Overview
Netskope DSPM enables you to scan data within GCP Spanner data stores, supporting Discovery, Classification, and Automation to assess security risks associated with your data accurately. Follow the instructions below to configure and connect your GCP Spanner data store.
Prerequisites:
Before connecting a GCP Data Store, be sure you have completed all the steps and the setup needed to onboard GCP projects.
Configure GCP Spanner Permissions
The following permissions are required within your custom GCP IAM role to enable scanning of Spanner data stores.
Cloud Spanner Viewer Cloud Spanner Database Reader
Read more about enabling these permissions in the Manual Onboarding for GCP Projects article.
Retrieve Connection Information
Netskope DSPM requires additional information to communicate with your Spanner instance. Please follow the steps below to identify the connection values for later use within Netskope DSPM.
- Go to your GCP Console and click on the name of the Spanner instance you wish to scan.
- For the database instance you wish Netskope DSPM to scan, note the following values. These will later be used within Netskope DSPM to connect your data store.
| Database Value | Corresponding Netskope DSPM Value | Color | Example |
|---|---|---|---|
| Project ID | Data Store Endpoint | Yellow | ![]() |
| Spanner Instance Name | Data Store Endpoint | Green | ![]() |
| Database Name | Data Store Endpoint | Blue | ![]() |
Connect Your Data Store
Step 1: Provide Credentials
Follow these steps to configure the connection:
-
Go to Data Stores > Data Store Inventory.
-
Click CONNECT A DATA STORE in the upper right.
Tip: Alternatively, if the data store was already found by auto-discovery, go to the Discovered tab and click Connect in the Actions column.

-
In the Connect a Data Store window, click the data store icon you wish to connect.
-
In the Provide Credentials section, complete the following fields:
| Field | Value |
|---|---|
| Select GCP Account | Select one of the GCP Accounts defined when connecting GCP infrastructure. If only one GCP account is configured, the field will default. |
| Data Store Identifier | Provide a friendly name to describe this data store. This value is displayed in other Netskope DSPM screens such as Policy Management and Classification Management. |
| Data Store Endpoint | Endpoint format is /projects/{project ID}/instances/{spanner instance name}/databases/{database name}. Obtain the bracketed values in Retrieve Connection Information section above. The example here would read: /projects/sapient-cycle-1234/instances/das-development-spanner/databases/dev_googlesql |
| Authentication Method | GCP IAM Role is used to authenticate this data store, which was configured during Infrastructure Onboarding. |
| Scan Frequency | Controls how often your Data Store is reviewed for changes, Netskope DSPM’s recommended frequency is defaulted, which you can override (if desired). |
| Sidecar Pool | If you will use sidecars to monitor this data store, select a sidecar pool with network visibility to said data store. This field is displayed when there is at least one defined sidecar pool. To learn more, please visit our Sidecar Administration article. |
Step 2: Scanning Infrastructure
- Click Next.
- When the Select Capabilities tab appears, complete the following fields:
- Assign a Data Owner (Optional): Select one or more users responsible for this data store.
- Which databases should Netskope DSPM scan?: Select the specific data stores and schemas to monitor, if applicable.
- Features: Select the features you want to enable.
| Capability | Supported for GCP Spanner |
|---|---|
| Discovery | Yes |
| Privilege Analysis | No |
| Shadow Data Analysis | No |
| Classification | Yes |
| Data-In-Use Monitoring | No |
| Automation | Yes |
Step 3: Review and Save
- Click Save.
- When the Review tab appears, the system validates your configuration. If there are any issues, follow the on-screen instructions to fix them.
- Click Save to finalize the connection.




