Iceberg Read Restrictions: portable policy needs trusted engines
Portable table access needs a policy contract between the catalog and trusted query engines.
What happened
Snowflake’s 4 September engineering post describes Read Restrictions, an extension to the Apache Iceberg REST Catalog specification. Catalog responses can carry caller-specific row filters and column masks to trusted readers. The post describes the specification and end-to-end proofs of concept, with engine integration still needed. It is not a claim that every Iceberg reader already enforces these controls.
Why it matters
Open formats make it easier for several engines to operate over the same physical data. That creates a governance problem if security policies live only inside one compute engine. Policy therefore has to become more closely associated with the shared data and metadata layer.
Who it affects: Data governance teams, lakehouse architects, security engineers and organisations implementing multi-engine Iceberg architectures.
What to do next
For every open table, answer a simple question: If another approved engine reads this table tomorrow, which governance controls follow it? Audit masking, row filters, identities and policy ownership across engines rather than validating only the primary query platform.
Signal Take
Open data without portable governance is only partially open. The long-term value of formats such as Iceberg will depend not just on cross-engine readability, but on whether meaning and policy can travel with the data.
Scope and limitations
Policy portability requires compatible trusted engines and catalog configuration. The specification does not make enforcement automatic for all readers.
Sources and editorial record
Snowflake — interoperable governance (opens in a new tab)- Source type
- Vendor documentation or announcement
- Source published
- 4 Sept 2026
- Source checked
- 19 Sept 2026
Prepared with AI assistance and checked against the linked source. This is editorial interpretation, not an independent product benchmark. How we work.