# Triagic + Snowflake: ticket investigations over your database, read-only

> Snowflake in Triagic: Browse databases and run read-only SQL against a Snowflake warehouse. Read-only, with a credential you configure.

Source: https://triagic.com/integrations/snowflake

## What you can ask

- How many orgs called the legacy export API in the last 90 days, and which three in the last 30?
- Does the warehouse show the same plan for acme-labs as the billing system does?
- Which warehouses ran more than four hours yesterday, and what did they cost?
- Find every row in EVENTS for user 51930 between 10:00 and 10:20 UTC on Tuesday
- List the tables in PROD.ANALYTICS and show me which ones mention refunds

## How Triagic works with Snowflake [#how-triagic-works-with-snowflake]

Most support questions that end up with the data team are one query away: which orgs still use a feature, why an invoice disagrees with a dashboard, whether an account is on the plan the customer thinks it is. Triagic runs that query itself, from the desktop app, through a read-only Snowflake server that Triagic writes and ships inside the app. It exposes five tools: `list_databases`, `list_schemas`, `list_tables`, `describe_table` and `query`. `query` takes one `SELECT`, `WITH`, `SHOW`, `DESCRIBE`, `DESC` or `EXPLAIN` statement, and the Snowflake API it calls refuses a second statement in the same request.

Every query the agent runs is shown in the Console or on the ticket as it happens, with the SQL and the row count. The answer cites the tables it came from, so a support engineer can paste the SQL into a worksheet and get the same rows.

Snowflake has no read-only session, so the statement check is defense in depth, not the boundary. The boundary is the service user: create `triagic_reader` with `USAGE` on the warehouse and `SELECT` on the tables, put it in the Role field, and the agent cannot write no matter what the guard does.

Two things trip people up on setup. The account identifier is the part before `.snowflakecomputing.com`, never the whole URL; pasting the URL fails with a lookup error that reads like a network failure and is not. And a Programmatic Access Token is rejected with `394400` unless the user has a network policy, even though generating the token needed none. Both errors are mapped to their fix in the desktop app.

## What the agent can do

- `list_databases`
- `list_schemas`
- `list_tables`
- `describe_table`
- `query`

## Connect in three steps

1. **Mint a read-only credential in Snowflake.** Create a dedicated user or token that can only read. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.
2. **Add it in the Triagic portal.** Integrations, then Add shared data source, then Snowflake. Fill in: Account identifier (required): The org and account names joined by a hyphen (myorg-my_account), or an account locator with its region (xy12345.us-east-1). Not the dotted myorg.my_account form and not the full URL.; User (required): The login name. Pair it with “Role” below so queries run with SELECT-only grants.; Programmatic access token (required): Snowflake → your user → Settings → Authentication → Programmatic access tokens. It can be scoped to one role and expired independently of the user. Snowflake only accepts it from a user covered by a network policy.; Private key path (required): PKCS#8 PEM private key whose public half is set on the user (ALTER USER … SET RSA_PUBLIC_KEY). Path on each machine running Triagic, or paste the file itself.; Warehouse (required): Warehouse queries run on. Metadata calls work without one, but SELECTs will fail.
3. **Let a desktop pick it up.** Saving validates the shape of what you typed. The first desktop app to sync starts Snowflake locally and reports running or degraded with the error text.

Setup reference: https://triagic.com/docs/integrations/databases#snowflake

## Three ticket scenarios

### Can we kill the legacy export API?

**Ticket:** Roadmap review. One line says deprecate the legacy export API. Nobody can answer who still uses it.

**What Triagic found:** 14 orgs in the last 90 days, 3 in the last 30 and falling: one enterprise account and two trials, each with its last call date. Two tool calls, query against PROD.API_CALLS and a PostHog funnel, 11 seconds, nine cents.

### Numbers on the invoice do not match the dashboard

**Ticket:** A customer says their September invoice bills 412,000 events but their dashboard shows 380,000.

**What Triagic found:** The invoice table counts events at ingest time and the dashboard counts them after deduplication. 32,000 events had a duplicate event_id from a retrying webhook. The reply quotes both queries and the dedup rule.

### Snowflake cost review, monthly

**Ticket:** Not a ticket: the Snowflake cost checkup runs on the first of the month.

**What Triagic found:** Two warehouses with auto-suspend at 60 minutes idle, one XL warehouse serving a nightly job that finishes in four minutes, and 1.1 TB of a table nobody had queried since March. Findings persist under the same key until they are fixed.

## Read-only, by construction

Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary.

## FAQ

**Can I use key-pair authentication or SSO?**
Key pair, yes: register the public key on a service user and point Triagic at the private key. A Programmatic Access Token also works and needs a network policy on the user. Browser SSO and account passwords do not, because Snowflake's SQL API accepts neither.

**Which role does the agent query as?**
Whatever you put in the Role field, sent with every statement. Leave it blank and the user's default role applies. Either way, give it SELECT and nothing else.

**Does it need a warehouse?**
Yes for any SELECT. Metadata calls such as list_databases work without one, queries do not.

**Can Triagic change anything in Snowflake?**
No. Triagic writes this server: query takes one SELECT, SHOW, DESCRIBE or EXPLAIN and the API refuses a second statement. Snowflake has no read-only session, so the role's grants are the boundary. Give it a read-only credential as well, so the guarantee does not rest on one layer.

**What do I need to connect Snowflake?**
Account identifier, User, Programmatic access token, Private key path, Warehouse. The desktop app on a member's machine starts the connection; the portal never holds a live process.

**Does Snowflake cost extra?**
No. Every connector is included in the seat price. Start a 14-day trial without a card.

## Related integrations

- [PostgreSQL](https://triagic.com/integrations/postgres)
- [BigQuery](https://triagic.com/integrations/bigquery)
- [ClickHouse](https://triagic.com/integrations/clickhouse)
- [PostHog](https://triagic.com/integrations/posthog)
