Blog
0 min read

From zero to production: a comprehensive guide to managing Snowflake with Terraform

Written by
Greg Hinc

Manual clicks don’t scale. As Snowflake environments grow, managing them through the UI or ad-hoc scripts quickly leads to drift, blind spots, and compliance risks. What starts as a quick fix often becomes a challenge that slows delivery and exposes the business to security gaps.

Infrastructure as Code with Terraform solves these challenges by bringing software engineering discipline to Snowflake management. Using Terraform’s declarative language, engineers define the desired state of their Snowflake environment, track changes with version control, and apply them consistently across environments. Terraform communicates with Snowflake’s APIs through the official snowflakedb/snowflake provider, translating configuration into the SQL statements and API calls that keep your platform aligned and secure.

This guide provides a complete walkthrough of how to manage Snowflake with Terraform. From provisioning core objects like databases, warehouses, and schemas to building scalable role hierarchies and implementing advanced governance policies such as dynamic data masking.

Section 1: bootstrapping Terraform for secure Snowflake automation

The initial setup of the connection between Terraform and Snowflake is the most critical phase of the entire process. A secure and correctly configured foundation is paramount for reliable and safe automation. This section focuses on establishing this connection using production-oriented best practices, specifically tailored for non-interactive, automated workflows typical of CI/CD pipelines.

1.1 The principle of least privilege: the terraform service role

Terraform should not operate using a personal user account. Instead, a dedicated service user must be created specifically for Terraform automation. Before any Terraform code can be executed, a one-time manual bootstrapping process must be performed within the Snowflake UI or via SnowSQL. This involves using the ACCOUNTADMIN role to create the dedicated service user and a high-level role for Terraform's initial operations.

The following SQL statements will create a TERRAFORM_SVC service user and grant it the necessary

-- Use the highest-level role to create users and grant system roles
USE ROLE ACCOUNTADMIN;

-- Create a dedicated service user for Terraform
-- The RSA_PUBLIC_KEY will be set in the next step
CREATE USER TERRAFORM_SVC
	TYPE = SERVICE
  COMMENT = 'Service user for managing Snowflake infrastructure via Terraform.'
  RSA_PUBLIC_KEY = '<YOUR_PUBLIC_KEY_CONTENT_HERE>';

-- Grant the necessary system roles to the Terraform service user
GRANT ROLE SYSADMIN TO USER TERRAFORM_SVC;
GRANT ROLE SECURITYADMIN TO USER TERRAFORM_SVC;

Granting SYSADMIN and SECURITYADMIN to the service user is a necessary starting point for the infrastructure management. The SYSADMIN role holds the privileges required to create and manage account-level objects like databases and warehouses. The SECURITYADMIN role is required for managing security principals, including users, roles, and grants.

1.2 Authentication: the key to automation

The choice of authentication method is important. The Snowflake provider supports several authentication mechanisms, including basic password, OAuth, and key-pair authentication. For any automated workflow, especially within a CI/CD context, key-pair authentication is the industry-standard and recommended approach.

A CI/CD pipeline, such as one running in GitHub Actions, is a non-interactive environment. Basic password authentication is a significant security risk and not recommended. This leaves key-pair authentication as the only method that is both highly secure, as it avoids transmitting passwords, and fully automatable.

The following table provides a comparative overview of the primary authentication methods available in the Snowflake provider, reinforcing the recommendation for key-pair authentication in production automation scenarios.

Table 1: Snowflake provider authentication methods

Method Primary Use Case Security Profile CI/CD Suitability
Password Local development, quick tests Low. Exposes credentials in state or environment variables. Low. Requires secure secret management; often blocked by MFA.
OAuth User-delegated access for third-party applications High. Token-based, short-lived credentials. Medium. Complex to set up for non-interactive server-to-server flows.
Key-Pair Recommended for Automation. Service accounts, CI/CD pipelines. High. Asymmetric cryptography; no passwords transmitted. High. Designed for secure, non-interactive authentication.

To implement key-pair authentication, an RSA key pair must be generated. The following openssl commands will create a 2048-bit private key in the required PKCS#8 format and its corresponding public key:

Bash

# Navigate to a secure directory, such as ~/.ssh
cd ~/.ssh

# Generate an unencrypted 2048-bit RSA private key in PKCS#8 format
openssl genrsa 2048 | openssl pkcs8 -topk8 -inform PEM -out snowflake_terraform_key.p8 -nocrypt

# Extract the public key from the private key
openssl rsa -in snowflake_terraform_key.p8 -pubout -out snowflake_terraform_key.pub

After generating the keys, the content of the public key file (snowflake_terraform_key.pub), including the -----BEGIN PUBLIC KEY----- and -----END PUBLIC KEY----- headers, must be copied and pasted into the ALTER USER statement from the previous step to associate it with the TERRAFORM_SVC user. For enhanced security, the private key itself can be encrypted with a passphrase. The Snowflake provider supports this by using the private_key_passphrase argument in the provider configuration.

1.3 Provider configuration: connecting Terraform to Snowflake

With the service user created and the key-pair generated, the final step is to configure the Snowflake provider in the Terraform project. This is typically done in a providers.tf file.

The foundational configuration requires defining the snowflakedb/snowflake provider and setting the connection parameters.

terraform {
  required_providers {
    snowflake = {
      source  = "snowflakedb/snowflake"
      version = ">= 2.8.0" // Best practice: pin to a major version to avoid breaking changes
    }
  }
}

provider "snowflake" {
  organization_name = var.snowflake_org_name
  account_name      = var.snowflake_account_name
  user              = var.snowflake_user         // e.g., "TERRAFORM_SVC"
  role              = "SYSADMIN"                 // Default role for the provider's operations
  authenticator     = "SNOWFLAKE_JWT"
  private_key       = var.snowflake_private_key
}

It is critical that sensitive values, especially the private_key, are never hardcoded in configuration files. The recommended approach is to define them as input variables marked as sensitive = true and supply their values through secure mechanisms like environment variables (e.g., TF_VAR_snowflake_private_key) or integration with a secrets management tool like GitHub Secrets or AWS Secrets Manager.

A common source of initial connection failures is the incorrect identification of the organization_name and account_name. These values can be retrieved with certainty by executing the following SQL queries in the Snowflake UI: SELECT CURRENT_ORGANIZATION_NAME(); and SELECT CURRENT_ACCOUNT_NAME();. Providing these simple but effective commands can prevent significant user frustration.

For more mature IaC implementations that strictly adhere to the principle of least privilege, Terraform supports the use of aliased providers. This powerful pattern allows for the definition of multiple provider configurations within the same project, each assuming a different role. This mirrors Snowflake's own best practices, where object creation (SYSADMIN) is separated from security management (SECURITYADMIN).

The following example demonstrates how to configure aliased providers:

# Default provider uses SYSADMIN for object creation (e.g., databases, warehouses)
provider "snowflake" {
  alias             = "sysadmin"
  organization_name = var.snowflake_org_name
  account_name      = var.snowflake_account_name
  user              = var.snowflake_user
  private_key       = var.snowflake_private_key
  authenticator     = "SNOWFLAKE_JWT"
  role              = "SYSADMIN"
}

# Aliased provider for security-related objects (e.g., roles, users, grants)
provider "snowflake" {
  alias             = "securityadmin"
  organization_name = var.snowflake_org_name
  account_name      = var.snowflake_account_name
  user              = var.snowflake_user
  private_key       = var.snowflake_private_key
  authenticator     = "SNOWFLAKE_JWT"
  role              = "SECURITYADMIN"
}

When using aliased providers, individual resource blocks must explicitly specify which provider to use via the provider meta-argument (e.g., provider = snowflake.securityadmin). This ensures that each resource is created with the minimum necessary privileges, enforcing a robust security posture directly within the code.

Section 2: provisioning core Snowflake infrastructure

Once the secure connection is bootstrapped, Terraform can be used to define and manage the fundamental building blocks of the Snowflake environment. This section provides code examples for creating databases, virtual warehouses, and schemas - the foundational components for any data workload.

2.1 Laying the foundation: databases

The database is the top-level container for schemas and tables in Snowflake. The snowflake_database resource is used to provision and manage these containers.

The following HCL example creates a primary database for analytics workloads, demonstrating the use of the aliased sysadmin provider and an optional parameter for data retention.

‍resource "snowflake_database" "analytics_db" {
  provider = snowflake.sysadmin // Explicitly use the sysadmin provider for object creation

  name    = "ANALYTICS"
  comment = "Primary database for analytics workloads managed by Terraform."

  // Optional: Configure Time Travel data retention period.
  // This setting can have cost implications.
  data_retention_time_in_days = 30
}

A core strength of Terraform is its ability to manage dependencies implicitly through resource references. In this example, once the analytics_db resource is defined, other resources, such as schemas, can reference its attributes (e.g., snowflake_database.analytics_db.name).

2.2 Compute power: warehouses

Virtual warehouses are the compute engines in Snowflake, responsible for executing queries and data loading operations. FinOps makes a difference, especially once usage grows.The snowflake_warehouse resource provides comprehensive control over their configuration, enabling a balance between performance and cost.

This example defines a standard virtual warehouse for analytics and business intelligence tools, showcasing parameters for cost optimization and scalability.

resource "snowflake_warehouse" "analytics_wh" {
  provider = snowflake.sysadmin

  name    = "ANALYTICS_WH"
  comment = "Warehouse for the analytics team and BI tools."

  // Define the compute capacity of the warehouse.
  warehouse_size = "X-SMALL"

  // Cost-saving measures: suspend the warehouse when idle.
  auto_suspend = 60 // Suspend after 60 seconds of inactivity.
  auto_resume  = true

  // Optional: Configure for multi-cluster for higher concurrency.
  min_cluster_count = 1
  max_cluster_count = 4
  scaling_policy    = "ECONOMY" // Prioritize conserving credits over starting clusters quickly.
}

The parameters in this resource directly impact both performance and billing. warehouse_size determines the raw compute power and credit consumption per second. auto_suspend is a critical cost-control feature, ensuring that credits are not consumed when the warehouse is idle. For workloads with high concurrency needs, the min_cluster_count, max_cluster_count, and scaling_policy parameters allow the warehouse to dynamically scale out to handle query queues, and then scale back in to conserve resources. Managing these settings via Terraform ensures that cost and performance policies are consistently applied and version-controlled.

2.3 Organizing your data: schemas

Schemas are logical groupings of database objects like tables and views within a database. The snowflake_schema resource is used to create and manage these organizational units.

The following HCL creates a RAW schema within the ANALYTICS database defined earlier.

resource "snowflake_schema" "raw_data" {
  provider = snowflake.sysadmin

  // Create an explicit dependency on the database resource.
  database = snowflake_database.analytics_db.name

  name    = "RAW"
  comment = "Schema for raw, unprocessed data ingested from source systems."
}

It is important to note that when a new database is created in Snowflake, it automatically includes a default schema named PUBLIC. While this schema is created outside of Terraform's management, administrators should be aware of its existence. For environments that require strict access control, it is a common practice to immediately revoke all default privileges from the

PUBLIC schema to ensure it is not used inadvertently. Terraform can be used to manage this revocation if desired, but the schema itself will not be in the Terraform state unless explicitly imported.

Section 3: mastering access control with role hierarchies

Effective access control is a cornerstone of data governance and security. Snowflake's Role-Based Access Control (RBAC) model is exceptionally powerful, particularly its support for role hierarchies. Managing this model via Terraform provides an auditable, version-controlled, and scalable approach to permissions management. This section details how to construct a robust RBAC framework using a best-practice model of functional and access roles. At scale, keeping this clean is less about writing the first version and more about maintaining standards over time, which is why Platform Team as a Service often owns RBAC and grants as the platform grows.

3.1 The building blocks: creating account roles

The foundation of the RBAC model is the creation of roles. A recommended pattern is to create two distinct types of roles:

  • Functional roles: These roles represent a job function or a persona, such as DATA_ANALYST or DATA_ENGINEER. Users are granted these roles.
  • Access roles: These roles represent a specific set of privileges on a specific set of objects, such as SALES_DB_READ_ONLY or RAW_SCHEMA_WRITE. These roles are granted to functional roles, not directly to users.

This separation decouples users from direct permissions, making the system vastly more scalable and easier to manage. The snowflake_account_role resource is used to create both types of roles

// Define a functional role representing a user persona.
resource "snowflake_account_role" "data_analyst" {
  provider = snowflake.securityadmin // Use the securityadmin provider for role management

  name    = "DATA_ANALYST"
  comment = "Functional role for users performing data analysis and reporting."
}

// Define an access role representing a specific set of privileges.
resource "snowflake_account_role" "analytics_db_read_only" {
  provider = snowflake.securityadmin

  name    = "ANALYTICS_DB_READ_ONLY"
  comment = "Grants read-only access to all objects in the ANALYTICS database."
}

3.2 Constructing the hierarchy: granting roles to roles

The true power of Snowflake's RBAC model is realized by creating hierarchies of roles. By granting access roles to functional roles, a logical and maintainable privilege structure is formed. If a data analyst needs access to a new data source, the corresponding access role is granted to the DATA_ANALYST functional role once, rather than granting privileges to every individual analyst. This pattern is essential for managing permissions at scale.

The snowflake_grant_account_role resource is used to create these parent-child relationships between roles. It is important to use this resource, as the older snowflake_role_grants resource is deprecated.

The following example demonstrates how to grant the ANALYTICS_DB_READ_ONLY access role to the DATA_ANALYST functional role, and then nest the functional role under the system SYSADMIN role to complete the hierarchy.

// Grant the access role to the functional role.
// This gives all members of DATA_ANALYST the privileges of ANALYTICS_DB_READ_ONLY.
resource "snowflake_grant_account_role" "grant_read_access_to_analyst" {
  provider = snowflake.securityadmin

  role_name        = snowflake_account_role.analytics_db_read_only.name
  parent_role_name = snowflake_account_role.data_analyst.name
}

// Grant the functional role to SYSADMIN to create a clear role hierarchy.
// This allows system administrators to manage and assume the functional role.
resource "snowflake_grant_account_role" "grant_analyst_to_sysadmin" {
  provider = snowflake.securityadmin

  role_name        = snowflake_account_role.data_analyst.name
  parent_role_name = "SYSADMIN"
}

3.3 Assigning privileges to access roles

With the role structure in place, the final step is to grant specific object privileges to the access roles. The snowflake_grant_privileges_to_account_role resource is a consolidated and powerful tool for this purpose. This resource has evolved significantly in the Snowflake provider; older versions required separate grant resources for each object type (e.g., snowflake_database_grant), which resulted in verbose and repetitive code. The modern resource uses a more complex but flexible block structure (on_account_object, on_schema, etc.) to assign privileges. Users migrating from older provider versions may find this a significant but worthwhile refactoring effort.

This example grants the necessary USAGE and SELECT privileges to the ANALYTICS_DB_READ_ONLY access role.

// Grant USAGE privilege on the database to the access role.
resource "snowflake_grant_privileges_to_account_role" "grant_db_usage" {
  provider          = snowflake.securityadmin
  account_role_name = snowflake_account_role.analytics_db_read_only.name
  privileges        = ["USAGE"]
  
  on_account_object {
    object_type = "DATABASE"
    object_name = snowflake_database.analytics_db.name
  }
}

// Grant USAGE privilege on the schema to the access role.
resource "snowflake_grant_privileges_to_account_role" "grant_schema_usage" {
  provider          = snowflake.securityadmin
  account_role_name = snowflake_account_role.analytics_db_read_only.name
  privileges        = ["USAGE"]

  on_schema {
    // Use the fully_qualified_name for schema-level objects.
    schema_name = snowflake_schema.raw_data.fully_qualified_name
  }
}

// Grant SELECT on all existing tables in the schema.
resource "snowflake_grant_privileges_to_account_role" "grant_all_tables_select" {
    provider          = snowflake.securityadmin
    account_role_name = snowflake_account_role.analytics_db_read_only.name
    privileges        = ["SELECT"]
    
    on_schema_object {
        all {
            object_type_plural = "TABLES"
            in_schema          = snowflake_schema.raw_data.fully_qualified_name
    }
  }
}

// Grant SELECT on all FUTURE tables created in the schema.
resource "snowflake_grant_privileges_to_account_role" "grant_future_tables_select" {
  provider          = snowflake.securityadmin
  account_role_name = snowflake_account_role.analytics_db_read_only.name
  privileges        = ["SELECT"]

  on_schema_object {
    future {
      object_type_plural = "TABLES"
      in_schema          = snowflake_schema.raw_data.fully_qualified_name
    }
  }
}

A particularly powerful feature demonstrated here is the use of the future block. Granting privileges on future objects ensures that the access role will automatically have the specified permissions on any new tables created within that schema. This dramatically reduces operational overhead, as permissions do not need to be manually updated every time a new table is deployed. However, it is important to understand Snowflake's grant precedence: future grants defined at the schema level will always take precedence over those defined at the database level. This can lead to "insufficient privilege" errors if not managed carefully across different roles and grant levels.

3.4 An optional "Audit" role for bypassing data masks

In certain scenarios, such as internal security audits or compliance reviews, it may be necessary for specific, highly-trusted users to view data that is normally protected by masking policies. Creating a dedicated "audit" role for this purpose provides a controlled and auditable mechanism to bypass data masking when required.

This role should be considered a highly privileged functional role and granted to users with extreme care.

// Define a special functional role for auditing PII data.
resource "snowflake_account_role" "pii_auditor" {
  provider = snowflake.securityadmin

  name    = "PII_AUDITOR"
  comment = "Functional role for users who need to view unmasked PII for audit purposes."
}

Crucially, creating this role is not enough. For it to be effective, every relevant masking policy must be explicitly updated to include logic that unmasks data for members of the PII_AUDITOR role. This ensures that the ability to view sensitive data is granted on a policy-by-policy basis. An example of how to modify a masking policy to incorporate this audit role is shown in the following section.

Section 4: advanced data governance with dynamic data masking

Moving beyond infrastructure provisioning, Terraform can also codify and enforce sophisticated data governance policies. Snowflake's Dynamic Data Masking is a powerful feature for protecting sensitive data at query time. By managing these policies with Terraform, organizations can ensure that data protection rules are version-controlled, auditable, and consistently applied across all environments.

4.1 Defining the masking logic

A masking policy is a schema-level object containing SQL logic that determines whether a user sees the original data in a column or a masked version. The decision is made dynamically at query time based on the user's context, most commonly their active role.

The snowflake_masking_policy resource is used to define this logic. The policy's body contains a CASE statement that evaluates the user's session context and returns the appropriate value.

The following example creates a policy to mask email addresses for any user who is not in the DATA_ANALYST or PII_AUDITOR role.

resource "snowflake_masking_policy" "email_mask" {
  provider = snowflake.sysadmin // Policy creation often requires SYSADMIN or a dedicated governance role

  name     = "EMAIL_MASK"
  database = snowflake_database.analytics_db.name
  schema   = snowflake_schema.raw_data.name
  
  // Defines the signature of the column the policy can be applied to.
  // The first argument is always the column value to be masked.
  argument {
    name = "email_val"
    type = "VARCHAR"
  }
  
  // The return data type must match the input data type.
  return_type = "VARCHAR"

  // The core masking logic is a SQL expression.
  body = <<-EOF
    CASE
      WHEN IS_ROLE_IN_SESSION('DATA_ANALYST') OR IS_ROLE_IN_SESSION('PII_AUDITOR') THEN email_val
      ELSE '*********'
    END
  EOF

  comment = "Masks email addresses for all roles except DATA_ANALYST and PII_AUDITOR."
}

The SQL expression within the body argument offers immense flexibility. It can use various context functions (like CURRENT_ROLE() or IS_ROLE_IN_SESSION()) and even call User-Defined Functions (UDFs) to implement complex logic. However, this flexibility means the logic itself is not validated by Terraform's syntax checker; it is sent directly to Snowflake for validation during the

terraform apply step. It is also a strict requirement that the data type defined in the argument block and the return_type must match the data type of the column to which the policy will eventually be applied.

4.2 Applying the policy to a column

Creating a masking policy is only the first step; it does not protect any data on its own. The policy must be explicitly applied to one or more table columns. This crucial second step is often a point of confusion for new users, who may create a policy and wonder why data is still unmasked. The snowflake_table_column_masking_policy_application resource creates this essential link between the policy and the column.

The following example demonstrates how to apply the EMAIL_MASK policy to the EMAIL column of a CUSTOMERS table.

// For this example, we assume a 'CUSTOMERS' table with an 'EMAIL' column
// already exists in the 'RAW' schema. In a real-world scenario, this table
// might also be managed by Terraform or by a separate data loading process.
// We use a data source to reference this existing table.
data "snowflake_table" "customers" {
  database = snowflake_database.analytics_db.name
  schema   = snowflake_schema.raw_data.name
  name     = "CUSTOMERS"
}

// Apply the masking policy to the specific column.
resource "snowflake_table_column_masking_policy_application" "apply_email_mask" {
  provider = snowflake.sysadmin

  table_name  = "\"${data.snowflake_table.customers.database}\".\"${data.snowflake_table.customers.schema}\".\"${data.snowflake_table.customers.name}\""
  column_name = "EMAIL" // The name of the column to be masked

  masking_policy_name = snowflake_masking_policy.email_mask.fully_qualified_name
  
  // An explicit depends_on block ensures that Terraform creates the policy
  // before attempting to apply it, preventing race conditions.
  depends_on = [
    snowflake_masking_policy.email_mask
  ]
}

This two-step process—defining the policy logic and then applying it - provides a clear and modular approach to data governance. The same policy can be defined once and applied to many different columns across multiple tables, ensuring that the masking logic is consistent and centrally managed.

Conclusion: the path to mature Snowflake IaC

This guide has charted a course from the initial, manual bootstrapping of a secure connection to the automated provisioning and governance of a production-grade Snowflake environment. To ensure the long-term success and scalability of managing Snowflake with Terraform, several key practices should be adopted as standard procedure:

  • Version control: All Terraform configuration files must be stored in a version control system like Git. This provides a complete, auditable history of all infrastructure changes and enables collaborative workflows such as pull requests for peer review before any changes are applied to production.
  • Remote state management: The default behaviour of Terraform is to store its state file locally. In any team or automated environment, this is untenable. A remote backend, such as an Amazon S3 bucket with a DynamoDB table for state locking, must be configured. This secures the state file, prevents concurrent modifications from corrupting the state, and allows CI/CD pipelines and team members to work from a consistent view of the infrastructure.
  • Modularity: As the number of managed resources grows, monolithic Terraform configurations become difficult to maintain. Code should be refactored into reusable modules. For instance, a module could be created to provision a new database along with a standard set of access roles and default schemas. This promotes code reuse, reduces duplication, and allows for more organized and scalable management of the environment.
  • Provider versioning: The Snowflake Terraform provider is actively evolving. To prevent unexpected breaking changes from new releases, it is crucial to pin the provider to a specific major version in the terraform block (e.g., version = "~> 2.8"). This allows for intentional, planned upgrades. When upgrading between major versions, it is essential to carefully review the official migration guides, as significant changes, particularly to grant resources, may require a concerted migration effort.

With this robust foundation in place, the path is clear for expanding automation to encompass even more of Snowflake's capabilities. The next logical steps include using Terraform to manage snowflake_network_policy for network security, snowflake_row_access_policy for fine-grained data filtering, and snowflake_task for orchestrating SQL workloads. Ultimately, the entire workflow should be integrated into a CI/CD pipeline, enabling a true GitOps model where every change to the Snowflake environment is proposed, reviewed, and deployed through a fully automated and audited process. By embracing this comprehensive approach, organizations can unlock the full potential of their data platform, confident in its security, scalability, and operational excellence.

Why Snowstack for Terraform and Snowflake

Automation without expertise can still fail. Terraform gives you the tools, but it takes experience and the right design patterns to turn Snowflake into a secure, cost-efficient, and scalable platform. The hard part is deciding what “good” looks like in your Snowflake account and making that repeatable across teams, environments, and change cycles.

That is where Snowstack comes in. As a Snowflake-first consulting partner, we help organizations move beyond trial-and-error scripts to fully automated, production-grade environments. Our engineers design secure architectures, embed Terraform best practices, and ensure governance and cost controls are built in from day one.

FAQs

Start with the stable building blocks: warehouses, databases, schemas, roles, and grants. Codifying these gives you a repeatable baseline, clearer reviews, and fewer "who changed what" moments. If you want help turning that into a production standard, our Snowflake consulting is built for exactly that.

Yes. A dedicated service user keeps changes auditable, avoids personal-account dependencies, and makes it easier to enforce least privilege. We usually set this up during a Snowflake implementation so the roles and permissions are clean from the start.

Key pair authentication is the go-to approach for automation because it avoids passwords and supports key rotation. The real "gotchas" are how you store the private key, how you rotate it without downtime, and how you lock down the service role. If you want a proven baseline, that's a common starting point in Snowflake consulting.

Drift usually comes from "out-of-band" changes in Snowsight, differences in naming/identifiers, or having more than one resource trying to own the same privilege set. The fix is to pick one source of truth, standardize object identifiers, and keep grants/ownership patterns consistent. When teams need ongoing ownership, that's what Platform Team as a Service is for.

Make cost controls part of the code, not tribal knowledge. That means codifying warehouse sizing rules, auto suspend, scaling settings, and environment defaults, then pairing it with a usage review cadence. If savings is the goal, this is exactly the focus of our FinOps work.

Provider upgrades can include grant model changes and deprecations, which can break older configurations if you're still using removed resources. Treat upgrades like a controlled migration: update in steps, migrate grant resources intentionally, and avoid mixing old and new grant patterns in the same scope. If you want us to review the upgrade path before you roll it out, start with Snowflake consulting.

Yes, but do it in phases. First codify a baseline (core warehouses, core roles, and standard grants), then gradually bring the rest under management through imports or controlled rebuilds. The goal is to reduce risk, not "flip a switch" overnight. We typically approach this through Snowflake consulting or a scoped implementation.

Learn more about Snowflake from top experts

Join data leaders who get Snowflake insights and updates delivered straight to their inbox.

Thanks for joining us!

We’ll keep you posted with fresh updates and resources.

Oops! Something went wrong while submitting the form.
Insights

Learnings for data leaders

Blog
5 min read

7 Snowflake Security Essentials for Mid-Market Teams

The 2024 Snowflake breaches hit 165 organizations, mostly through stolen credentials and missing MFA. Mid-market teams need enterprise-grade controls without an enterprise-sized security team. Here are the seven security and governance essentials to get right during implementation, not after the first audit.

Read more

Mid-market data and analytics leaders face a unique challenge when implementing Snowflake. You need enterprise-grade security controls but often lack the dedicated security teams that larger organizations maintain. The 2024 Snowflake breaches proved what can happen when access controls are weak. With 165 organizations affected, the lesson is clear: security must be part of the implementation, not an afterthought. Snowstack helps enterprises implement Snowflake security with governance frameworks embedded from day one, ensuring mid-market teams achieve compliance confidence without slowing down delivery.

This guide breaks down seven security and governance essentials that mid-market teams need to address when deploying Snowflake. Each essential covers what to implement, why it matters, and how to get it right the first time.

Key Takeaways: 7 Snowflake Security Essentials for Mid-Market Teams

  • Role-based access control structures permissions around business functions rather than individual users for scalable governance.
  • Multi-factor authentication blocks credential-based attacks, which caused most recent Snowflake security incidents.
  • Data encryption at rest and in transit protects sensitive information from unauthorized access and interception.
  • Network policies restrict platform access to approved IP ranges and reduce external attack surface.
  • Snowstack embeds governance controls during initial architecture design, helping mid-market teams achieve 100% audit readiness.

Security and Governance Essentials for Mid-Market Snowflake Implementations

1. Role-Based Access Control and Least Privilege

RBAC forms the foundation of Snowflake security. Instead of granting privileges directly to users, you assign privileges to roles and then grant those roles to users. This approach simplifies administration, supports compliance requirements, and makes access audits straightforward.

Mid-market teams should create a structured role hierarchy that separates functional roles from administrative ones. A finance analyst should have read access to reporting tables only. An ETL engineer needs write access to staging schemas. Keep these responsibilities distinct with specific, targeted grants rather than broad database-level permissions.

Critical practices include isolating compute access from data access, using separate roles for warehouse usage and data queries, and reserving ACCOUNTADMIN for emergency situations only.

2. Multi-Factor Authentication Enforcement

MFA blocks the most common attack vector: stolen credentials. The 2024 breaches happened because passwords were compromised and MFA was missing. Enforcing MFA across your entire Snowflake environment is the single most effective step you can take to protect user accounts.

Integrate Snowflake with your existing identity provider through SAML or OAuth for centralized management. Require MFA at the IdP level so all integrated applications, including Snowflake, inherit the same authentication standards. Document break-glass procedures for critical roles in case your SSO provider experiences downtime.

Do not make MFA optional. A universal enforcement policy is the only way to ensure this control cannot be circumvented by individual users.

3. Data Encryption Configuration

Snowflake encrypts data at rest with AES-256 and data in transit with TLS 1.2+ by default. For mid-market organizations handling regulated data, consider customer-managed encryption keys through your cloud provider's Key Management Service. This adds control over key access and the ability to revoke access instantly if needed.

Tri-Secret Secure combines a customer-managed key with Snowflake-managed and cloud provider keys. No single entity can decrypt the data independently. Establish key rotation policies and implement separate keys for development, staging, and production environments.

Monitor your KMS audit logs for unusual key access attempts. Early detection of anomalous activity can prevent security incidents from escalating.

4. Network Policies and IP Allowlisting

Network policies restrict access to your Snowflake environment based on IP addresses. This limits potential attack surface by ensuring only authorized networks can connect to your data platform.

Define allowlists based on your corporate network ranges, VPN endpoints, and trusted partner connections. For organizations with distributed teams, combine network policies with private connectivity options like AWS PrivateLink or Azure Private Link.

Review and update network policies quarterly as your organization's network footprint changes. Remote work and cloud-based tools can introduce new IP ranges that need authorization.

5. Activity Monitoring and Audit Logging

Continuous monitoring of user activities and access patterns identifies potential security threats before they become incidents. Snowflake's ACCOUNT_USAGE schema stores query history, login history, and administrative changes for up to one year.

Forward these logs to your SIEM platform for correlation with other security events across your infrastructure. Configure automated alerts for high-risk activities: ACCOUNTADMIN logins, unusual data export volumes, failed authentication attempts from new locations.

Create visualization dashboards to spot anomalies in query patterns and login trends. A sudden spike in data access outside business hours warrants immediate investigation. Grant access to ACCOUNT_USAGE views only to a dedicated AUDITOR role to preserve log integrity.

6. Data Classification and Dynamic Masking

Data classification identifies and tags sensitive columns, while dynamic masking automatically redacts that data based on the querying user's role. This protects sensitive information without altering source data or limiting legitimate analytics work.

Use Snowflake's EXTRACT_SEMANTIC_CATEGORIES function or partner tools to scan and tag sensitive columns automatically. Create masking policies with conditional logic that returns full values for authorized roles and redacted values for everyone else.

Apply masking policies through classification tags rather than individual columns. Any column tagged as PII automatically inherits the correct masking policy, reducing manual configuration and ensuring consistent protection across your environment.

7. Governance Framework and Compliance Alignment

Mid-market organizations operating under SOC 2, HIPAA, GDPR, or PCI DSS need governance controls built into initial architecture. Retrofitting compliance is expensive and error-prone. Embed lineage tracking, access documentation, and audit trails from day one.

Document your data governance framework including data classification standards, retention policies, access review cadences, and incident response procedures. Regular access reviews, conducted quarterly at minimum, verify that role assignments remain appropriate as team members change responsibilities.

Snowstack delivers Snowflake consulting with compliance expertise for regulated industries. Our implementations achieve 100% audit readiness for SOC 2 and GDPR frameworks with governance controls, access audits, and full traceability embedded during the initial build.

How Mid-Market Teams Can Secure Their Snowflake Platform

Security and governance decisions made during Snowflake implementation determine long-term platform health. Mid-market teams that address these seven essentials from the start avoid costly remediation projects later.

The challenge for many mid-market organizations is internal expertise. Specialized Snowflake knowledge for security architecture, RBAC design, and compliance frameworks requires experience across multiple deployments. Snowstack brings this Snowflake expertise to mid-market teams through Platform Team as a Service, compressing typical implementation timelines while embedding enterprise-grade security controls.

Ready to implement secure Snowflake data governance for your organization? Contact Snowstack to discuss your specific security and compliance requirements.

Contact us to discuss your specific requirements!

FAQs

RBAC assigns privileges to roles rather than to individual users. Users inherit permissions by being granted roles, which simplifies administration and makes access audits straightforward. The model supports least privilege by ensuring users only reach the data their job function requires. Role hierarchy design is part of every AI-Ready Data Governance engagement.

MFA blocks credential-based attacks, which caused most recent Snowflake security incidents. By requiring a second verification factor beyond the password, MFA protects accounts even when credentials have been stolen through phishing or other attacks.

Snowflake encrypts all data at rest with AES-256 and all data in transit with TLS 1.2 or higher by default. Organizations that need additional control can use customer-managed encryption keys through their cloud provider's KMS for tighter key governance and compliance flexibility.

Network policies restrict platform access based on IP address. They define which network ranges can connect to your Snowflake account, reducing attack surface by blocking connection attempts from unauthorized locations.

Quarterly at minimum, with monthly spot checks on high-privilege administrative roles to catch permission drift. Roles tied to employees who have changed positions or left the organization should be reviewed immediately, not at the next scheduled cycle. Teams without the bandwidth to hold that cadence run it through Platform Team as a Service.

Snowflake supports SOC 2, HIPAA, GDPR, PCI DSS, and other regulatory frameworks. The platform ships with access control, encryption, audit logging, and data masking features that meet compliance requirements when configured correctly. Configuration is the operative word, and embedding those controls during the initial build is part of Snowflake Implementation.

Blog
5 min read

7 Things to Know About Snowflake Support Partners

Most Snowflake partner rankings ignore what mid-market teams actually need. Here are seven evaluation criteria that predict whether an engagement delivers, plus the questions worth asking before you sign.

Read more

Choosing a Snowflake consulting and support services partner shapes whether your data platform becomes a competitive asset or an ongoing headache. Generic partner rankings rarely help mid-market data leaders make confident decisions because they overlook the operational realities that matter most during modernization projects.

Mid-market organizations face a distinct set of challenges. Limited internal Snowflake expertise, fluctuating project demands, and strict budget constraints make vendor selection critical. The wrong partner can leave your team managing technical debt for years.

Snowstack helps enterprises implement Snowflake solutions with fast migrations, trusted data platforms, and AI-ready infrastructure designed for speed, compliance, and business growth. This guide covers seven essential evaluation criteria that go beyond certifications and logos.

Quick guide: 7 things to know when choosing Snowflake support partners

  1. Snowstack: Top choice for mid-market teams needing dedicated Snowflake expertise with 90-day delivery
  2. Service model clarity: Understand the difference between project-based and ongoing support
  3. Operational depth: Look for 24/7 monitoring and defined SLAs
  4. Cost optimization focus: Confirm FinOps capabilities that reduce Snowflake spend
  5. AI readiness: Verify Cortex AI and ML pipeline experience
  6. Knowledge transfer: Ensure documentation and training are included
  7. Governance expertise: Check for RBAC, compliance, and audit trail capabilities

How we chose the evaluation criteria for Snowflake support partners

Mid-market data leaders need partners who deliver results without the overhead of large consultancy engagements. We focused on factors that directly impact project success, team productivity, and long-term platform health.

  • Delivery speed: How quickly can the partner move from discovery to production? Faster timelines mean faster business value.
  • Service model flexibility: Does the partner offer project-based work, managed services, or both? Your needs may shift over time.
  • Cost management capability: Can the partner demonstrate measurable Snowflake cost reductions through optimization?
  • AI and advanced analytics readiness: Does the partner have hands-on experience with Cortex AI, ML pipelines, and vector search integration?
  • Governance and compliance track record: Can they implement RBAC, data masking, and audit trails for regulated industries?
  • Knowledge transfer approach: Will your internal team gain skills, or will you remain dependent on the partner indefinitely?

The 7 best things to know for Snowflake support partner evaluation

1. Snowstack: Top Snowflake consulting partner for mid-market modernization

Snowstack delivers Platform Team as a Service, compressing typical 12-month projects into 90-day engagements. The firm specializes in mid-market to enterprise organizations that need dedicated Snowflake expertise without building large internal teams.

Every engagement includes senior architects from start to finish. This differs from larger consultancies where senior resources often disappear after the sales cycle. FinOps cost optimization comes standard, not as an expensive add-on.

Client outcomes include 30 to 50 percent cost reduction and 80 percent faster reporting cycles across pharma, financial services, and FMCG implementations. The structured collaboration model features bi-weekly reviews, backlog planning, and clear RACI ownership.

Snowstack benefits

  • 90-day delivery framework: Enterprise implementations move from discovery to production in compressed timeframes, letting your team see results while larger projects would still be in planning
  • Embedded FinOps: Every engagement includes cost analysis that identifies 30 to 50 percent spending reduction through warehouse right-sizing and query optimization
  • AI-ready architecture: Implementations support Cortex AI integration, vector search, and ML pipeline deployment from day one
  • 24/7 monitoring: SLA-driven support with automated alerting delivers 60 percent faster incident resolution
  • Knowledge transfer built in: Documentation, runbooks, and training reduce long-term consulting dependency
  • Compliance expertise: Governance controls for SOC 2, GDPR, and HIPAA get embedded during initial architecture

Snowstack pros and cons

Pros:

  • Senior architects remain involved throughout the entire engagement
  • Proven delivery across regulated industries including pharma and financial services
  • Transparent methodology with bi-weekly reviews and clear accountability

Cons:

  • Focused specifically on Snowflake rather than multi-platform data strategies
  • Mid-sized firm may have capacity constraints during peak demand periods
  • Engagements require active client participation in reviews and planning sessions

2. Service model clarity: Project-based vs. managed support

Many organizations begin with a migration project and later realize they need ongoing operational support. Understanding the difference between engagement models prevents costly transitions later.

Project-based engagements work for defined initiatives like migrations or platform builds. Managed services make sense when your team lacks the capacity for day-to-day platform operations. Some partners offer hybrid models that combine implementation with ongoing support.

Service model benefits

  • Project-based clarity: Fixed scope and timeline give predictable costs for budget planning
  • Managed service continuity: Ongoing support ensures platform stability without internal hiring
  • Hybrid flexibility: Combine implementation expertise with operational coverage as needs evolve

Service model pros and cons

Pros:

  • Clear engagement boundaries help manage stakeholder expectations
  • Managed services reduce internal team burden during high-demand periods
  • Hybrid models adapt to changing organizational priorities

Cons:

  • Project-based work may leave gaps in ongoing optimization
  • Managed services require trust in external teams for critical operations
  • Hybrid arrangements can create confusion about responsibilities

3. Operational depth: 24/7 monitoring and SLA commitments

Platform stability directly impacts business operations. Partners with operational depth offer monitoring, incident response, and defined service level agreements that protect your investment.

Look for partners who implement automated alerting and can demonstrate response time commitments. The difference between reactive support and proactive monitoring often determines whether issues become outages or get resolved before anyone notices.

Operational depth benefits

  • Proactive monitoring: Automated systems catch issues before they impact downstream reporting
  • Defined SLAs: Response and resolution time commitments create accountability
  • Incident documentation: Clear records help identify patterns and prevent recurring problems

Operational depth pros and cons

Pros:

  • 24/7 coverage protects against overnight and weekend incidents
  • SLA commitments give measurable partner accountability
  • Proactive monitoring reduces firefighting for internal teams

Cons:

  • Round-the-clock support adds to engagement costs
  • SLAs only matter if partners actually meet them consistently
  • Monitoring requires proper configuration to avoid alert fatigue

4. Cost optimization focus: FinOps that reduces Snowflake spend

Snowflake's consumption-based pricing can spiral quickly without proper governance. Partners with genuine FinOps expertise demonstrate measurable cost reductions through warehouse right-sizing, query optimization, and automated scaling policies.

Ask for specific examples of cost savings from previous engagements. Credible partners show before-and-after metrics from client environments rather than theoretical projections.

Cost optimization benefits

  • Warehouse right-sizing: Matching compute resources to actual workload demands eliminates waste
  • Query optimization: Efficient queries reduce credit consumption without sacrificing performance
  • Automated scaling: Auto-suspend and resource monitors prevent runaway costs

Cost optimization pros and cons

Pros:

  • Cost savings often pay for the consulting engagement within months
  • Optimization creates ongoing value beyond the initial project
  • Visibility into spending patterns supports better budget planning

Cons:

  • Aggressive optimization may impact query performance if poorly executed
  • Cost management requires ongoing attention as workloads change
  • Some partners treat FinOps as an upsell rather than a core capability

5. AI readiness: Cortex AI and ML pipeline experience

Modern Snowflake implementations must support machine learning pipelines, large language model integrations, and retrieval-augmented generation patterns. Partners without hands-on AI experience deliver platforms that require expensive redesign when your organization advances AI initiatives.

Verify that partners have implemented Cortex AI, vector search, and Snowpark ML in production environments. Theoretical knowledge differs significantly from practical deployment experience.

AI readiness benefits

  • Cortex AI integration: Built-in AI capabilities run where your data already lives
  • Vector search support: Embeddings enable semantic search across documents and products
  • ML pipeline deployment: Snowpark enables model training and serving inside Snowflake

AI readiness pros and cons

Pros:

  • AI-ready architecture eliminates costly platform redesign later
  • Keeping ML workloads in Snowflake simplifies governance
  • Native AI features reduce dependency on external ML infrastructure

Cons:

  • AI workloads require careful compute cost management
  • Cortex AI capabilities continue evolving rapidly
  • Teams need training to take advantage of AI features

6. Knowledge transfer: Documentation and team enablement

The goal of any consulting engagement should be reducing long-term dependency, not creating it. Partners who invest in knowledge transfer leave your team with runbooks, documentation, and practical skills.

Ask about training components, documentation standards, and how the partner handles handoff at project completion. Organizations that skip this step often find themselves calling consultants for basic operational questions.

Knowledge transfer benefits

  • Runbooks and documentation: Clear guides help internal teams handle routine operations
  • Hands-on training: Practical skill building creates lasting internal capability
  • Architecture decision records: Documentation explains why decisions were made, not just what was built

Knowledge transfer pros and cons

Pros:

  • Internal capability reduces ongoing consulting costs
  • Documentation supports team member transitions
  • Trained teams can extend the platform without external help

Cons:

  • Knowledge transfer requires time investment from internal teams
  • Documentation quality varies significantly between partners
  • Training effectiveness depends on participant engagement

7. Governance expertise: RBAC, compliance, and audit trails

Data governance and security requirements have become business-critical for organizations operating under SOC 2, HIPAA, GDPR, and PCI DSS. Partners with governance expertise implement controls during initial architecture rather than retrofitting them later.

The cost differential between proactive governance and reactive compliance can reach significant amounts in enterprise environments. Look for partners who demonstrate role-based access control design, data masking policies, and lineage tracking capabilities.

Governance benefits

  • Role-based access control: Structured role hierarchies provide clarity and security
  • Data masking: Column-level masking protects sensitive information automatically
  • Audit trails: Complete lineage tracking supports compliance reporting

Governance pros and cons

Pros:

  • Built-in governance prevents expensive compliance remediation
  • Proper access controls reduce data breach risk
  • Audit readiness simplifies regulatory examinations

Cons:

  • Governance implementation adds complexity to initial projects
  • Overly restrictive controls can slow down legitimate data access
  • Compliance requirements vary by industry and geography

Comparison table: Snowflake support partner evaluation criteria

Evaluation Factor Snowstack Large Consultancies Boutique Specialists
Typical Delivery Timeline 90 days 12-18 months 4-6 months
Senior Architect Involvement Throughout engagement Sales cycle only Varies by firm
FinOps Cost Optimization ✓ Included standard ✗ Optional add-on ✓ Often included
AI/ML Implementation Experience ✓ Cortex AI production deployments ✓ Framework-based ✗ Limited

What questions should you ask a Snowflake consulting partner before signing?

The right questions reveal whether a partner can deliver on their promises. Focus on specifics rather than accepting vague assurances.

Start with their methodology. Ask them to walk through their implementation approach and show sanitized architecture diagrams from similar projects. Credible partners have documented processes they can explain clearly.

Dig into their team structure. Find out who will actually work on your project day-to-day, not just who attends the sales meetings. Junior resources may struggle with complex Snowflake architecture decisions.

  • Request case studies with measurable outcomes and cost savings data
  • Ask about their approach to knowledge transfer and documentation
  • Clarify what happens if the project runs over budget or timeline
  • Verify their hands-on experience with Cortex AI and Snowflake migrations

How do you evaluate a Snowflake partner's AI and analytics capabilities?

AI capability has become critical as organizations deploy machine learning pipelines and LLM integrations. Consultants without practical Cortex AI experience deliver platforms that need expensive rework when AI initiatives mature.

Ask for specific examples of AI implementations. Request details about vector search deployments, ML model serving, and governance patterns for AI workloads. Theoretical knowledge differs significantly from production deployment experience.

Verify they can demonstrate cost management for AI workloads. Cortex AI and ML pipelines can consume significant compute resources without proper guardrails. Partners should explain their approach to balancing AI capability with cost efficiency.

Why Snowstack is the top Snowflake consulting partner for mid-market data platform modernization

Snowstack combines deep Snowflake consulting expertise with proven delivery methods and transparent team structures. The firm delivers production-ready environments in 90 days while larger consultancies require 12 to 18 months for equivalent capability.

Cost optimization gets delivered as core methodology rather than optional add-on. Every Snowstack engagement includes FinOps analysis that identifies spending reduction opportunities through warehouse right-sizing, query optimization, and automated scaling policies.

AI readiness comes embedded in architecture from day one. Snowstack implementations support Cortex AI integration, vector search capabilities, and machine learning pipeline deployment without requiring platform redesign. The Platform Team as a Service model provides ongoing senior architect access rather than transitioning to junior support resources post-implementation.

Ready to evaluate Snowflake support partners for your data platform modernization? Contact Snowstack to discuss your specific requirements.

Contact us to discuss your specific requirements!

FAQs

Because they understand the schema, not the business meaning. Without governed definitions for metrics, fiscal calendars, and segment rules, the model infers them, and inference is where confident, wrong answers originate. Take a look at our AI and Governance page for more details.

A runtime context-enrichment layer announced at Summit 2026 (June 2) that automatically assembles business context (query history, metadata, BI dashboards, and semantic views) and supplies it to CoWork and CoCo at query time. Snowflake's internal benchmark reports it lifts accuracy from 47% to 83% on complex enterprise queries. It is in private preview as of June 2026.

No. Cortex Sense draws on your semantic views and metadata. Building a governed semantic layer now improves Cortex Analyst answers today and becomes the exact substrate Cortex Sense consumes when it reaches GA.

No. RBAC and governance control who can access data; they do not certify that the data is correct, consistently defined, or current. An agent can be fully governed and still return a wrong number from a table with an upstream error.

For new work, semantic views: they're native schema-level objects with full RBAC, sharing, and catalog support. Legacy YAML semantic models still work with Cortex Analyst for backward compatibility.

Blog
5 min read

Why your Snowflake agents give wrong answers on good data

Your Snowflake agent gives wrong answers on clean data because it knows your schema, not your business - here's the context layer that fixes it.

Read more

Under the Hood: grounding CoWork with Cortex Sense — not just prompting it

Your agent isn't wrong because your data is dirty. It's wrong because it doesn't know what your data means. An LLM can read your schema perfectly — table names, column types, row counts — and still have no idea that net revenue means gross revenue after discounts, that the fiscal year starts in February, or that "active customer" excludes anyone who churned last quarter. That gap between the schema an agent sees and the business meaning it doesn't is where confident, wrong answers come from. Closing it is now the single highest-leverage thing a data team can do for AI.

That's also the thesis Snowflake built its entire Summit 2026 agentic story around.

What actually changed at Summit 2026

Two things matter for anyone running agents on Snowflake:

Snowflake Intelligence is now CoWork. Same product lineage — the personal work agent that decomposes a question, researches across structured and unstructured data, and returns a cited answer — new name. If you saw Episode 3, this is the thing you already built against. Existing deployments migrate automatically.

Cortex Sense is the headline, and it's about accuracy, not features. Cortex Sense is a runtime context-enrichment layer: it automatically assembles business context — query history, object metadata, BI dashboards, and Horizon Context semantic views — and feeds it to CoWork and CoCo at query time, with no manual configuration. Snowflake's own internal benchmark puts the difference starkly: 47% accuracy on complex enterprise queries without it, 83% with it— and just 23% for frontier coding agents wired up through Snowflake's MCP connector alone. The message Snowflake is sending could not be clearer: context, not the model, determines agent quality.

We agree with that framing. But there are two catches, and they're exactly where a data team's real work lives.

The two catches nobody puts on the keynote slide

Catch #1 — Cortex Sense is private preview (as of June 2026). CoWork is shipping to enterprises now; Cortex Sense is not generally available yet. So the default CoWork deployment today operates closer to that 47% baseline, withoutSnowflake's own context infrastructure at production readiness. You can't wait for the feature to flip on and rescue answer quality before your stakeholders start trusting (or distrusting) the agent.

Catch #2 — even at GA, Cortex Sense is only as good as what's underneath it. Read the description again: it assembles context from your semantic views, metadata, and dashboards. If those definitions are missing, ambiguous, or contradictory, Cortex Sense faithfully assembles ambiguous context. And there's a deeper trap that governance alone never solves: access control is not correctness. RBAC enforces who can query the revenue table; it says nothing about whether that table is accurate, consistently defined, or current. An agent querying a revenue figure with an upstream ingestion error will return a confident, beautifully-cited, wrong number — and every guardrail will have done its job.

So the work is the same whether Cortex Sense is in preview or GA: you build the governed context layer and you make sure the data beneath it is actually right. The good news is that this work is not throwaway — the semantic layer you build now is precisely the substrate Cortex Sense consumes later. You're not waiting for the feature; you're getting ahead of it.

Here's how we build it.

Under the Hood: the context layer, step by step

Step 1 — Put the business definitions in a governed semantic view

A semantic view is a schema-level Snowflake object that maps physical columns to business concepts — facts, dimensions, and metrics — and stores the definitions natively, under RBAC, where both Cortex Analyst and (eventually) Cortex Sense read them. This is where you kill ambiguity once, centrally, instead of in fifty different dashboards.

The canonical example is the one Snowflake itself uses: revenue is physically stored in a column called amt_ttl_pre_dsc, but the business always means gross revenue after discounts. You encode that once:

CREATE OR REPLACE SEMANTIC VIEW analytics.sales.revenue_model
  TABLES (
    orders AS prod.sales.orders
      PRIMARY KEY (order_id)
      WITH SYNONYMS ('sales', 'bookings')
      COMMENT = 'One row per order line. Source of truth for revenue.',
    unit AS prod.sales.business_unit_dim
      PRIMARY KEY (unit_id)
  )
  RELATIONSHIPS (
    orders_to_unit AS orders (unit_id) REFERENCES unit (unit_id)
  )
  FACTS (
    orders.gross_amount   AS amt_ttl_pre_dsc,
    orders.discount_rate  AS disc_rate
  )
  DIMENSIONS (
    unit.unit_name    AS unit_name WITH SYNONYMS ('business unit', 'segment'),
    orders.order_date AS order_dt
  )
  METRICS (
    orders.net_revenue AS SUM(orders.gross_amount * (1 - orders.discount_rate))
      COMMENT = 'Net revenue = gross revenue after discounts. Use this for ALL
                 revenue reporting. Never sum amt_ttl_pre_dsc directly.'
  )
  COMMENT = 'Governed revenue model. These definitions are the single source
             of truth for agents and BI alike.';

Now anyone — human or agent — asks the question the same way and gets the same number:

SELECT * FROM SEMANTIC_VIEW (
  analytics.sales.revenue_model
  METRICS    net_revenue
  DIMENSIONS unit_name
);

Step 2 — Write your comments like prompts, because they are

This is the part that separates "it compiles" from "the agent is actually right." In a semantic view, Cortex Analyst reads your COMMENT text as instructions, not documentation. The comment on net_revenue above isn't a note for a future engineer — it's telling the model which column is not revenue. Be that explicit everywhere: define what a metric means, when to use it, and what to avoid. If you don't write it down, the model guesses, and a guess is how you get a wrong answer on clean data.

Two more high-leverage moves on the same object:

  • Synonyms so "business unit," "segment," and "BU" all resolve to one dimension. Agents fail constantly on vocabulary mismatch; this fixes it cheaply.
  • Verified queries — known-good question/SQL pairs that anchor the model on your hardest or most political metrics:
-- inside CREATE SEMANTIC VIEW, after the COMMENT clause:
AI_VERIFIED_QUERIES (
  net_rev_by_unit AS (
    QUESTION  'What was net revenue by business unit last quarter?'
    VERIFIED_AT 1717200000
    VERIFIED_BY '(owner = data-platform@yourco.com)'
    SQL 'SELECT * FROM SEMANTIC_VIEW (analytics.sales.revenue_model
           METRICS net_revenue DIMENSIONS unit_name)'
  )
);

One discipline worth stating plainly: only add verified queries you have actually validated. One wrong example teaches the model a bad habit at scale.

Step 3 — Measure the lift on your KPIs, don't take 47→83 on faith

Snowflake's benchmark is theirs, on their data. Before you tell your CFO the agent is trustworthy, prove it on your questions. Snowflake ships a Cortex Agent evaluation framework for exactly this — define a dataset of real questions with expected answers, then score the agent against it:

evaluation:
  agent_params:
    agent_name: "revenue_agent"
    agent_type: "CORTEX AGENT"
  run_params:
    label: "Baseline — before semantic layer"
    source_metadata:
      type: "dataset"
      dataset_name: "kpi_eval_set"
  metrics:
    - answer_correctness        # how close the answer is to ground truth
    - tool_selection_accuracy   # did it call the right tools? (public preview)
    - logical_consistency       # reference-free; consistency across the run

Run it once before the semantic layer exists, run it again after. The delta is your evidence — and your regression test. Wire it into CI so a careless change to a metric definition can't silently re-break answer quality next month.

Step 4 — Fix the data the context layer points at

A perfect semantic layer over a stale or half-loaded table still produces a wrong answer, just a well-defined one. So the context work has a twin: source-to-report reconciliation, freshness checks, and catching the broken or partial feeds that quietly poison a metric. That's a whole topic — it's Episode 5 — but flag it now, because "the agent gave the wrong number" is at least as often an ingestion problem as a semantics problem.

What this means, by role

If you lead data or analytics: the semantic layer is no longer a BI nicety — it's the accuracy substrate for every agent you're about to be asked to deploy. Building it now pays twice: better Cortex Analyst answers today, and a ready-made context source for Cortex Sense when it GAs.

If you're the architect or lead engineer: treat semantic views as strict contracts, not flexible SQL. Model relationships explicitly, comment like you're prompting, anchor hard metrics with verified queries, and put an evaluation set in CI. This is the build work that makes the demo survive contact with production.

If you own the platform strategy (VP / CDO): the question your stakeholders are really asking is "can we trust this for a real decision?" The honest answer is "only as far as our governed definitions and our data quality go." That's a roadmap, not a blocker — and it's a far better place to invest than another model evaluation.

How we'd approach it

Most teams we talk to don't have a context problem they can see — they have a trust problem they can feel: two dashboards disagree, an agent answer doesn't match the board deck, nobody's quite sure which number is right. The fix starts with finding where the definitions diverge and where the data underneath is wrong, before pointing any agent at it.

That's the shape of our AI-readiness assessment — a fixed-scope first step that maps your sources, definitions, and the gaps between what your reports say and what your data actually contains, so the agents you ship are accurate by construction. If your CoWork answers are landing in the "confident but wrong" zone, that's the place to start.

FAQs

Because they understand the schema, not the business meaning. Without governed definitions for metrics, fiscal calendars, and segment rules, the model infers them, and inference is where confident, wrong answers originate. Take a look at our AI and Governance page for more details.

A runtime context-enrichment layer announced at Summit 2026 (June 2) that automatically assembles business context (query history, metadata, BI dashboards, and semantic views) and supplies it to CoWork and CoCo at query time. Snowflake's internal benchmark reports it lifts accuracy from 47% to 83% on complex enterprise queries. It is in private preview as of June 2026.

No. Cortex Sense draws on your semantic views and metadata. Building a governed semantic layer now improves Cortex Analyst answers today and becomes the exact substrate Cortex Sense consumes when it reaches GA.

No. RBAC and governance control who can access data; they do not certify that the data is correct, consistently defined, or current. An agent can be fully governed and still return a wrong number from a table with an upstream error.

For new work, semantic views: they're native schema-level objects with full RBAC, sharing, and catalog support. Legacy YAML semantic models still work with Cortex Analyst for backward compatibility.

Notes & sources: Cortex Sense status and the 47%→83% figure are from Snowflake's own materials and product announcements (Snowflake Summit 2026, June 2); Cortex Sense is in private preview as of June 2026, so treat the figure as a vendor benchmark and validate on your own data. Semantic-view DDL and the comment-as-instruction behavior follow Snowflake's CREATE SEMANTIC VIEW and semantic-view documentation; semantic-view SQL is stricter than ordinary SQL, so validate any DDL against current docs for your account version. Cortex Agent evaluation metrics (answer correctness, tool-selection accuracy, logical consistency) are from Snowflake's Cortex Agent evaluations documentation.

Explore our latest blog posts for valuable insights.
View more insights
Stay up to date

Top data insights, delivered to your inbox

 Thanks for joining us!

We’ll keep you posted with fresh updates and resources.

Oops! Something went wrong while submitting the form.

Transform your data with Snowflake

You don't need to hire a data army or wait months to see results. Our Snowflake specialists will get you up and running fast, so you can make better decisions, cut costs, and beat competitors who are still stuck with spreadsheets and legacy systems

Learn more