AWS and Salesforce: governing zero-copy data access
AWS describes direct access from Salesforce Data 360 to Iceberg data in S3. Shared access still needs explicit ownership.
What happened
AWS’s walkthrough connects Salesforce Data 360 to Iceberg tables in S3 through the Glue Iceberg REST endpoint, with Lake Formation managing access.
Why it matters
Fewer replicated datasets can reduce reconciliation work. Consumers still need agreement on freshness, definitions and who can change the shared record.
Who it affects: AWS lakehouse teams, Salesforce data owners and governance practitioners.
A practical example
Before exposing a customer table, agree which identifier joins it to Salesforce records and which columns each consumer may read.
What to do next
Pilot one dataset with documented consumers and a narrowly scoped access role.
- Confirm account and Lake Formation prerequisites.
- Test schema changes and revoked permissions.
- Measure latency and query costs under representative load.
Signal Take
Treat shared access as a data contract, with a named owner and an agreed change process.
Scope and limitations
The source is a vendor walkthrough. Performance and savings depend on the workload; no benchmark was performed here.
Sources and editorial record
AWS Blog (opens in a new tab)- Source type
- Vendor technical blog
- Source published
- 15 Jul 2026
- Source checked
- 19 Sept 2026
Prepared with AI assistance and checked against the linked source. This is editorial interpretation, not an independent product benchmark. How we work.