE ANALYTICS TO ROLE DATABLARE_READER;
GRANT SELECT ON FUTURE TABLES IN DATABASE ANALYTICS TO ROLE DATABLARE_READER;
CREATE USER DATABLARE TYPE = SERVICE
DEFAULT_ROLE = DATABLARE_READER DEFAULT_WAREHOUSE = DATABLARE_WH
RSA_PUBLIC_KEY = 'paste-your-public-key';
GRANT ROLE DATABLARE_READER TO USER DATABLARE;
To keep a column out at the source, attach a masking policy or grant a view without it.
Example questions
Try them on the e-commerce sample first, then on the order and product tables in your warehouse:
- What was gross revenue by month for the last year?
- Which product categories grew fastest quarter over quarter?
- What share of revenue comes from discounted articles?
- Which customers have the highest lifetime order value?
Connect Snowflake to your AI tools
Sign up free, add your Snowflake account, and connect Claude, ChatGPT or Claude Code. See pricing for plans.