Skip to content

Triagic + Snowflake: ticket investigations over your database, read-only

Browse databases and run read-only SQL against a Snowflake warehouse. Connect as a role that only has SELECT. Triagic connects to Snowflake from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Snowflake.

What you can ask

  • How many orgs called the legacy export API in the last 90 days, and which three in the last 30?
  • Does the warehouse show the same plan for acme-labs as the billing system does?
  • Which warehouses ran more than four hours yesterday, and what did they cost?
  • Find every row in EVENTS for user 51930 between 10:00 and 10:20 UTC on Tuesday
  • List the tables in PROD.ANALYTICS and show me which ones mention refunds

How Triagic works with Snowflake

Most support questions that end up with the data team are one query away: which orgs still use a feature, why an invoice disagrees with a dashboard, whether an account is on the plan the customer thinks it is. Triagic runs that query itself, from the desktop app, through a read-only Snowflake server that Triagic writes and ships inside the app. It exposes five tools: list_databases, list_schemas, list_tables, describe_table and query. query takes one SELECT, WITH, SHOW, DESCRIBE, DESC or EXPLAIN statement, and the Snowflake API it calls refuses a second statement in the same request.

Every query the agent runs is shown in the Console or on the ticket as it happens, with the SQL and the row count. The answer cites the tables it came from, so a support engineer can paste the SQL into a worksheet and get the same rows.

Snowflake has no read-only session, so the statement check is defense in depth, not the boundary. The boundary is the service user: create triagic_reader with USAGE on the warehouse and SELECT on the tables, put it in the Role field, and the agent cannot write no matter what the guard does.

Two things trip people up on setup. The account identifier is the part before .snowflakecomputing.com, never the whole URL; pasting the URL fails with a lookup error that reads like a network failure and is not. And a Programmatic Access Token is rejected with 394400 unless the user has a network policy, even though generating the token needed none. Both errors are mapped to their fix in the desktop app.

What the agent can do

These are the 5 tools Triagic exposes from the Snowflake MCP server. Anything else the server lists is dropped at connect time.

  • list_databases
  • list_schemas
  • list_tables
  • describe_table
  • query

Connect in three steps

  1. 1

    Mint a read-only credential in Snowflake

    Create a dedicated user or token that can only read. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.

  2. 2

    Add it in the Triagic portal

    Integrations, then Add shared data source, then Snowflake.

    • Account identifier: The org and account names joined by a hyphen (myorg-my_account), or an account locator with its region (xy12345.us-east-1). Not the dotted myorg.my_account form and not the full URL.
    • User: The login name. Pair it with “Role” below so queries run with SELECT-only grants.
    • Programmatic access token: Snowflake → your user → Settings → Authentication → Programmatic access tokens. It can be scoped to one role and expired independently of the user. Snowflake only accepts it from a user covered by a network policy.
    • Private key path: PKCS#8 PEM private key whose public half is set on the user (ALTER USER … SET RSA_PUBLIC_KEY). Path on each machine running Triagic, or paste the file itself.
    • Warehouse: Warehouse queries run on. Metadata calls work without one, but SELECTs will fail.
  3. 3

    Let a desktop pick it up

    Saving validates the shape of what you typed. The first desktop app to sync starts Snowflake locally and reports running or degraded with the error text.

Field-by-field setup, TLS options and the error table: Snowflake in the docs.

Three ticket scenarios

Can we kill the legacy export API?

Ticket: Roadmap review. One line says deprecate the legacy export API. Nobody can answer who still uses it.

What Triagic found: 14 orgs in the last 90 days, 3 in the last 30 and falling: one enterprise account and two trials, each with its last call date. Two tool calls, query against PROD.API_CALLS and a PostHog funnel, 11 seconds, nine cents.

Numbers on the invoice do not match the dashboard

Ticket: A customer says their September invoice bills 412,000 events but their dashboard shows 380,000.

What Triagic found: The invoice table counts events at ingest time and the dashboard counts them after deduplication. 32,000 events had a duplicate event_id from a retrying webhook. The reply quotes both queries and the dedup rule.

Snowflake cost review, monthly

Ticket: Not a ticket: the Snowflake cost checkup runs on the first of the month.

What Triagic found: Two warehouses with auto-suspend at 60 minutes idle, one XL warehouse serving a nightly job that finishes in four minutes, and 1.1 TB of a table nobody had queried since March. Findings persist under the same key until they are fixed.

Read-only, by construction

Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.

FAQ

Can I use key-pair authentication or SSO?
Key pair, yes: register the public key on a service user and point Triagic at the private key. A Programmatic Access Token also works and needs a network policy on the user. Browser SSO and account passwords do not, because Snowflake's SQL API accepts neither.
Which role does the agent query as?
Whatever you put in the Role field, sent with every statement. Leave it blank and the user's default role applies. Either way, give it SELECT and nothing else.
Does it need a warehouse?
Yes for any SELECT. Metadata calls such as list_databases work without one, queries do not.
Can Triagic change anything in Snowflake?
No. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary. Give it a read-only credential as well, so the guarantee does not rest on one layer.
What do I need to connect Snowflake?
Account identifier, User, Programmatic access token, Private key path, Warehouse. The desktop app on a member's machine starts the connection; the portal never holds a live process.
Does Snowflake cost extra?
No. Every connector is included in the seat price. Start a 14-day trial without a card.

Related integrations

Try it on your own Snowflake

No card. Install the desktop app, connect Snowflake read-only, and triage a real ticket this afternoon.