Secure access to data in Sigma
Sigma supports different methods that you can use to secure and manage access to your data. Use them in different combinations to provide scalable and effective data security in Sigma.
The options that make the most sense for your organization depend on how you plan to use Sigma, and where you prefer to restrict access to data.
Restrict access to data in your data platform
If you want to manage access restrictions in your data platform, use role-based access control (RBAC) already defined there instead of duplicating the logic in Sigma.
Use one of the following methods when connecting to reuse the RBAC in your data platform:
Use OAuth
If you configure connection-level OAuth, Sigma authenticates each user to your data platform using their own identity, so any RBAC or row access policies enforced by your data platform apply automatically. Each user must have an account in the data platform and in Sigma for connection-level OAuth to enforce RBAC in the data platform.
Dynamically assign roles with a user attribute
If a connection uses key pair authentication, you can use a user attribute to specify the role that Sigma uses to query your data platform on behalf of the current user. By setting up dynamic assignment of roles, your data platform’s existing role-based security policies determine what data a given user can access. See Dynamically assign roles used by a connection.
Use session and SQL variables
If you use a Snowflake connection with key pair authentication, you can set session or SQL variables that Snowflake uses to enforce row access policies. See Specify session variables for a Snowflake connection.
Isolate data in separate Sigma organizations
If you isolate each customer’s or business unit’s data in a separate organization using Sigma Tenants, you can ensure that unauthorized users can never access data that they do not have authorization to interact with. Sigma Tenants can be used in combination with data platform RBAC and restricting access to data in Sigma.
If you do not need to fully separate users, connections, authentication, AI providers, and branding for each customer or business unit, you can also use version tags and source swapping to isolate the data queried within a single Sigma organization.
Restrict access to data in Sigma
If you plan to manage access to data directly in Sigma, grant the relevant data access and set up appropriate row-level and column-level security rules:
Grant data access permissions
Data access permissions control which users and teams can access a connection and the databases, schemas, and tables within it. Access is additive, so permissions granted at a database or catalog level also apply to its schemas and objects. See Data access overview and Manage access to data and connections.
If you use OAuth to manage access to a connection, connection-level access grants still apply, but do not grant database, schema, or table-level data access permissions.
Apply row-level and column-level security
Use RLS and CLS to restrict access to specific rows or columns of data in a data model based on user identity, team membership, or an assigned user attribute value:
- Row-level security (RLS) restricts specific rows of data.
- Column-level security (CLS) restricts or masks entire columns of data.

