Snowflake6 min read

How to audit your Snowflake environment: the four axes that matter

Most Snowflake audits stop at cost. A real audit covers four axes — cost, security, freshness, and data usefulness — because the questions your CDO, CISO, and CFO ask can't be answered by a dashboard alone.

Most Snowflake audits stop at cost. They tell you which warehouses ran too hot, which queries burned the most credits, and where the auto-suspend timer is misconfigured. Then they hand you a subscription to a dashboard and disappear.

That's necessary. It's not sufficient. A real audit — the one that answers what your board is actually asking — covers four axes, not one. Miss any of them and you'll patch the symptom without ever seeing the disease.

Why cost audits alone aren't enough

The dashboards were built to serve one buyer: the FinOps lead trying to defend next quarter's Snowflake budget. That's a valid buyer. But they're not the only one asking questions.

Your CISO wants to know which users don't have MFA, which roles are over-privileged, whether PII sits in tables that shouldn't have it. Your CDO wants to know whether the data teams are shipping stale numbers to the board. Your VP of Data wants to know which tables nobody actually reads — the ones that are quietly costing storage for no analytical value.

None of those questions get answered by a cost dashboard. They get answered by an audit.

Axis 1 — Cost & usage

Start here because it's easiest to defend to a CFO. Warehouse map, credit consumption trend, spend anomalies, storage cost breakdown, time-travel bloat, per-team attribution. Every finding should carry a £ or $ figure. If you can't say “this warehouse is costing you £X/month and here's what to change,” you don't have a finding — you have an observation.

Common patterns: warehouses that stayed size-XL after a one-off Q4 spike and never came back down. Dev/UAT warehouses running 24×7 when they only need to be up during working hours. Continuous polling jobs that could safely move to a scheduled cadence.

Axis 2 — Security posture

MFA coverage per user. Over-privileged roles nobody reviews. Network policies (or their absence). PII in tables that shouldn't have it. Access anomalies — a user querying data they've never touched before. Dormant users still holding write access.

This axis is what your board asks about when the industry has a breach. Snowsight will show you a query. It won't show you posture.

Axis 3 — Data freshness

Table-level freshness signals. Pipelines with broken cadence — a job that was supposed to run daily but has been silently failing for three weeks. Stale dependencies — a downstream report depending on a table that stopped updating in Q3. The downstream impact of freshness gaps — which reports are silently wrong right now.

This is the “you found out from the CFO on Thursday” axis. A proper audit surfaces it before someone else does.

Axis 4 — Data usefulness

The one most audits skip entirely. Bytes-read per table over 30, 60, 90 days. Consumers per table. Tables with zero consumption but non-zero storage cost. Reports and models whose consumer count dropped to zero six months ago but which are still refreshing in production.

This axis quantifies rot. Every quarter, more silt builds up. Eventually the pipes back up. Nobody is watching because nobody's job is to notice.

Findings synthesis — the atomic unit of value

Every finding across every axis should roll into a single prioritised list. Not a dashboard. Not a spreadsheet. A list.

Each finding needs three things: a £ figure (or a compliance-grade risk value), an effort estimate (S/M/L), and a suggested owner. Without ownership, findings are entertainment.

That's what makes an audit actionable versus interesting. Interesting audits get printed and shelved. Actionable audits get shipped.

The audit gap — 20–40% waste, unprovable

Most Snowflake customers estimate 20–40% of their bill is waste. They just can't prove which 20–40% — so they can't fix it.

That's the gap. Not the waste itself — the waste is real. The gap is the ability to prove it with evidence a CFO will sign off on.

A four-axis audit closes the gap. That's what makes it worth doing.

VS

Vikram Saxena

Founder & Principal Architect, Blue Thread

Fix the data warehouse. Then build AI on top.

Twenty minutes to talk through your Snowflake environment or your AI plans — whichever is holding you up. No pitch, no pressure.