Skip to main content

Query redaction for Snowflake

Connect docs via MCP

By default, Atlan stores the SQL text it extracts from Snowflake exactly as written at source. That text can contain literal values from your business data, such as email addresses in a WHERE clause or account numbers in a view definition.

Query redaction replaces those literal values with placeholders before Atlan stores them. Redaction runs in memory while the workflow extracts data, so the original values aren't written to Atlan's storage or sent outside your environment. Query structure, table references, and column references are preserved, so lineage is unaffected.

Redaction is off by default. You opt in per workflow using the Redact SQL Text option.

Enable redaction

Redact SQL Text is a separate option on each workflow, so you can enable it for the crawler, the miner, or both.

WorkflowWhere to find itSupported connection types
Snowflake crawlerConfigure crawler screenDirect connections only, using either Information Schema or Account Usage
Snowflake minerConfigure miner screenBoth direct connections and Secure Agent
Crawler redaction requires direct connection

On the crawler, Redact SQL Text has no effect when the connection uses the Agent extraction method. The option still appears in the form, but the workflow ignores it and stores SQL unredacted. If you crawl Snowflake through a Secure Agent and need redaction, enable it on the miner, which supports both connection types.

Changing this option applies to future runs only. See Limitations.

What Atlan redacts

Redaction applies to the columns that carry SQL text for each workflow.

WorkflowRedacted content
CrawlerView definitions, function and UDF definitions, stored procedure bodies, semantic view definitions, semantic fact, metric, and dimension expressions, and pipe COPY statements
MinerQuery history text from SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY

Within that text, Atlan replaces:

  • String literals with '<REDACTED:STRING>'.
  • Numeric literals with 1. Atlan substitutes a valid number rather than a text placeholder so that the redacted SQL remains parseable.

Atlan also removes comments from redacted SQL and reformats the statement, so stored text won't match the original layout.

Values Atlan preserves

Some literals are safe to keep and can break the SQL if replaced, so redaction preserves them:

  • Date and time literals, such as '2026-01-01' or '2026-01-01 14:30:00'.
  • Month and weekday names, and date part keywords such as MONTH or QUARTER.
  • Currency codes, such as 'USD'.
  • Boolean words: TRUE, FALSE, YES, and NO.

Everything else is treated as potentially sensitive and redacted.

Before and after

A query extracted by the miner:

-- monthly EMEA revenue check
select order_id, customer_email
from analytics.public.orders
where region = 'EMEA' and order_total > 500.75
and created_at >= '2026-01-01' and currency = 'USD';

The same query as Atlan stores it with Redact SQL Text enabled:

/* redacted: true, hash: 1234567890, redacted_hash: 9876543210 */
SELECT
order_id,
customer_email
FROM analytics.public.orders
WHERE
region = '<REDACTED:STRING>'
AND order_total > 1
AND created_at >= '2026-01-01'
AND currency = 'USD'

Note the following:

  • 'EMEA' was replaced, while the date and the currency code were preserved as allowlisted values.
  • 500.75 became 1. Redaction indicates that a number was present, not what it was.
  • The comment was removed and the statement was reformatted.
  • Atlan adds a header comment recording that the text was redacted, along with fingerprints of the original and redacted statements. The fingerprint values differ for every statement.
  • analytics.public.orders, order_id, and customer_email are unchanged, which is why lineage still resolves.

What redaction preserves

Redaction only changes literal values. Because everything Atlan uses to build relationships stays intact, enabling redaction doesn't change:

Limitations

Review these before you rely on redaction for a compliance requirement.

Redaction isn't retroactive. It applies only to SQL that Atlan extracts after you enable the option. SQL text already stored in Atlan from earlier runs stays unredacted. To remove it, work with Atlan support.

SQL that Atlan can't parse is stored unredacted. Redaction works by parsing each statement. When parsing fails, Atlan stores the original statement and marks it with a /* redacted: false, reason: parse_error, ... */ header comment instead of dropping it. Dynamic SQL, statements wrapped in EXECUTE IMMEDIATE, and procedure bodies written in other languages are the most common cases. If your compliance requirement is that no unredacted SQL can be stored, treat this as a gap and raise it with Atlan support.

Redaction increases workflow runtime. Every statement is parsed and rewritten. Expect crawler and miner runs to take longer, and account for this if a workflow already runs close to its schedule interval. If you enable redaction on a Secure Agent, Atlan recommends assigning at least 4 CPU cores to the agent.

Enabling redaction rewrites stored SQL. Because the stored text changes for every asset, the first run after you enable the option updates SQL text across the connection.

See also