Triagic + Snowflake: ticket investigations over your database, read-only
Browse databases and run read-only SQL against a Snowflake warehouse. Connect as a role that only has SELECT. Triagic connects to Snowflake from the desktop app on each member's machine, with a credential you configure, and shows every call it makes while it investigates a ticket. Nothing is copied out of Snowflake.
What you can ask
- How many orgs called the legacy export API in the last 90 days, and which three in the last 30?
- Does the warehouse show the same plan for acme-labs as the billing system does?
- Which warehouses ran more than four hours yesterday, and what did they cost?
- Find every row in EVENTS for user 51930 between 10:00 and 10:20 UTC on Tuesday
- List the tables in PROD.ANALYTICS and show me which ones mention refunds
What the agent can do
These are the 5 tools Triagic exposes from the Snowflake MCP server. Anything else the server lists is dropped at connect time.
- list_databases
- list_schemas
- list_tables
- describe_table
- query
Connect in three steps
- 1
Mint a read-only credential in Snowflake
Create a dedicated user or token that can only read. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.
- 2
Add it in the Triagic portal
Integrations, then Add shared data source, then Snowflake.
- Account identifier: The org and account names joined by a hyphen (myorg-my_account), or an account locator with its region (xy12345.us-east-1). Not the dotted myorg.my_account form and not the full URL.
- User: The login name. Pair it with “Role” below so queries run with SELECT-only grants.
- Programmatic access token: Snowflake → your user → Settings → Authentication → Programmatic access tokens. It can be scoped to one role and expired independently of the user. Snowflake only accepts it from a user covered by a network policy.
- Private key path: PKCS#8 PEM private key whose public half is set on the user (ALTER USER … SET RSA_PUBLIC_KEY). Path on each machine running Triagic, or paste the file itself.
- Warehouse: Warehouse queries run on. Metadata calls work without one, but SELECTs will fail.
- 3
Let a desktop pick it up
Saving validates the shape of what you typed. The first desktop app to sync starts Snowflake locally and reports running or degraded with the error text.
Field-by-field setup, TLS options and the error table: Snowflake in the docs.
Three ticket scenarios
- Can we kill the legacy export API?
Ticket: Roadmap review. One line says deprecate the legacy export API. Nobody can answer who still uses it.
What Triagic found: 14 orgs in the last 90 days, 3 in the last 30 and falling: one enterprise account and two trials, each with its last call date. Two tool calls, query against PROD.API_CALLS and a PostHog funnel, 11 seconds, nine cents.
- Numbers on the invoice do not match the dashboard
Ticket: A customer says their September invoice bills 412,000 events but their dashboard shows 380,000.
What Triagic found: The invoice table counts events at ingest time and the dashboard counts them after deduplication. 32,000 events had a duplicate event_id from a retrying webhook. The reply quotes both queries and the dedup rule.
- Snowflake cost review, monthly
Ticket: Not a ticket: the Snowflake cost checkup runs on the first of the month.
What Triagic found: Two warehouses with auto-suspend at 60 minutes idle, one XL warehouse serving a nightly job that finishes in four minutes, and 1.1 TB of a table nobody had queried since March. Findings persist under the same key until they are fixed.
Read-only, by construction
Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.
FAQ
- Can I use key-pair authentication or SSO?
- Key pair, yes: register the public key on a service user and point Triagic at the private key. A Programmatic Access Token also works and needs a network policy on the user. Browser SSO and account passwords do not, because Snowflake's SQL API accepts neither.
- Which role does the agent query as?
- Whatever you put in the Role field, sent with every statement. Leave it blank and the user's default role applies. Either way, give it SELECT and nothing else.
- Does it need a warehouse?
- Yes for any SELECT. Metadata calls such as list_databases work without one, queries do not.
- Can Triagic change anything in Snowflake?
- No. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary. Give it a read-only credential as well, so the guarantee does not rest on one layer.
- What do I need to connect Snowflake?
- Account identifier, User, Programmatic access token, Private key path, Warehouse. The desktop app on a member's machine starts the connection; the portal never holds a live process.
- Does Snowflake cost extra?
- No. Every connector is included in the seat price. Start a 14-day trial without a card.
Related integrations
- PostgreSQLBrowse schemas and run read-only SQL against a Postgres database.
- BigQueryQuery datasets and inspect table schemas. Writes are not blocked. Use a service account limited to read-only roles.
- ClickHouseRun read-only SQL against a ClickHouse cluster.
- PostHogQuery product analytics behind a ticket: errors, events, insights, feature flags, experiments, and session data. Connects to PostHog's hosted server; only its read-only tools are exposed.
Try it on your own Snowflake
No card. Install the desktop app, connect Snowflake read-only, and triage a real ticket this afternoon.