Loading
Prepare for Email to Become the Default Login ExperienceRead More
About Salesforce Data 360
Plan Your Snowflake Environment for Identity Boost

Plan Your Snowflake Environment for Identity Boost

Before accepting identity boost collaboration invitations, decide how to isolate customer data in your Snowflake account and which region to use. These decisions affect the architecture of every collaboration that you accept, so make them before you receive your first invitation.

Required Editions

Available in: Enterprise Edition (home org)
You can’t receive or accept collaboration invitations in Developer Edition.

Choose a Multitenant Isolation Model

If you're collaborating with multiple consumers, choose how to isolate each consumer's data in your Snowflake environment. Choose one of these two isolation models.

Feature Object per Tenant (OPT) Account per Tenant (APT)
Isolation boundary Separate database and schema within one Snowflake account for each customer Separate Snowflake account per customer
Security guarantee Depends on role-based access control (RBAC) configuration Hard platform boundary — not dependent on RBAC
Operations overhead Lower — one account, one job deployment Higher — separate account, job deployment, and security integration per customer
Recommended for Partners with a mature Snowflake RBAC practice Partners with regulated-industry customers or strict data isolation requirements
Note
Note In the Object Per Tenant model, your enrichment job runs at the account level. A misconfigured role can expose another customer's data to the enrichment job. If you use this model, scope each customer's enrichment job execution role strictly to that customer's database and schema, and never use ACCOUNTADMIN or SYSADMIN roles for enrichment job execution.

Choose a Snowflake Account Region

When your Snowflake account is in the same AWS region as a consumer's Data 360 instance, Data 360 uses Snowflake's zero-copy sharing for the data share, which doesn't consume Data 360 credits. If the regions differ, Data 360 physically replicates the data and consumes Data 360 credits.

When you receive an invitation, the Consumer Salesforce Region field on the Accept Clean Room Collaboration Invitation wizard shows the consumer's region. Use that value to confirm that your account is in a compatible region before you accept.

If you serve customers across multiple regions, provision one Snowflake account per region to avoid cross-region data transfer fees. If you maintain a single account, AWS US-east-2 (Ohio) is compatible with all US-based Data 360 regions.

 
Loading
Salesforce Help | Article