New function ALL_USER_DETAILS: Returns name and email to all sessions in an account (Pending)

Attention

This behavior change is in the 2026_08 bundle.

For the current status of the bundle, refer to Bundle history.

Snowflake is adding a new function, ALL_USER_DETAILS, that returns the name, first name, last name, and email address of active users in the account whose name matches a given prefix.

Before the change:

Only user names were discoverable account-wide, through ALL_USER_NAMES(). Resolving a specific user’s first name, last name, or email required resolving that user through ENTITY_DETAIL('USER', ...), which requires the caller to hold a resolvable object, or through SHOW USERS, which is too slow for account-wide lookups.

After the change:

A new function, ALL_USER_DETAILS(prefix, limit), returns the name, first name, last name, and email address of all active users whose name begins with prefix, up to limit rows, plus a hiddenCount of matches above the limit. The function resolves no object, so any session in the account can call it.

The prefix argument is case-sensitive, matching the prefix-matching behavior of SHOW USERS.

This behavior change is most likely to affect accounts where a user’s real name or email address is considered sensitive. The highest impact is on multi-tenant and Powered by Snowflake accounts that host several of their own end customers in one Snowflake account, separated only by role-based access control, and on security-sensitive customers who deliberately obscure account membership.

Actions required

Accounts that do not want user names and email addresses disclosed to all sessions can run:

ALTER ACCOUNT SET INCLUDE_PROTECTED_USER_DATA = FALSE;

INCLUDE_PROTECTED_USER_DATA is an ordinary account parameter, not a bundle control, so it continues to apply after the 2026_08 bundle reaches General Availability. Disabling the 2026_08 bundle only defers this change; it stops preventing disclosure once the bundle is Generally Enabled.

To check the current setting and confirm the effective behavior:

SHOW PARAMETERS LIKE 'INCLUDE_PROTECTED_USER_DATA' IN ACCOUNT;

Then, from a low-privilege role, call ALL_USER_DETAILS('A', 10) and confirm the output matches the intended disclosure posture for the account.

Ref: 2429