Grant "SELECT", "USAGE", “READ_METADATA” privilege for all catalogs, databases (or schemas) and tables for "protecto_group".
Create medium sized sql warehouse for Protecto and give "can manage" permission for "protecto_group".
Grant “can manage” permission to “protecto_group” in all SQL warehouses on which the Protecto application needs to analyze. This is required to retrieve access logs (audit logs).