> ## Documentation Index
> Fetch the complete documentation index at: https://docs.textql.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Row-Level Security & Identity-Aware Access

> Data platform engineers / DBAs who own Snowflake, Databricks, or another warehouse’s access controls; analytics engineers writing governed query surfaces; and the workspace admi…

Make "each user sees only their rows" true in TextQL — **without maintaining two copies of your access rules**. This workshop is for the data platform engineer or DBA who owns warehouse security, working alongside the workspace admin. The punchline up front: if your warehouse already enforces row and column access, you usually don't rebuild anything — you route identity through.

## Who this is for

Data platform engineers / DBAs who own Snowflake, Databricks, or another warehouse's access controls; analytics engineers writing governed query surfaces; and the workspace admin who will turn the enforcement dials. Best run as a **DBA + admin pair**.

## What you'll be able to do

* Choose the right enforcement home for each source — warehouse-enforced (zero duplication) or ontology-enforced — using a decision table, not vibes.
* Turn on **per-member authentication** so your existing row access policies, secure views, and grants apply to every TextQL query untranslated.
* Write **fail-closed row-level guards** in the ontology for the cases the warehouse can't cover.
* **Mirror existing warehouse policies** into ontology guards when per-member auth isn't available — with a drift check so the copy never silently rots.
* Prove the boundary holds with a positive + adversarial test suite, then lock the query path and operate it.

<CardGroup cols={2}>
  <Card title="Two enforcement homes">Warehouse floor vs ontology narrowing — the decision table.</Card>
  <Card title="Zero duplication">Per-member auth: your existing policies just apply.</Card>
  <Card title="Model the policy">The who-sees-what matrix, written down first.</Card>
  <Card title="Write the guards">Fail-closed row filters in governed .tql.</Card>
  <Card title="Mirror the warehouse">Translate existing policies; add a drift alarm.</Card>
  <Card title="Prove it">Positive + adversarial tests, as real users.</Card>
  <Card title="Lock & operate">Close the raw-SQL path, audit it, review it.</Card>
</CardGroup>

## Before you start

You need: admin access to a TextQL workspace, a connected warehouse where you can see (or create) at least one access policy or restricted role, and a governed ontology for that source — this workshop *secures* query surfaces; [**Build Your Ontology, End to End**](/workshops/build-your-ontology/overview) creates them. If your ontology is thin, run that first.

<Note>
  **🤖 Prefer to have Ana run this workshop?** — Paste the runner from `ana-runner-full.md` (or this workshop's URL) into a new Ana thread and she'll facilitate it module by module on your own workspace.
</Note>
