What you will be able to do
- Choose between a direct share, a listing, a data exchange and a clean room
- Publish a private or Snowflake Marketplace listing with the right privileges
- Explain how cross-region auto-fulfillment works and what it asks of providers and consumers
- Build a Streamlit in Snowflake app and share it with roles for self-service data access
1.Listings versus direct shares
Snowflake gives you four ways to share data. A direct share sends specific database objects to another account in your region. A listing packages a share together with metadata and offers it as a data product to one or more accounts. A data exchange is a group of accounts that you set up and manage, and you offer a share to that group. A clean room shares data while controlling which queries can run against it.
Checkpoint 1 of 8· Match them up
Match each sharing option to what it does
Tap a term, then the definition that fits it.
All four options rest on shares. They differ in packaging, in who can see the data, and in how much control you keep over its use.
“a Data Exchange, in which you set up and manage a group of accounts and offer a share to that group”Source: docs.snowflake.com
| Requirement | Direct share | Listing |
|---|---|---|
| Consumer in the same region | Supported | Supported |
| Consumer in another region or on another cloud | Not supported | Supported through cross-cloud auto-fulfillment |
| Public offer on the Snowflake Marketplace | Not supported | Supported |
| Charge for access | Not supported | Supported (paid listings) |
| Descriptions, sample queries, consumer usage metrics | Not supported | Supported |
Checkpoint 2 of 8· Check yourself
A provider in AWS us-east wants to share data with a customer whose account runs in Azure West Europe. What should they use?
Direct shares only reach accounts in the provider's region. Sharing across regions or clouds takes a listing with auto-fulfillment.
“A direct share works only with accounts in the same region.”Source: docs.snowflake.com
Checkpoint 3 of 8· Exam question
A provider wants a consumer to always see the latest committed rows in a shared table the moment the provider's transaction commits, with no manual refresh step on either side. Which characteristic of Secure Data Sharing delivers this?
Correct answer: A — Shares reference the provider's live micro-partitions, so modified rows appear to the consumer once the provider's transaction commits
- A. A share is a pointer to the same underlying storage the provider owns, not a copy, so the moment a provider's write commits, the consumer's read-only database built from the share reflects it with no batch job, refresh, or reload required.
- B. There is no scheduled re-cloning mechanism behind a share; cloning would create a divergent, static copy at the time of the clone rather than the live, always-current view a share provides, and it isn't how data sharing keeps consumers current.
- C. Snowpipe auto-ingest is a file-based continuous loading mechanism triggered by cloud storage event notifications; it has no role in Secure Data Sharing, which works by extending storage-level access rather than staging and loading files.
- D. Sharing exposes read access to the current state of the provider's objects, but Time Travel on shared objects is limited and is not the reason consumers see fresh data; the immediacy comes from sharing the live micro-partitions, not from replicated historical versions.
Sources1
2.Publishing a listing privately or on the Snowflake Marketplace
Before you publish, accept the Snowflake Provider and Consumer Terms and review the Provider Policies. To offer paid listings or listings on the Snowflake Marketplace, you also need a provider profile. Use ACCOUNTADMIN, or a custom role that ACCOUNTADMIN has granted the listing privileges after ORGADMIN delegated them.
| Task | Required roles and privileges |
|---|---|
| Create a data listing | Global CREATE LISTING; CREATE SHARE; OWNERSHIP (or sufficient grants) on the database, schemas, and objects being shared |
| Modify or configure a listing | OWNERSHIP on the listing, or MODIFY on the listing |
| Publish a listing | OWNERSHIP on the listing; the publishing role must own the attached share or application package; an approved provider profile |
| Publish a paid listing | The requirements to publish a listing, plus a Stripe Express account |
You can't transfer ownership of a share. If one role creates the share and another creates the listing, grant MODIFY on the listing to the role that owns the share.
To create a private listing, open Provider Studio in Snowsight and choose Create Listing » Specified Consumers. Then attach a data product: either pick database objects, and Snowflake creates a secure share for them, or pick an existing share. Next, choose Free or Paid, add the consumers' organization and account names, and fill in the description and legal terms. Optional extras are attributes, a data dictionary, business needs and Quick Start example queries. A listing you do not publish is saved as a draft.
A paid listing also needs a pricing plan, either usage-based or a flat fee, and an offer. The offer's purchase type controls whether access is self-service. Self-serve lets consumers see the price and buy the listing directly. Sales-led requires them to contact you. To move an existing direct share onto a listing, choose Create Listing » Snowflake Marketplace and select the existing secure share as the product, instead of picking individual objects.
Checkpoint 4 of 8· Check yourself
Which purchase type lets a consumer buy a paid listing without contacting the provider?
Self-serve shows the price and allows direct purchase. Sales-led requires contacting the provider. Limited-time and Recurring are contract types, not purchase types.
“select Self-serve to allow consumers to see the price and purchase the listing directly”Source: docs.snowflake.com
Sources2
3.Managing cross-region auto-fulfillment
If you add a consumer from a region other than your own to a listing, Snowflake enables auto-fulfillment. Once that consumer gets the listing, Snowflake replicates the data product to the consumer's region. In the listing's Auto-fulfillment section you set how often to replicate, as a value and an interval. If you have no default warehouse set, you also choose a warehouse for auto-fulfillment.
There are a few constraints to plan around. Providers outside the US government regions must use Cross-Cloud Auto-Fulfillment to reach consumers in those regions, and the secure share area created there is billed at that region's rates. Replicating a primary database is blocked when the database contains certain object types, so check the replication limitations before you promise a cross-region share.
Checkpoint 5 of 8· Check yourself
When you add a consumer in a remote region to a listing, what must you configure for auto-fulfillment?
The Auto-fulfillment section asks how often to replicate the data product to the remote region, and for a warehouse if you have no default warehouse.
“specify how often to replicate your data product from your region to the remote region”Source: docs.snowflake.com
Converting a direct share to a listing so that remote consumers can use it needs coordination with those consumers. After the listing is published, tell remote consumers how to get it. Their request triggers replication, and they receive an email when it finishes. Each consumer then drops the database they imported from the direct share, gets the listing, and creates a database with the same name, so their queries keep working.
Checkpoint 6 of 8· Put it in order
Order the steps for moving a remote consumer from a direct share to an auto-fulfilled listing
- 1.Consumer receives an email that the data is available
- 2.Auto-fulfillment replicates the data to the remote region
- 3.Consumer drops the database imported from the direct share and creates one from the listing with the same name
- 4.Provider publishes the listing and tells remote consumers how to access it
- 5.Consumer gets the listing
Replication starts only after the consumer gets the listing. The consumer swaps databases only after the completion email arrives.
“When auto-fulfillment completes, the consumer receives an email that the data is available.”Source: docs.snowflake.com
Sources2
4.Streamlit apps for dashboards and self-service access
Shares and listings deliver data to other accounts. Streamlit in Snowflake delivers data to people, through apps. Streamlit is an open-source Python library for building and sharing custom web apps. In Snowflake, an app processes data where it lives, without moving data or code to an external system. Snowflake manages the app's compute and storage and stores its code in a Snowflake object, which role-based access control protects. For dashboard and data-tool patterns, Snowflake points to its Streamlit in Snowflake demos. The sources used here do not cover individual dashboard widgets.
To create an app in Snowsight, open Projects » Streamlit, select + Streamlit App, name it, and choose the database and schema it belongs to. Then choose a runtime. A container runtime runs on a compute pool and uses a query warehouse for its queries; a warehouse runtime runs on a warehouse. Finally, replace the starter code in the editor with your own code.
Sharing the app with roles is what makes it a self-service tool. In the app, select Share, add a role and give it one of two permission levels. View and share lets the role view the app and share it further. View only lets it view the app but not share it. Business users open the app-viewer URL. Any role with the needed USAGE privilege can open that URL, whichever permission level it was given.
Checkpoint 7 of 8· Check yourself
An analyst role was given View only on a Streamlit app. Which statement is true?
View only allows viewing but not resharing. The app-viewer URL works for any role with the required USAGE privilege, whatever the sharing level.
“View only: If a user visits the app-builder URL, they can only view the app.”Source: docs.snowflake.com
Checkpoint 8 of 8· Exam question
A data engineer runs `CREATE SHARE partner_share;` and then attempts `GRANT SELECT ON VIEW analytics.public.regional_summary TO SHARE partner_share;`, where `regional_summary` is a standard (non-secure) view. What happens?
Correct answer: A — Snowflake rejects the grant with an error, because only secure views can be added to a share, so the view must first be recreated as secure
- A. Snowflake enforces that only secure views are permitted in shares and returns an error if a standard view is added, precisely to prevent exposing the view's internal logic and to guarantee that any predicate-based filtering inside the view cannot be reverse-engineered by a consumer.
- B. There is no silent, temporary hiding behavior for standard views added to shares; the operation is rejected outright rather than partially succeeding with restricted visibility of the view definition.
- C. Snowflake does not perform an automatic, unattended conversion of a standard view into a secure view as part of granting it to a share; the engineer must explicitly define the view as secure before the grant can succeed.
- D. There is no row-count-zero fallback or manual approval gate tied to sharing a standard view; the grant statement itself fails validation rather than completing and then restricting results at query time.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.A direct share can reach any Snowflake account, whatever its region or cloud.Why is that wrong?
A direct share reaches only accounts in the provider's region. To reach other regions or clouds, use a listing with cross-cloud auto-fulfillment.
Covered in Listings versus direct shares
Practise it for real
Create a Streamlit in Snowflake app and give an analyst role view-only access to it
1.In Snowsight, open Projects » Streamlit and select + Streamlit App. Name it and choose its database and schema.
Why: The app is stored as a Snowflake object in that location, and role-based access control governs it.
You should see: The create dialog asks you to choose a runtime.
2.Choose Run on warehouse and pick a warehouse, then select Create.
Why: A warehouse runtime is the simpler of the two runtimes to set up.
You should see: The editor opens with starter code and a side-by-side preview.
3.Select Share, type the analyst role's name, and choose View only from the drop-down.
Why: View only lets the role use the app but not share it further.
You should see: The role appears in the app's sharing list with View only.
4.Select Copy link, choose For app viewers, and send the URL to the analysts.
Why: Any role with the needed USAGE privilege can open the app-viewer URL.
You should see: Analysts using that role can open the app.
Stuck? Get a nudge
If the analysts cannot open the link, check that their role is in the app's sharing list.
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“Use a listing when you want to share across regions, offer data publicly on the Snowflake Marketplace, charge for access”
↩︎ Listings versus direct shares“To share across regions or cloud platforms, use a listing with cross-cloud auto-fulfillment”
↩︎ Exam trap 1“a Data Exchange, in which you set up and manage a group of accounts and offer a share to that group”
↩︎ Checkpoint“A direct share works only with accounts in the same region.”
↩︎ Checkpoint - 2.
“Create a provider profile to offer paid listings or listings on the Snowflake Marketplace.”
↩︎ Publishing a listing privately or on the Snowflake Marketplace“grant the MODIFY privilege on the listing to the role that owns the share or application package”
↩︎ Publishing a listing privately or on the Snowflake Marketplace“Snowflake enables auto-fulfillment to replicate data to the remote region after a consumer gets your listing”
↩︎ Managing cross-region auto-fulfillment“You must use Cross-Cloud Auto-Fulfillment, and your data product can only contain or reference objects supported for auto-fulfillment.”
↩︎ Managing cross-region auto-fulfillment“Drop the existing imported database created from the direct share.”
↩︎ Managing cross-region auto-fulfillment“select Self-serve to allow consumers to see the price and purchase the listing directly”
↩︎ Checkpoint“specify how often to replicate your data product from your region to the remote region”
↩︎ Checkpoint“When auto-fulfillment completes, the consumer receives an email that the data is available.”
↩︎ Checkpoint - 3.
“build applications that process and use data in Snowflake without moving data or application code to an external system”
↩︎ Streamlit apps for dashboards and self-service access“a Snowflake object that uses Role-based Access Control (RBAC) to manage access to your Streamlit app”
↩︎ Streamlit apps for dashboards and self-service access“For additional use cases on building dashboards, data tools, and ML/AI, see Streamlit in Snowflake demos.”
↩︎ Streamlit apps for dashboards and self-service access - 4.https://docs.snowflake.com/en/developer-guide/streamlit/app-development/creating-your-appOfficial docs
“Choose a runtime environment for your app (container or warehouse).”
↩︎ Streamlit apps for dashboards and self-service access - 5.https://docs.snowflake.com/en/developer-guide/streamlit/features/sharing-streamlit-appsOfficial docs
“All roles with necessary USAGE privileges on the app can access the app-viewer URL, regardless of the sharing option.”
↩︎ Streamlit apps for dashboards and self-service access“View only: If a user visits the app-builder URL, they can only view the app.”
↩︎ Checkpoint