SELECT on the tables to ingest. Auxia connects directly and reads on a recurring schedule — read-only, with no tables copied or exported and no scheduled jobs for you to maintain.
Before proceeding, review the Source Data Requirements to ensure your tables are ready to be connected with Auxia.
1. Overview
You provision three objects in your account — a warehouse, a service user (key-pair auth), and a read-only role — and grant the role access to the tables you want shared. Auxia authenticates as that user and reads each table directly, on a schedule, using your warehouse for compute. Flow:- A role that can
CREATE WAREHOUSE,CREATE USER,CREATE ROLE, andGRANT(typicallyACCOUNTADMIN). - Each shared table/view should have a timestamp column marking when a row was added/updated (e.g.,
UPDATE_DATE), so Auxia can read incrementally rather than rescanning the full table.
2. Create a Warehouse
A dedicated, auto-suspending warehouse for Auxia’s reads keeps compute cost low and isolates it for easy attribution.3. Create a Key-Pair Service User
Auxia uses key-pair authentication (no password). Your Auxia solutions engineer provides the public key to paste in below.4. Create a Read-Only Role and Grant Access
Run the following, repeating theGRANT SELECT line for each table or view you want Auxia to read:
5. Send the Details to Auxia
Share the following with your Auxia solutions engineer:- Account URL — e.g.
https://<org>-<account>.snowflakecomputing.com - Username (
AUXIA_INGESTION_USER), role (AUXIA_INGESTION_ROLE), and warehouse (AUXIA_INGESTION_WH) - Database / schema / table (or view) names to ingest
- The timestamp/watermark column for each object (used for incremental reads)
- Desired refresh cadence (e.g., hourly or daily) and when source data typically lands
6. Cost
- Reads run on your warehouse, in your account — so warehouse compute and any Snowflake data-transfer-out are billed to you, and Auxia bears no Snowflake cost. A dedicated warehouse that auto-suspends, combined with watermark-scoped incremental reads, keeps this minimal. Auxia advises on warehouse sizing for your data volume during onboarding.
- No data is copied or staged on your side — Auxia reads the tables in place; there is nothing to store or clean up.
7. Security & Governance
- Read-only, scoped to exactly the tables you
GRANT. - Key-pair auth, no password — Auxia holds only the private key (in its secret manager); you register only the public key.
- Revocable — drop the role or disable the user to cut off all access immediately.
- Rotatable — replace the user’s
RSA_PUBLIC_KEYat any time; Auxia coordinates the matching private-key rotation. - Network-restrictable — you can attach a Snowflake network policy to the service user if you want to limit it to Auxia’s egress addresses (ask your solutions engineer).
8. Recommended Practices
- Grant least privilege — only the databases, schemas, and tables to be ingested, on a dedicated role.
- Use a dedicated, auto-suspending warehouse so Auxia’s read cost is isolated and easy to attribute; size it to your data volume (Auxia will advise).
- Ensure a watermark column on each table so reads stay incremental rather than full scans.
- Share base tables, not views, where possible — Auxia reads the underlying tables directly.
9. Summary
10. FAQ
Does Auxia create or modify anything in our environment? No. Auxia reads your existing tables in place — no copies, no exports, no schema changes, and no new pipelines. Who bears the Snowflake cost? You do, but minimally — reads run on a dedicated, auto-suspending warehouse in your account and are scoped to the watermark window. Auxia bears no Snowflake compute. Can we revoke Auxia’s access? Yes, at any time — drop the role or disable the service user. How do we rotate the credential? Replace the user’sRSA_PUBLIC_KEY; Auxia stores the private key by reference and coordinates the rotation, so it does not require reconfiguring the connection.
Prefer not to grant direct access to your account? Two alternatives are available: Secure Data Sharing (you share into Auxia’s account) and GCS Export (you push files to Auxia’s bucket). Discuss the trade-offs with your Auxia solutions engineer.