Skip to main content
Make “each user sees only their rows” true in TextQL — without maintaining two copies of your access rules. This workshop is for the data platform engineer or DBA who owns warehouse security, working alongside the workspace admin. The punchline up front: if your warehouse already enforces row and column access, you usually don’t rebuild anything — you route identity through.

Who this is for

Data platform engineers / DBAs who own Snowflake, Databricks, or another warehouse’s access controls; analytics engineers writing governed query surfaces; and the workspace admin who will turn the enforcement dials. Best run as a DBA + admin pair.

What you’ll be able to do

  • Choose the right enforcement home for each source — warehouse-enforced (zero duplication) or ontology-enforced — using a decision table, not vibes.
  • Turn on per-member authentication so your existing row access policies, secure views, and grants apply to every TextQL query untranslated.
  • Write fail-closed row-level guards in the ontology for the cases the warehouse can’t cover.
  • Mirror existing warehouse policies into ontology guards when per-member auth isn’t available — with a drift check so the copy never silently rots.
  • Prove the boundary holds with a positive + adversarial test suite, then lock the query path and operate it.

Two enforcement homes

Warehouse floor vs ontology narrowing — the decision table.

Zero duplication

Per-member auth: your existing policies just apply.

Model the policy

The who-sees-what matrix, written down first.

Write the guards

Fail-closed row filters in governed .tql.

Mirror the warehouse

Translate existing policies; add a drift alarm.

Prove it

Positive + adversarial tests, as real users.

Lock & operate

Close the raw-SQL path, audit it, review it.

Before you start

You need: admin access to a TextQL workspace, a connected warehouse where you can see (or create) at least one access policy or restricted role, and a governed ontology for that source — this workshop secures query surfaces; Build Your Ontology, End to End creates them. If your ontology is thin, run that first.
🤖 Prefer to have Ana run this workshop? — Paste the runner from ana-runner-full.md (or this workshop’s URL) into a new Ana thread and she’ll facilitate it module by module on your own workspace.