CertSafari
    Snowflake SnowPro Advanced: Security Engineer (SEA-C01)· Lessons

    Domain 2 · Lesson 7/21

    Restricting Query Result Downloads in Snowsight

    Restrict data exfiltration.

    7 min read
    4.29% of exam
    2 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Explain how an account-level parameter value becomes the default for users and how it can be overridden for one user
    • Use the Snowsight download-button parameter to hide result downloads for an account or for specific users
    • Use a data movement policy UI_DOWNLOAD rule to decide when downloads are allowed, and recognise which downloads it does not cover

    1.Account defaults and user overrides

    Controls on result downloads are applied through the parameter hierarchy, so it helps to start there. An account parameter can only be set at the account level, with ALTER ACCOUNT. Many other parameters can be set at more than one level.

    For parameters tied to users, the account-level value is the default. Administrators set it with ALTER ACCOUNT, and it becomes the default for individual users and their sessions. An administrator with the right privileges, usually a SECURITYADMIN user, can override it for one user with ALTER USER. For object parameters, where the user is the object, the account value is the default for objects in the account, and users with the right privileges override it on an individual object with ALTER <object>.

    The Parameters reference marks this as "Can be set for Account » User". The account value is the policy for everyone, and a value on a user replaces it for that user only.

    Checkpoint 1 of 5· Check yourself

    An account sets a user-overridable parameter to TRUE with ALTER ACCOUNT. What happens for a user who has no value of their own?

    Sources1

    2.Hiding the Snowsight download button

    The simplest control is a Boolean parameter that decides whether users see a button to download data in Snowsight. If it is TRUE, users don't see the button. If it is FALSE (the default), they do. Its type is *Object (for users)*, and it can be set for Account > User. You can hide the button for the whole account with ALTER ACCOUNT, then turn it back on for a named analyst with ALTER USER. You can also leave the account default alone and hide the button only for high-risk users.

    The excerpt of the Parameters reference available to this lesson gives this parameter's behaviour, levels and default, but not its identifier. Look up the exact name on the Parameters page before relying on it.

    This parameter is all-or-nothing. A user either has the button or does not, whatever query they ran and however many rows it returned.

    Checkpoint 2 of 5· Check yourself

    Security wants result downloads hidden for everyone except one approved analyst. How is that done with the Snowsight download-button parameter?

    Sources1

    3.Deciding when downloads are allowed with data movement policies

    To control *when* downloads are allowed, rather than switching them off, use a data movement policy (DMP). A policy contains rules, and each rule covers one movement type. The type for Snowsight result downloads is UI_DOWNLOAD. It applies to the Download button on the results pane for SQL and Python files in workspaces, to result downloads from notebook cells in workspaces, and to the download in Query History.

    Each rule has a MAX_ROWS expression that returns an integer:

    What a rule's MAX_ROWS return value means
    MAX_ROWS returnsEffect
    NULLNo limit from this rule
    0Block the movement operation
    Positive integerMaximum number of rows allowed for that operation

    The MAX_ROWS body can call SYS_CONTEXT to read session and movement context. That lets a rule allow small downloads, block large ones, or make an exception for approved roles. When a UI_DOWNLOAD enforce rule's threshold is met, Snowsight disables the download button. Below the threshold, the download goes ahead.

    Two details matter. First, UI_DOWNLOAD supports enforcement only. Alert rules are not supported for this type, so you can't use it to "allow but notify". Second, the type doesn't cover every download button. It excludes, among others, downloads in Streamlit apps and the Export as HTML option in workspaces.

    To apply a policy across the whole account, attach it with ALTER ACCOUNT SET DATA MOVEMENT POLICY. Only one account-level policy can be active at a time, and it applies only where no tag-based policy resolves.

    Checkpoint 3 of 5· Check yourself

    A team wants analysts to keep downloading Snowsight results, but wants an alert whenever someone downloads more than 10,000 rows. Why can't a UI_DOWNLOAD rule do this?

    Checkpoint 4 of 5· Exam question

    Enforcement on stage creation is now active, but a nightly task still unloads with `COPY INTO @legacy_ext_stage`, a stage created years ago with embedded `CREDENTIALS`. Security wants those unloads to fail until the stage is moved onto a storage integration. Which setting provides this?

    Sources2

    4.Result retrieval that bypasses the button

    Hiding or disabling a button in Snowsight doesn't stop a driver from fetching the same rows. Data movement policies cover this with the PROGRAMMATIC_FETCH type. It applies to data accessed from a driver or connector, SnowSQL, Snowflake CLI, the SQL API, or a stored procedure.

    Each statement gets at most one primary movement type, chosen in a fixed order of precedence. A statement that runs inside a stored procedure is classified as PROGRAMMATIC_FETCH even when the session that called it started in Snowsight. A policy that only constrains SNOWSIGHT_UI therefore won't apply to a procedure called from a worksheet.

    Checkpoint 5 of 5· Put it in order

    Put the movement types in the order Snowflake checks them when it picks a statement's primary movement type

    1. 1.COPY_INTO_INTERNAL_STAGE
    2. 2.AGENT_ACCESS
    3. 3.COPY_INTO_EXTERNAL_STAGE
    4. 4.SNOWSIGHT_UI
    5. 5.PROGRAMMATIC_FETCH

    Sources2

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.A UI_DOWNLOAD rule can be put in ALERT_RULES so downloads go ahead but are flagged.Why is that wrong?

      Alert rules aren't supported for UI_DOWNLOAD. Enforcement disables the download button.

      Covered in Deciding when downloads are allowed with data movement policies

    2. 2.A stored procedure called from a Snowsight worksheet is governed by SNOWSIGHT_UI rules.Why is that wrong?

      Statements inside a stored procedure are classified as PROGRAMMATIC_FETCH, even when the calling session started in Snowsight.

      Covered in Result retrieval that bypasses the button

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “To set an account parameter, you run the ALTER ACCOUNT command.”
      ↩︎ Account defaults and user overrides
      “can run the ALTER USER command to override session parameters for individual users”
      ↩︎ Account defaults and user overrides
      “Account administrators can run the ALTER ACCOUNT command to set object parameters for objects in the account.”
      ↩︎ Account defaults and user overrides
      “Controls whether users in an account see a button to download data in Snowsight”
      ↩︎ Hiding the Snowsight download button
      “TRUE: Users in the account don’t see a button to download data in Snowsight.”
      ↩︎ Hiding the Snowsight download button
      “The values that you set at this level become the default values for individual users and their sessions.”
      ↩︎ Checkpoint
      “Object (for users) — Can be set for Account > User”
      ↩︎ Checkpoint
    2. 2.
      “Applies when a user downloads query results from the Snowsight UI, specifically the Download button on the results pane”
      ↩︎ Deciding when downloads are allowed with data movement policies
      “Button disabled: When a UI_DOWNLOAD enforce rule threshold is met, downloads are disallowed by disabling the download button in the Snowsight UI.”
      ↩︎ Deciding when downloads are allowed with data movement policies
      “The MAX_ROWS body can call SYS_CONTEXT to read session and movement context”
      ↩︎ Deciding when downloads are allowed with data movement policies
      “Only one account-level policy can be active at a time.”
      ↩︎ Deciding when downloads are allowed with data movement policies
      “Applies when Snowflake classifies the statement as programmatic data access from a driver or connector, SnowSQL, Snowflake CLI, SQL API, or a stored procedure.”
      ↩︎ Result retrieval that bypasses the button
      “Alert rules are not supported for this movement type.”
      ↩︎ Exam trap 1
      “statements executing inside a stored procedure classify as PROGRAMMATIC_FETCH rather than SNOWSIGHT_UI, even when the calling session originates from Snowsight.”
      ↩︎ Exam trap 2
      “Upon enforcement, the applicable download button is disabled. Alert rules are not supported for this movement type.”
      ↩︎ Checkpoint
      “For one statement, Snowflake picks at most one primary movement type for DMP evaluation, in this fixed order:”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 15 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.