Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Read by thought-leaders and decision-makers around the world. Phone Number: +1-650-246-9381 Email: pub@towardsai.net
228 Park Avenue South New York, NY 10003 United States
Website: Publisher: https://towardsai.net/#publisher Diversity Policy: https://towardsai.net/about Ethics Policy: https://towardsai.net/about Masthead: https://towardsai.net/about
Name: Towards AI Legal Name: Towards AI, Inc. Description: Towards AI is the world's leading artificial intelligence (AI) and technology publication. Founders: Roberto Iriondo, , Job Title: Co-founder and Advisor Works for: Towards AI, Inc. Follow Roberto: X, LinkedIn, GitHub, Google Scholar, Towards AI Profile, Medium, ML@CMU, FreeCodeCamp, Crunchbase, Bloomberg, Roberto Iriondo, Generative AI Lab, Generative AI Lab VeloxTrend Ultrarix Capital Partners Denis Piffaretti, Job Title: Co-founder Works for: Towards AI, Inc. Louie Peters, Job Title: Co-founder Works for: Towards AI, Inc. Louis-François Bouchard, Job Title: Co-founder Works for: Towards AI, Inc. Cover:
Towards AI Cover
Logo:
Towards AI Logo
Areas Served: Worldwide Alternate Name: Towards AI, Inc. Alternate Name: Towards AI Co. Alternate Name: towards ai Alternate Name: towardsai Alternate Name: towards.ai Alternate Name: tai Alternate Name: toward ai Alternate Name: toward.ai Alternate Name: Towards AI, Inc. Alternate Name: towardsai.net Alternate Name: pub.towardsai.net
5 stars – based on 497 reviews

Frequently Used, Contextual References

TODO: Remember to copy unique IDs whenever it needs used. i.e., URL: 304b2e42315e

Resources

Free: 6-day Agentic AI Engineering Email Guide.
Learnings from Towards AI's hands-on work with real clients.
Production RBAC, Cost Optimization, and Deployment Patterns for Cortex Agents
Latest   Machine Learning

Production RBAC, Cost Optimization, and Deployment Patterns for Cortex Agents

Last Updated on October 6, 2026 by Editorial Team

Author(s): Satish Kumar

Originally published on Towards AI.

The developer-to-production pipeline for Snowflake’s Cortex Agent GA enhancements — Personal Database sandboxes, temporary agents, COPY GRANTS, and the cost math on Cortex Search suspension.

Part 2 of 2 — Part 1: Your Cortex Agent Specification Is Visible to Every Role That Can Invoke It

Production RBAC, Cost Optimization, and Deployment Patterns for Cortex Agents
From Personal Database to Production: Building Secure, Governed & Cost-Efficient Cortex Agents

Part 1 covered why secure agents exist and how spec redaction actually works — including the ownership gotcha that silently breaks redaction when ACCOUNTADMIN owns the agent. This article covers the production deployment pipeline: how to develop, validate, deploy, and operate a secure Cortex Agent with proper RBAC, zero-downtime updates, and cost controls.

The running example is the same release notes intelligence agent from Part 1.

The Developer Workflow: Personal Database to Production

Develop in Personal Database

Each developer creates agents in their own Personal Database. No CREATE AGENT privilege on shared schemas required.

CREATE OR REPLACE AGENT "USER$JSMITH".PUBLIC.release_notes_dev
COMMENT = 'Dev iteration — testing new orchestration instructions'
FROM SPECIFICATION $$
models:
orchestration: claude-sonnet-4-6
instructions:
response: "Testing revised response format — include release date in bold."
orchestration: "Always use ReleaseAnalyst first, fall back to ReleaseSearch."
tools:
- tool_spec:
type: "cortex_analyst_text_to_sql"
name: "ReleaseAnalyst"
- tool_spec:
type: "cortex_search"
name: "ReleaseSearch"
tool_resources:
ReleaseAnalyst:
semantic_view: "release_intel_db.data.release_notes_model"
ReleaseSearch:
search_service: "release_intel_db.data.release_search"
max_results: 5
$$;

The Personal Database agent references production data sources (the semantic view and search service) but lives in an isolated schema. No naming conflicts. No shared-schema privilege requirements.

Validate with Temporary Agent

Before promoting to production, create a temporary agent. Session-scoped — it disappears when the session ends and doesn’t require CREATE AGENT on the target schema.

CREATE TEMPORARY AGENT release_notes_validation
FROM SPECIFICATION $$
models:
orchestration: claude-sonnet-4-6
orchestration:
budget:
seconds: 30
tokens: 16000
instructions:
response: "Testing revised response format — include release date in bold."
orchestration: "Always use ReleaseAnalyst first, fall back to ReleaseSearch."
tools:
- tool_spec:
type: "cortex_analyst_text_to_sql"
name: "ReleaseAnalyst"
- tool_spec:
type: "cortex_search"
name: "ReleaseSearch"
tool_resources:
ReleaseAnalyst:
semantic_view: "release_intel_db.data.release_notes_model"
ReleaseSearch:
search_service: "release_intel_db.data.release_search"
max_results: 5
$$;

-- Validate
SELECT SNOWFLAKE.CORTEX.DATA_AGENT_RUN(
'release_notes_validation',
$${"messages": [{"role": "user", "content": [{"type": "text", "text": "What features reached GA on September 16, 2026?"}]}]}$$
);

Temporary agent limitations: no versioning (COMMIT, aliases), cannot convert to permanent, and DATA_AGENT_RUN requires a fully qualified name for permanent agents (temp agents use the session namespace).

Promote with COPY GRANTS

The production agent already has grants to release_agent_consumer and analyst_role. COPY GRANTS preserves all of them during the replacement.

USE ROLE release_agent_owner;

CREATE OR REPLACE SECURE AGENT release_intel_db.agents.release_notes_agent
COMMENT = 'Production release notes agent — v2, revised orchestration.'
PROFILE = '{"display_name": "Release Intel", "avatar": "release-notes.png", "color": "blue"}'
COPY GRANTS
FROM SPECIFICATION $$
models:
orchestration: claude-sonnet-4-6
orchestration:
capabilities:
analytical_search: true
tool_not_accessible: accept
budget:
seconds: 30
tokens: 16000
instructions:
response: >
You are a release notes intelligence assistant. Include the release
date in bold for every feature mentioned. Be precise about GA vs
Preview status.
orchestration: >
Always use ReleaseAnalyst first. Fall back to ReleaseSearch only when
ReleaseAnalyst cannot answer.
tools:
- tool_spec:
type: "cortex_analyst_text_to_sql"
name: "ReleaseAnalyst"
- tool_spec:
type: "cortex_search"
name: "ReleaseSearch"
tool_resources:
ReleaseAnalyst:
semantic_view: "release_intel_db.data.release_notes_model"
execution_environment:
type: "warehouse"
warehouse: "COMPUTE_WH"
ReleaseSearch:
search_service: "release_intel_db.data.release_search"
max_results: 5
$$;

-- Verify grants survived
SHOW GRANTS ON AGENT release_intel_db.agents.release_notes_agent;

The operation is atomic. Consumers experience no interruption. Note: COPY GRANTS must come after PROFILE and before FROM SPECIFICATION — the clause ordering matters.

RBAC Design

-- Owner role: full specification access, deployment authority
CREATE ROLE IF NOT EXISTS release_agent_owner;
GRANT CREATE AGENT ON SCHEMA release_intel_db.agents TO ROLE release_agent_owner;
GRANT USAGE ON DATABASE release_intel_db TO ROLE release_agent_owner;
GRANT USAGE ON SCHEMA release_intel_db.agents TO ROLE release_agent_owner;
GRANT USAGE ON SCHEMA release_intel_db.data TO ROLE release_agent_owner;

-- Consumer role: invocation only, no spec visibility
CREATE ROLE IF NOT EXISTS release_agent_consumer;
GRANT USAGE ON DATABASE release_intel_db TO ROLE release_agent_consumer;
GRANT USAGE ON SCHEMA release_intel_db.agents TO ROLE release_agent_consumer;
GRANT USAGE ON AGENT release_intel_db.agents.release_notes_agent
TO ROLE release_agent_consumer;
-- Transfer ownership away from ACCOUNTADMIN (see Part 1)
GRANT OWNERSHIP ON AGENT release_intel_db.agents.release_notes_agent
TO ROLE release_agent_owner REVOKE CURRENT GRANTS;
GRANT USAGE ON AGENT release_intel_db.agents.release_notes_agent
TO ROLE release_agent_consumer;
Three roles, four capabilities, one asymmetry: everyone can invoke, few can read.

The consumer role has exactly 4 grants: USAGE on database, schema, agent, and warehouse. Zero grants on the DATA schema. Zero SELECT on any table. Zero GRANT_OPTION anywhere.

Graceful Degradation: What Happens When a Tool Goes Down

With tool_not_accessible: accept, the agent continues when a configured tool is unavailable. Here is what we observed with the Cortex Search service suspended:

Three query shapes, three routing paths — only one ever needs a retry.

The failover was genuinely graceful. Structured queries were unaffected. Conceptual queries took ~11 seconds longer (retry loop) but returned correct answers via SQL fallback.

Write on Medium

The three tool_not_accessible values:

Three settings, two real policies: availability or compliance.

Cost Optimization

The deployment has three cost levers:

The Cortex Search service was the largest controllable cost. With TARGET_LAG = '1 hour', it refreshes hourly regardless of data changes. For a dataset that updates weekly, that's waste.

-- Suspend to stop refresh costs
ALTER CORTEX SEARCH SERVICE release_intel_db.data.release_search SUSPEND;

-- Resume when needed (rebuilds from checkpoint)
ALTER CORTEX SEARCH SERVICE release_intel_db.data.release_search RESUME;

Break-even analysis: The search service costs ~0.04 credits/day. Each agent invocation costs ~0.0034 credits. At fewer than 12 conceptual queries per day, the search service costs more than the queries it serves. Recommended suspend threshold: fewer than 5 conceptual queries/day.

Both settings scale together: low volume suspends, high volume refreshes hourly.

Trade-Offs

When to Use Secure Agents

  • The specification contains proprietary orchestration logic
  • The agent is shared with external accounts or through Native Apps
  • Multiple teams have USAGE but should not see tool configurations

When to Avoid

  • Internal agents where all consumers are trusted
  • Development environments where spec transparency aids debugging

What to Monitor

-- Invocation volume and errors
SELECT execution_status, COUNT(*) AS cnt
FROM SNOWFLAKE.ACCOUNT_USAGE.QUERY_HISTORY
WHERE query_text ILIKE '%DATA_AGENT_RUN%release_notes_agent%'
AND start_time > DATEADD('day', -7, CURRENT_TIMESTAMP())
GROUP BY 1;

-- Ownership hasn't reverted after replacement
SHOW AGENTS LIKE 'release_notes_agent' IN SCHEMA release_intel_db.agents;
-- Check: is_secure = true, owner = RELEASE_AGENT_OWNER (not ACCOUNTADMIN)

Key Takeaway

  1. The deployment pipeline is now complete. Personal Database → temporary agent → secure production agent with COPY GRANTS. Before September 2026, each step had friction.
  2. COPY GRANTS is the most operationally important enhancement. Losing grants during CREATE OR REPLACE was the most common production incident. COPY GRANTS makes agent updates as safe as view replacements. Clause order matters: COMMENT → PROFILE → COPY GRANTS → FROM SPECIFICATION.
  3. The semantic view is a zero-cost asset. Unlike the search service, it has no ongoing compute cost. The Cortex Analyst tool generates SQL at invocation time against metadata. This makes it the most cost-efficient component in the agent architecture.
  4. Suspend the search service when it costs more than the queries it serves. Below ~12 conceptual queries/day, the hourly refresh cycle is waste. The agent degrades gracefully to SQL-based search via tool_not_accessible: accept.

The gap between “agent prototype” and “production agent” just closed. Cortex Agents now have the same lifecycle primitives — secure objects, session-scoped testing, grant preservation, personal development sandboxes — that Snowflake’s mature object types have had for years.

Found this useful? 👏 Give it a clap — it helps others discover it too.

Follow for weekly Snowflake engineering deep dives, practical architecture insights, and technical quick bytes. ❄️

You may use, share, adapt, and build upon this work. For public redistribution or substantial adaptation, please retain attribution and include a link to the original article or repository and the author’s LinkedIn profile. Private and internal use requires no attribution. Provided “as is” for educational purposes. Please validate and test all examples before using them in production. Views are my own and do not represent any current or former employer.

Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.

Published via Towards AI


Towards AI Academy

We Build Enterprise-Grade AI. We'll Teach You to Master It Too.

15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.

Start free — no commitment:

→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day

→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages

Our courses:

→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.

→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.

→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.

Note: Article content contains the views of the contributing authors and not Towards AI.