Plan Your Snowflake Environment for Identity Boost
Before accepting identity boost collaboration invitations, decide how to isolate
customer data in your Snowflake account and which region to use. These decisions affect the
architecture of every collaboration that you accept, so make them before you receive your first
invitation.
Required Editions
Available in: Enterprise Edition (home org)
You can’t receive or accept collaboration invitations in Developer Edition.
Choose a Multitenant Isolation Model
If you're collaborating with multiple consumers, choose how to isolate each consumer's data in
your Snowflake environment. Choose one of these two isolation models.
Feature
Object per Tenant (OPT)
Account per Tenant (APT)
Isolation boundary
Separate database and schema within one Snowflake account for each customer
Separate Snowflake account per customer
Security guarantee
Depends on role-based access control (RBAC) configuration
Hard platform boundary — not dependent on RBAC
Operations overhead
Lower — one account, one job deployment
Higher — separate account, job deployment, and security integration per
customer
Recommended for
Partners with a mature Snowflake RBAC practice
Partners with regulated-industry customers or strict data isolation
requirements
Note In the Object Per Tenant model, your enrichment job runs at the account level. A
misconfigured role can expose another customer's data to the enrichment job. If you use this
model, scope each customer's enrichment job execution role strictly to that customer's database
and schema, and never use ACCOUNTADMIN or SYSADMIN roles for enrichment job execution.
Choose a Snowflake Account Region
When your Snowflake account is in the same AWS region as a consumer's Data 360 instance, Data 360 uses Snowflake's zero-copy sharing
for the data share, which doesn't consume Data 360 credits. If the regions
differ, Data 360 physically replicates the data and consumes Data 360 credits.
When you receive an invitation, the Consumer Salesforce Region field on
the Accept Clean Room Collaboration Invitation wizard shows the consumer's region. Use that
value to confirm that your account is in a compatible region before you accept.
If you serve customers across multiple regions, provision one Snowflake account per region to
avoid cross-region data transfer fees. If you maintain a single account, AWS US-east-2 (Ohio)
is compatible with all US-based Data 360 regions.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.