Who this is for
Data platform engineers / DBAs who own Snowflake, Databricks, or another warehouse’s access controls; analytics engineers writing governed query surfaces; and the workspace admin who will turn the enforcement dials. Best run as a DBA + admin pair.What you’ll be able to do
- Choose the right enforcement home for each source — warehouse-enforced (zero duplication) or ontology-enforced — using a decision table, not vibes.
- Turn on per-member authentication so your existing row access policies, secure views, and grants apply to every TextQL query untranslated.
- Write fail-closed row-level guards in the ontology for the cases the warehouse can’t cover.
- Mirror existing warehouse policies into ontology guards when per-member auth isn’t available — with a drift check so the copy never silently rots.
- Prove the boundary holds with a positive + adversarial test suite, then lock the query path and operate it.
Two enforcement homes
Warehouse floor vs ontology narrowing — the decision table.
Zero duplication
Per-member auth: your existing policies just apply.
Model the policy
The who-sees-what matrix, written down first.
Write the guards
Fail-closed row filters in governed .tql.
Mirror the warehouse
Translate existing policies; add a drift alarm.
Prove it
Positive + adversarial tests, as real users.
Lock & operate
Close the raw-SQL path, audit it, review it.
Before you start
You need: admin access to a TextQL workspace, a connected warehouse where you can see (or create) at least one access policy or restricted role, and a governed ontology for that source — this workshop secures query surfaces; Build Your Ontology, End to End creates them. If your ontology is thin, run that first.🤖 Prefer to have Ana run this workshop? — Paste the runner from
ana-runner-full.md (or this workshop’s URL) into a new Ana thread and she’ll facilitate it module by module on your own workspace.