Skip to main content
This guide contains the necessary steps to connect a Snowflake environment to your Elementary account.

Create a user for Elementary cloud

  • Please create a Snowflake key-pair (private and public key) using this guide.
  • Using the public key generated in the previous step, please run the following in your dbt project folder:
This command will generate a query to create a user with the necessary permissions. Run this query on your data warehouse with admin permissions to create the user.

Permissions and security

Elementary Cloud doesn’t require read permissions to your tables and schemas, but only the following:
  • Read-only access to the Elementary schema.
  • Access to read metadata in INFORMATION_SCHEMA (table metadata and query history), related to the tables in your dbt project.
It is recommended to create a user using the instructions specified above to avoid granting excess privileges. For more details, refer to security and privacy.

Grant permissions to monitor dynamic tables

To monitor Snowflake dynamic tables, Elementary needs the MONITOR privilege on those dynamic tables, granted per database.
This privilege isn’t included in the roles granted during user creation. Grant it separately for each database containing dynamic tables you want Elementary to monitor.
Run the following in a Snowflake worksheet with admin permissions. Set databases to the list of databases containing the dynamic tables you want Elementary to monitor, and elementary_role to your Elementary role name:

Fill the connection form

Provide the following fields:
  • Account: Find your account by using the Snowflake account URL and removing snowflakecomputing.com. e.g. example.us-east-1. For more information, see Account Identifiers in the Snowflake docs.
  • Database name: The name of the database where your Elementary schema exist. e.g. analytics.
  • Warehouse: e.g. ELEMENTARY_WAREHOUSE.
  • Elementary schema: The name of your Elementary schema. Usually [schema name]_elementary.
  • Role (optional): e.g. ELEMENTARY_ROLE.
Elementary Cloud supports the following authentication methods:
  • Key pair (Recommended):
    • User: The user created for Elementary.
    • Private key: The private key you generated for Elementary. For more information, see Generate Private Key in the Snowflake docs.
    • Private key passphrase (optional)
  • User password (Deprecated, not recommended):
    • User: The user created for Elementary.
    • Password: The password you set when creating your Snowflake account.
Snowflake are in the process of deprecating single-factor username & password authentication for all human users. As a result, while still supported, we recommend configuring the user in advance using key-pair authentication rather than username & password, and configuring the user as TYPE=SERVICE (this is automatically handled in the user creation macro above).See here for more information regarding this change.

Add the Elementary IP to allowlist

If you use network policies to restrict access, run this query on your data warehouse with admin permissions:
After creating a network policy you would need to activate it. To activate a network policy for the elementary user simply run the following command -

Need help with onboarding?

We can provide support on Slack or hop on an onboarding call.