Snowflake CoWork (Cortex Agents)

Monitor Snowflake Cortex Agents in Monte Carlo for full agent observability

Monte Carlo's Agent Observability provides full visibility into your Snowflake CoWork Cortex Agents. Cortex Agents log detailed trace data natively to Snowflake, and Monte Carlo reads this data directly โ€” giving you trace-level visibility, out-of-the-box dashboards, and full agent monitor coverage without deploying additional infrastructure or modifying your agent code.

What is Snowflake CoWork?

Snowflake CoWork is Snowflake's managed platform for building and deploying AI agents powered by Cortex. Teams can create agents that answer questions, execute SQL, search internal data, and interact with tools โ€” all within Snowflake's environment. Cortex Agents log detailed trace data natively, including conversation history, tool execution, LLM planning, and response generation.

Why Connect Snowflake Cortex Agents to Monte Carlo?

Connecting your Snowflake Cortex agents to Monte Carlo gives you full observability into how your agents are behaving in production. Monte Carlo reads Cortex Agent trace data directly from Snowflake, so there's nothing to deploy or instrument.

Connecting Snowflake Cortex Agents

Now that we know the value connecting a Snowflake Cortex Agent to Monte Carlo can bring, here are the necessary steps to set up the integration.

  1. Grant permissions to Monte Carlo's service account in Snowflake.
  2. Add the agent in Monte Carlo.
๐Ÿ“˜

Prerequisites

An existing Snowflake integration in Monte Carlo. Your Snowflake account must be connected to Monte Carlo with a service account configured. If you haven't set this up yet, see our Snowflake integration guide.

You will need permissions to use the ACCOUNTADMIN role on Snowflake to grant the required access.

Required Snowflake permissions

Monte Carlo's service account needs the following privileges to read your Cortex Agents' trace data and the semantic views and Cortex Search services they use. See Snowflake's access control documentation for details.

On the agent, to read trace data:

  • MONITOR on each agent you want to observe

  • The SNOWFLAKE.CORTEX_USER database role

  • READ UNREDACTED AI OBSERVABILITY EVENTS TABLE on the account. Without it, prompts and completions are redacted (Snowflake BCR, April 24, 2026).

  • USE AI FUNCTIONS on the account, for Agent Evaluation monitors and Clustering. Only needed if your account has revoked it from PUBLIC.

On the semantic views and Cortex Search services the agent uses, so Reinforcement Loop can read how they're configured:

  • REFERENCES on each semantic view

  • USAGE on each Cortex Search service

  • USAGE on their databases and schemas

Access to the agent doesn't include the semantic views and Cortex Search services, so grant them separately. Monte Carlo only describes these objects. It never queries them or the data underneath.

Grant permissions

Run the following to grant everything above, replacing <monte_carlo_role> with your Monte Carlo service account's role. To find the agent's semantic views and Cortex Search services, run DESCRIBE AGENT and check tool_resources for each semantic_view and search_service .

USE ROLE ACCOUNTADMIN;
 
-- On the agent
GRANT MONITOR ON AGENT <database>.<schema>.<agent_name> TO ROLE <monte_carlo_role>;
GRANT DATABASE ROLE SNOWFLAKE.CORTEX_USER TO ROLE <monte_carlo_role>;
GRANT READ UNREDACTED AI OBSERVABILITY EVENTS TABLE ON ACCOUNT TO ROLE <monte_carlo_role>;
GRANT USE AI FUNCTIONS ON ACCOUNT TO ROLE <monte_carlo_role>;
 
-- On each semantic view and Cortex Search service
GRANT USAGE ON DATABASE <resource_database> TO ROLE <monte_carlo_role>;
GRANT USAGE ON SCHEMA <resource_database>.<resource_schema> TO ROLE <monte_carlo_role>;
GRANT REFERENCES ON SEMANTIC VIEW <resource_database>.<resource_schema>.<semantic_view_name> TO ROLE <monte_carlo_role>;
GRANT USAGE ON CORTEX SEARCH SERVICE <resource_database>.<resource_schema>.<service_name> TO ROLE <monte_carlo_role>;

To cover objects created later in the same schema:

GRANT MONITOR ON FUTURE AGENTS IN SCHEMA <database>.<schema> TO ROLE <monte_carlo_role>;

GRANT REFERENCES ON FUTURE SEMANTIC VIEWS IN SCHEMA <resource_database>.<resource_schema> TO ROLE <monte_carlo_role>;

GRANT USAGE ON FUTURE CORTEX SEARCH SERVICES IN SCHEMA <resource_database>.<resource_schema> TO ROLE <monte_carlo_role>;

Validate permissions

Run these as the Monte Carlo service account role. Each should succeed without error.

-- 1. Verify the agent is visible:
SHOW AGENTS;

-- 2. Verify trace data is accessible:
SELECT * FROM TABLE(
    SNOWFLAKE.LOCAL.GET_AI_OBSERVABILITY_EVENTS(
        '<database>',
        '<schema>',
        '<agent_name>',
        'CORTEX AGENT'
    )
);

-- 3. list the semantic views and Cortex Search services the agent uses.
--    In the returned spec, read tool_resources: a semantic_view for each
--    Cortex Analyst tool, a search_service for each Cortex Search tool.
DESCRIBE AGENT <database>.<schema>.<agent_name>;

-- 4. Confirm each semantic view can be described:
DESC SEMANTIC VIEW <resource_database>.<resource_schema>.<semantic_view_name>;

-- 5. Confirm each Cortex Search service can be described:
DESCRIBE CORTEX SEARCH SERVICE <resource_database>.<resource_schema>.<service_name>;

A does not exist or not authorized error on a semantic view or Cortex Search service that exists means the Monte Carlo role is missing the grant.

Adding the agent in Monte Carlo

  1. In Monte Carlo, navigate to Settings โ†’ Agent Observability
  2. Click Add
  3. Choose Snowflake as the platform type
  4. Select a Domain for the agent to be assigned to
  5. Select a Snowflake Warehouse: Choose the warehouse where your target Cortex Agent(s) are available
  6. Select an Agent: Once the warehouse is selected, Monte Carlo will discover available Cortex Agents that it has permissions to access. Select the agent by its name
  7. Click Import to complete the connection

Once connected, Monte Carlo begins ingesting trace and span data and you're ready to create Agent Monitors.



Did this page help you?