← Back to home
Secure Banking Platform

A Secure, Governed Snowflake Platform for a Bank — Dev to Prod

13-week engagement · secure environment build across dev, QA & prod

Over 13 weeks I stood up a secure, governed Snowflake environment for a commercial bank and carried it from dev and QA toward production — enterprise identity, two-layer RBAC, defense-in-depth controls, a medallion data foundation with a dbt transformation layer, and repeatable build scripts so prod comes up from the same source as non-prod. Plus a 40-work-area assessment the client's team now operates itself.

2 accts
NONPROD (dev · QA) + PROD
13 wks
end to end
20
RBAC roles · 3,700+ grants
4-layer
defense-in-depth security

Architecture — Cloud & Data

Microsoft Azure cloud
External sources
GitHub
Git integration for dbt projects
CRM data share
Inbound Snowflake share
Document store
File connector
OpenFlow
Data ingestion
PostgreSQL
Source-system mirror
data ingestion
Snowflake — two accounts
NONPROD · DEV + QA PROD · same architecture
Bronze
Raw landing · inbound shares isolated
Silver
Cleaned, conformed, business-keyed · staging
Gold
Analytics-ready marts
Consumers
Semantic views · Cortex Agent · Search · Streamlit · BI
dbt — transformation engine across Bronze → Silver → Gold
PLATFORM_DB — cross-cutting platform, utility, security, and dbt-project objects
identity · storage · private networking
Azure platform services
Microsoft Entra ID
SSO (SAML2) + SCIM — central identity
Azure Storage
Storage containers + external stage
VNet + PrivateLink
Private connectivity over the corporate network

Outcomes

Governed Platform Foundation

  • Medallion architecture (Bronze / Silver / Gold + staging) across dev and QA
  • 13 databases, 84 schemas, 7 workload-isolated warehouses
  • Two-layer RBAC — 20 custom roles, 3,700+ privilege grants

Enterprise Identity & Security

  • Azure AD SSO (SAML2) + SCIM provisioning, live
  • Authentication-policy posture documented
  • Ordered RBAC + ownership remediation runbook

Data & Transformation Layer

  • Live CRM source data across dev and QA
  • dbt infrastructure — external access, git, native project objects
  • Scheduled-task framework ready for production models

Repeatable Dev → Prod Provisioning

  • NONPROD (dev + QA) built first; PROD stands up from the same scripts
  • Turn-key build scripts regenerate the environment end to end
  • Environment parity — identical architecture, isolated data & credentials
  • Snowflake-native AI & BI workloads run on the governed foundation

A Planning System the Team Operates — Not Just a Report

  • 40-work-area assessment classified: 12 delivered · 10 in plan · 18 scoped for follow-on
  • 10-phase production-standup playbook + independent architecture review
  • YAML-driven discovery taxonomy with build scripts that regenerate the reports
  • Snapshot toolchain captures live account state as evidence — the team runs the system going forward

Security — Defense in Depth

L1 · Network
PrivateLink connectivity Network policy / IP allowlist
L2 · Identity & Authentication
Azure AD SSO (SAML2) SCIM provisioning Key-pair (JWT) auth MFA enrollment Break-glass account
L3 · Data Protection
Masking policies Row-access policies Data classification tags
L4 · Monitoring & Governance
Cortex usage monitoring Resource monitors Audit queries Data retention policy
Data

The four-layer model as designed. Per-control implementation status is the client's, not mine to publish.

The Stack

Snowflake Cortex AI — Search, Analyst, Agents dbt Streamlit Azure AD — SSO / SCIM Azure Storage PrivateLink Python tooling Medallion architecture RBAC

Client name withheld. Figures and outcomes are drawn from the engagement's client-verified closeout.