Data Exports: Level's Snowflake to GCP Cloud Storage

Last updated: June 18, 2026

This article outlines the steps to set up a secure way for Level AI to send data from Snowflake instance to your Google Cloud Storage (GCS) bucket. Please follow the instructions below carefully to complete the integration process from your side.

Step 1: Share Your Cloud Storage Bucket Name

  • Create a Google Cloud Storage bucket (if one does not already exist) where you want Level AI to export data files.

  • Share the exact name of the bucket with us.

Upon receiving the bucket name, Level AI will initiate the integration process and provide you with our Snowflake Storage Service Account—this will be in the form of a Google email principal. You must grant access to this service account, as detailed in the following steps.

Step 2: Create a Custom IAM Role for Snowflake

  • In the Google Cloud Console, navigate to IAM Admin > Roles.

  • Click Create Role.

  • Provide a Title and optionally, Description for the role.

  • Select Add Permissions and include the following permissions:

    • storage.buckets.get

      1. storage.objects.get

      2. storage.objects.create

      3. storage.objects.delete

      4. storage.objects.list

  • Click Add. Then, click Create to finalize the custom role.

Step 3: Granting Access to the Cloud Storage Bucket

  • In the Google Cloud Console, navigate to Cloud Storage > Buckets.

  • Identify and select the bucket you created in Step 1.

  • Go to the Permissions tab and switch to View by principals.

  • Click Grant access.

  • In the Add principals section,

    • Paste the Snowflake Storage Service Account email provided by Level AI.

    • Under Assign roles, Select the custom IAM role you created in Step 2.

  • Click Save to apply the changes.

Domain Restricted Sharing Error

On clicking Save, if you receive the error Domain restricted sharing or similar, this likely means that your was created on or after May 3, 2024, and Google Cloud is enforcing a domain restriction constraint in its organization policies. The default constraint allows only users from your domain to be granted access.

To allow Level AI’s Snowflake service account to access your GCS bucket, you will need to update your organization’s domain restriction policy to include Snowflake’s service account domain.

For this, please reach out to your Level AI POC who will provide you with the following identifiers that will assist you in making this update:

  • Project ID: snowflake-project-id

  • Google Workspace Customer ID: snowflake-customer-directory-id

Once your domain restriction policy is updated, you can resume Step 3.

 

Upon receiving your confirmation, we will proceed with configuring the exports on our end. If you have any questions or encounter any issues, please reach out to your Level AI Account Executive/ Point of Contact.