# Installation

Setting up takes a few minutes: install the app, approve two things, and grant it read access to the tables
you want to enrich.

## 1. Get the app

1. In Snowsight, open **Data Products » Marketplace** and search for **Tomba**.
2. Open the listing and click **Get**. Choose a name for the app (the examples in these docs use `TOMBA`) and
   a warehouse. An **X-Small** warehouse is enough: the work waits on the network, not on compute.
3. Try it for free first if the listing offers a trial (see [Pricing and limits](./pricing-and-limits#trial)).

## 2. Approve the connection and the privileges

Open the app from **Data Products » Apps » TOMBA** and go to the **Security** tab:

- **Tomba API connection:** approve it. It lets the app reach only `api.tomba.io` (HTTPS) and nothing else.
  Until you approve it, every lookup stops with a message asking you to.
- **Privileges:** the app asks for `CREATE EXTERNAL ACCESS INTEGRATION` (to create that connection) and
  `EXECUTE TASK` / `EXECUTE MANAGED TASK` (to run background runs, auto-resume and schedules on serverless
  compute). They are usually granted automatically; if not, grant them on the same tab.

## 3. Let the app read your tables

The app only reads tables you grant it. Run this as the owner of each table (views work too):

```sql
GRANT USAGE  ON DATABASE crm              TO APPLICATION TOMBA;
GRANT USAGE  ON SCHEMA   crm.public       TO APPLICATION TOMBA;
GRANT SELECT ON TABLE    crm.public.leads TO APPLICATION TOMBA;
```

If you forget, the app tells you which `GRANT` statements to run.

## 4. Give your team access

The app has two roles:

| Role         | Can                                                                                      |
| ------------ | ---------------------------------------------------------------------------------------- |
| `app_public` | Run every tool, read results and history, create background runs, resume and cancel runs |
| `app_admin`  | Everything above, plus change settings, clear the cache, and create or change schedules  |

```sql
GRANT APPLICATION ROLE TOMBA.app_public TO ROLE analyst;
GRANT APPLICATION ROLE TOMBA.app_admin  TO ROLE sysadmin;
```

## 5. Check the setup

```sql
CALL TOMBA.core.status();
```

Look for `external_access` with status `APPROVED`. `activated` turns true on your first lookup, when the app
connects to Tomba by itself. The result also shows your daily lookup limit and what is left today.

Then continue with the [Quickstart](./quickstart).

<Callout type="info">
    Updates are installed by Snowflake. You can also upgrade from **Data
    Products » Apps** when a new version is available; your results and history
    are kept.
</Callout>
