What you will be able to do
- Explain how an account-level parameter value becomes the default for users and how it can be overridden for one user
- Use the Snowsight download-button parameter to hide result downloads for an account or for specific users
- Use a data movement policy UI_DOWNLOAD rule to decide when downloads are allowed, and recognise which downloads it does not cover
1.Account defaults and user overrides
Controls on result downloads are applied through the parameter hierarchy, so it helps to start there. An account parameter can only be set at the account level, with ALTER ACCOUNT. Many other parameters can be set at more than one level.
For parameters tied to users, the account-level value is the default. Administrators set it with ALTER ACCOUNT, and it becomes the default for individual users and their sessions. An administrator with the right privileges, usually a SECURITYADMIN user, can override it for one user with ALTER USER. For object parameters, where the user is the object, the account value is the default for objects in the account, and users with the right privileges override it on an individual object with ALTER <object>.
The Parameters reference marks this as "Can be set for Account » User". The account value is the policy for everyone, and a value on a user replaces it for that user only.
Checkpoint 1 of 5· Check yourself
An account sets a user-overridable parameter to TRUE with ALTER ACCOUNT. What happens for a user who has no value of their own?
Values set at the account level become the defaults for users. A per-user setting is only needed to override them.
“The values that you set at this level become the default values for individual users and their sessions.”Source: docs.snowflake.com
Sources1
2.Hiding the Snowsight download button
The simplest control is a Boolean parameter that decides whether users see a button to download data in Snowsight. If it is TRUE, users don't see the button. If it is FALSE (the default), they do. Its type is *Object (for users)*, and it can be set for Account > User. You can hide the button for the whole account with ALTER ACCOUNT, then turn it back on for a named analyst with ALTER USER. You can also leave the account default alone and hide the button only for high-risk users.
The excerpt of the Parameters reference available to this lesson gives this parameter's behaviour, levels and default, but not its identifier. Look up the exact name on the Parameters page before relying on it.
This parameter is all-or-nothing. A user either has the button or does not, whatever query they ran and however many rows it returned.
Checkpoint 2 of 5· Check yourself
Security wants result downloads hidden for everyone except one approved analyst. How is that done with the Snowsight download-button parameter?
The parameter can be set for Account > User, so the account value is the default and a user-level value overrides it for one person.
“Object (for users) — Can be set for Account > User”Source: docs.snowflake.com
Sources1
3.Deciding when downloads are allowed with data movement policies
To control *when* downloads are allowed, rather than switching them off, use a data movement policy (DMP). A policy contains rules, and each rule covers one movement type. The type for Snowsight result downloads is UI_DOWNLOAD. It applies to the Download button on the results pane for SQL and Python files in workspaces, to result downloads from notebook cells in workspaces, and to the download in Query History.
Each rule has a MAX_ROWS expression that returns an integer:
| MAX_ROWS returns | Effect |
|---|---|
| NULL | No limit from this rule |
| 0 | Block the movement operation |
| Positive integer | Maximum number of rows allowed for that operation |
The MAX_ROWS body can call SYS_CONTEXT to read session and movement context. That lets a rule allow small downloads, block large ones, or make an exception for approved roles. When a UI_DOWNLOAD enforce rule's threshold is met, Snowsight disables the download button. Below the threshold, the download goes ahead.
Two details matter. First, UI_DOWNLOAD supports enforcement only. Alert rules are not supported for this type, so you can't use it to "allow but notify". Second, the type doesn't cover every download button. It excludes, among others, downloads in Streamlit apps and the Export as HTML option in workspaces.
To apply a policy across the whole account, attach it with ALTER ACCOUNT SET DATA MOVEMENT POLICY. Only one account-level policy can be active at a time, and it applies only where no tag-based policy resolves.
Checkpoint 3 of 5· Check yourself
A team wants analysts to keep downloading Snowsight results, but wants an alert whenever someone downloads more than 10,000 rows. Why can't a UI_DOWNLOAD rule do this?
For UI_DOWNLOAD, enforcement disables the download button and alert rules are not supported, so 'allow and notify' isn't available for this type.
“Upon enforcement, the applicable download button is disabled. Alert rules are not supported for this movement type.”Source: docs.snowflake.com
Checkpoint 4 of 5· Exam question
Enforcement on stage creation is now active, but a nightly task still unloads with `COPY INTO @legacy_ext_stage`, a stage created years ago with embedded `CREDENTIALS`. Security wants those unloads to fail until the stage is moved onto a storage integration. Which setting provides this?
Correct answer: A — Set `REQUIRE_STORAGE_INTEGRATION_FOR_STAGE_OPERATION = TRUE` at account level so load and unload on stages lacking an integration fail
- A. Correct. This parameter is checked when the stage is used, so pre-existing stages with embedded keys stop working for load and unload until they reference a storage integration.
- B. The creation parameter only evaluates new CREATE STAGE statements. It never revisits stages that already exist, so the legacy stage keeps working.
- C. A named stage is not an inline URL. The unload references the stage by name, so this parameter does not apply to the task.
- D. This parameter concerns internal stages only. The legacy stage is external, so the unload is not affected.
Sources2
4.Result retrieval that bypasses the button
Hiding or disabling a button in Snowsight doesn't stop a driver from fetching the same rows. Data movement policies cover this with the PROGRAMMATIC_FETCH type. It applies to data accessed from a driver or connector, SnowSQL, Snowflake CLI, the SQL API, or a stored procedure.
Each statement gets at most one primary movement type, chosen in a fixed order of precedence. A statement that runs inside a stored procedure is classified as PROGRAMMATIC_FETCH even when the session that called it started in Snowsight. A policy that only constrains SNOWSIGHT_UI therefore won't apply to a procedure called from a worksheet.
Checkpoint 5 of 5· Put it in order
Put the movement types in the order Snowflake checks them when it picks a statement's primary movement type
- 1.COPY_INTO_INTERNAL_STAGE
- 2.AGENT_ACCESS
- 3.COPY_INTO_EXTERNAL_STAGE
- 4.SNOWSIGHT_UI
- 5.PROGRAMMATIC_FETCH
Snowflake picks one primary type per statement in this fixed order. PROGRAMMATIC_FETCH applies only when nothing higher matches.
“For one statement, Snowflake picks at most one primary movement type for DMP evaluation, in this fixed order:”Source: docs.snowflake.com
Sources2
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.A UI_DOWNLOAD rule can be put in ALERT_RULES so downloads go ahead but are flagged.Why is that wrong?
Alert rules aren't supported for UI_DOWNLOAD. Enforcement disables the download button.
Covered in Deciding when downloads are allowed with data movement policies
2.A stored procedure called from a Snowsight worksheet is governed by SNOWSIGHT_UI rules.Why is that wrong?
Statements inside a stored procedure are classified as PROGRAMMATIC_FETCH, even when the calling session started in Snowsight.
Covered in Result retrieval that bypasses the button
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“To set an account parameter, you run the ALTER ACCOUNT command.”
↩︎ Account defaults and user overrides“can run the ALTER USER command to override session parameters for individual users”
↩︎ Account defaults and user overrides“Account administrators can run the ALTER ACCOUNT command to set object parameters for objects in the account.”
↩︎ Account defaults and user overrides“Controls whether users in an account see a button to download data in Snowsight”
↩︎ Hiding the Snowsight download button“TRUE: Users in the account don’t see a button to download data in Snowsight.”
↩︎ Hiding the Snowsight download button“The values that you set at this level become the default values for individual users and their sessions.”
↩︎ Checkpoint“Object (for users) — Can be set for Account > User”
↩︎ Checkpoint - 2.
“Applies when a user downloads query results from the Snowsight UI, specifically the Download button on the results pane”
↩︎ Deciding when downloads are allowed with data movement policies“Button disabled: When a UI_DOWNLOAD enforce rule threshold is met, downloads are disallowed by disabling the download button in the Snowsight UI.”
↩︎ Deciding when downloads are allowed with data movement policies“The MAX_ROWS body can call SYS_CONTEXT to read session and movement context”
↩︎ Deciding when downloads are allowed with data movement policies“Only one account-level policy can be active at a time.”
↩︎ Deciding when downloads are allowed with data movement policies“Applies when Snowflake classifies the statement as programmatic data access from a driver or connector, SnowSQL, Snowflake CLI, SQL API, or a stored procedure.”
↩︎ Result retrieval that bypasses the button“Alert rules are not supported for this movement type.”
↩︎ Exam trap 1“statements executing inside a stored procedure classify as PROGRAMMATIC_FETCH rather than SNOWSIGHT_UI, even when the calling session originates from Snowsight.”
↩︎ Exam trap 2“Upon enforcement, the applicable download button is disabled. Alert rules are not supported for this movement type.”
↩︎ Checkpoint“For one statement, Snowflake picks at most one primary movement type for DMP evaluation, in this fixed order:”
↩︎ Checkpoint