RiskHeatMap.aiGoverned demo

Incident Detail

Explainable by design

Customer data export after Snowflake role misconfiguration

Review the agent-generated root cause analysis, issue framing, control posture, risks, and actions before final approval.

Human approval remains required before controls, risks, and actions are finalised.

Incident

The source event that triggered downstream agent work.

System
Snowflake Analytics
Reported
Jul 10, 2026, 3:18 AM
Severity
Critical
Status
Monitoring

Monitoring identified an unusual export from a payment analytics schema after a privileged Snowflake role was assigned outside the approved access workflow.

Issue

Human-reviewable issue statement generated from the RCA.

P1Approved

Privileged analytics access can bypass export governance

Privileged role assignment and export monitoring are not sufficiently joined to prevent or rapidly contain sensitive data movement.

Owner: Data Security

Root Cause Analysis

Mock AI-generated narrative based on deterministic rules.

Ai Generated91 Confidence

Trigger

Privileged Snowflake role assignment outside the approved access workflow.

Summary

A temporary privileged role was granted without time-bound enforcement, allowing an anomalous export before monitoring triggered review.

Contributing factors

  • Role grants were not automatically reconciled against approved access tickets.
  • Export thresholds were configured for volume but not unusual user behaviour.
  • Session revocation required a manual security operation.

Risks

Inherent and residual risk posture tied to this incident.

Sensitive customer data exfiltration risk

InherentCriticalPending

Privileged analytics access could enable unauthorised movement of customer and payment data.

PrivacyScore 94

Residual privileged access risk

ResidualHighRejected

Manual role reconciliation leaves a residual window for inappropriate access.

SecurityScore 72

Data classification

Deterministic P0–P4 classification over the incident, issue, and RCA text.

P1Sensitive

Sensitive data indicators were detected and should remain under restricted review.

Reasons

Contains highly sensitive business or customer-impacting data.
Contains internal operational or incident response content.
Contains standard internal business process content.

Matched signals

paymentcustomer datamisconfigurationworkflowmonitoring

Recent audit events

Key system events for this incident package.

Security Operations

Jul 10, 2026, 3:27 AM

Exports Paused

action action-data-pause

Agent:Classification

Jul 10, 2026, 3:20 AM

Sensitive Data Flagged

incident inc-data-002

Connector:Snowflake

Jul 10, 2026, 3:18 AM

Anomalous Export Detected

incident inc-data-002

Controls

Control posture classified as effective, weakness, or gap.

Privileged role approval and expiry

WeaknessPending

Elevated analytics roles require ticket linkage, approval, and automatic expiry.

Owner: Identity and Access Management

Sensitive export anomaly monitoring

GapRejected

Exports are monitored against user, volume, time, destination, and data classification signals.

Owner: Security Operations

Actions

Recommended remediation work generated from the simulated agents.

Revoke active analytics sessions

In ProgressPending

Force re-authentication for accounts with access to the impacted analytics role.

Security OperationsDue Jul 15, 2026

Pause sensitive data exports

OpenPending

Disable scheduled and manual exports while scope and destination are validated.

Data PlatformDue Jul 15, 2026