AI SRE permissions and access
Learn what AI SRE can access, and how you can control who has access to AI SRE.
What can AI SRE access?
AI SRE can't see or query any Dataset that the user’s Observe by Snowflake role doesn't already grant access to.
Runtime queries executed through the MCP Server always use the permissions of the authenticated user or service account.
- If you do not have permission to read a Dataset, such as Kubernetes Logs, then the MCP Server and AI SRE will also be unable to query the Dataset.
- No privilege escalation occurs; the agent can only query Datasets that you can query in Observe by Snowflake UI or through OPAL.
Use RBAC to configure access to AI SRE
You can use RBAC permissions when you define group privileges to control who has the ability to use AI SRE. See Manage groups and members.
Updated 22 days ago
Did this page help you?