Data Exports: Level's Snowflake to AWS S3
Last updated: June 18, 2026
This article describes items that need to be set up by the customer before proceeding with other Snowflake- AWS S3 actions.
Step 1: Creating an IAM policy
Log into the AWS Management Console.
In the Home dashboard, search for and select IAM.
From the left-hand navigation pane, select Account settings.
Under Security Token Service (STS), in the Endpoints list, find the Snowflake region - US West (N. California). If the STS status is inactive, slide the toggle to Active.
From the left-hand navigation pane, click Policies.
Select Create Policy.
For Policy editor, select JSON.
Add a policy document that will allow Snowflake to access the S3 bucket and folder.
The following policy (in JSON format) provides Snowflake with the required permissions to load data using a single bucket and folder path.{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "s3:ListBucket",
"Resource": "arn:aws:s3:::"
},
{
"Sid": "VisualEditor1",
"Effect": "Allow",
"Action": [
"s3:PutObject",
"s3:GetObject"
],
"Resource": "arn:aws:s3:::/*"
}
]
}Click Next.
Enter a Policy name, for example, snowflake_access and optionally, a Description.
Click Create policy.
Step 2: Create the IAM Role in AWS
To configure access permissions for Snowflake in the AWS Management Console, do the following:
From the left-hand navigation pane in the Identity and Access Management (IAM) dashboard, click Roles.
Select Create role.
Select AWS account as the trusted entity type.
In the Account ID field, enter your own AWS account ID temporarily. Later, you modify the trust relationship and grant access to Snowflake.
Select the Require external ID option. An external ID is used to grant access to your AWS resources (such as S3 buckets) to a third party such as Snowflake.
Enter a placeholder ID such as 0000. In a later step, you will modify the trust relationship for your IAM role and specify the external ID for your storage integration.Select Next.
Select the policy you created in Step 1: Creating an IAM policy.
Click Next.
Enter a name and description for the role, then click Create role.
You have now created an IAM policy for a bucket, created an IAM role, and attached the policy to the role.On the Role summary page, locate and record the Role ARN value.
NOTE
Once the above steps are complete, share the Role ARN value and bucket name with Level AI. The support team will get back to you with two more details: STORAGE_AWS_IAM_USER_ARN and STORAGE_AWS_EXTERNAL_ID. Once you have received these values, proceed to complete the actions described in Step 3 below.
Step 3: Allowing the Level IAM User to assume the role
The following step-by-step instructions describe how to configure IAM access permissions for Snowflake in your AWS Management Console.
Log in to the AWS Management Console and click IAM.
From the left-hand navigation pane, click Roles.
Select the role you created in Step 2: Create the IAM Role in AWS.
Open the Trust relationships tab.
Click Edit trust policy.
Modify the policy document with the 2 values given to you by Level AI: STORAGE_AWS_IAM_USER_ARN and STORAGE_AWS_EXTERNAL_ID where,
snowflake_user_arn is the STORAGE_AWS_IAM_USER_ARN value Level AI shared with you. snowflake_external_id is the STORAGE_AWS_EXTERNAL_ID value Level AI shared with you.{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "",
"Effect": "Allow",
"Principal": {
"AWS": ""
},
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": {
"sts:ExternalId": ""
}
}
}
]
}
Upon receiving your confirmation, we will proceed with configuring the exports on our end. If you have any questions or encounter any issues, please reach out to your Level AI Account Executive/ Point of Contact.