When this module applies — Use this when a source must run on a shared service account (no per-member support, or an embedded surface) but the warehouse team has already encoded who-sees-what in row access policies, secure views, or row filters. If per-member auth is available, use Module 1 instead — a live identity beats the best copy.
4.1 · Read what already exists
Prompt
You’ll see: the warehouse’s actual policy inventory — or an explicit list of what the connector’s role can’t read. If the inventory comes back empty-handed, stop: ask the DBA to grant metadata visibility or export the policy DDL. Translating from memory defeats the purpose.
4.2 · Translate into guards
Prompt
You’ll see: a patch proposing guard-per-policy, with an honest “translation gaps” list. The gaps are the review agenda — your DBA approves the mapping the way they’d approve a firewall change, because that’s what it is.
4.3 · The copy will drift — alarm it
A translated policy is a snapshot; the warehouse remains the source of truth. The DBA will change a policy and nobody will remember the mirror. Don’t rely on memory:Prompt
You’ll see: an exception-only watcher. A warehouse policy change now triggers a review of the mirrored guard instead of a silent divergence — the same drift discipline as account hierarchies and golden datasets (Data Quality).
✅ Checkpoint
- The warehouse policy inventory exists — read from metadata, not reconstructed from memory
- Each policy has a mirrored guard proposed as a reviewed patch, with translation gaps listed
- The DBA reviewed the mapping
- Policy Drift Watch is running and silent on normal weeks