snowflake-strong-auth-migration-pilot
Installation
SKILL.md
Snowflake Strong-Auth Migration Pilot
Overview
Convert an uncertain Snowflake identity estate into an owner-backed, least-privilege authentication pilot. The useful unit is a named workload and its runtime—not a blanket account-wide password deadline. The pilot classifies PERSON, SERVICE, LEGACY_SERVICE, and SERVICE_AGENT principals, maps each bound workload to a supported target, and checks that managed MCP/OAuth primary-role scopes, client behavior, and secondary-role controls cannot silently broaden access.