Cortex Agents plan. Cortex Analyst writes the SQL. Cortex Search retrieves. Horizon Catalog governs the data. But the action the agent takes, what it queried, against whose semantic view, when, with what result, and on whose behalf, is still ungoverned the moment it crosses an account boundary. Hive signs every Cortex Agent action before it leaves the perimeter. Same Snowflake on top. A stronger, signed floor underneath. The governance story Snowflake already tells about data becomes the governance story you tell about agents.
From Baris on the Snowflake VP of AI podcast: "Agents need access to governed, well-modeled data, and a powerful context engine to deliver real business value." Horizon Catalog already governs the data. Cortex Analyst already grounds in semantic views. The next layer is the one that says "this agent, in this account, queried this semantic view, on behalf of this user, against this consumer share, at this timestamp." That is the receipt. That layer is still missing. We built it.
This is not about catching anyone. It is about deepening three advantages that get stronger the longer Snowflake runs the agent stack inside Horizon Catalog's perimeter.
Same Snowflake on the surface. A stronger floor underneath. You can pick up any one of these building blocks on its own, or run them as a full stack. Your call, not ours.
Six checks run on every Cortex Agent action: budget, scope, identity, time, location, chain. Privileged columns never leave their jurisdiction and never train a model. Every access gets signed and logged underneath Horizon RBAC.
A signed receipt for every Cortex Agent action. The plan hash, semantic view version, SQL fired, model version, result fingerprint, user, and timestamp all get locked down together. Admissible in court under FRE 901(b)(9) and 902(13) to (14). Easy for auditors and insurers to work with.
A way to process privileged columns without exposing them. Cortex Search can answer questions over a corpus the model never sees in plain text. If a subpoena comes, the answer is simple: we cannot produce what we never had.
Disclosure built for each consumer across data shares. Prove that every agent in the consumer account that touched your shared semantic view stayed within scope, without exposing the share itself. This is the receipt data providers have never been able to hand back to data consumers, until now.
Think of this as a menu, not a feature list. Every line below is something we ship today on top of the same four building blocks, and those four building blocks support any number of agent shapes underneath Cortex.
Signed proof for every Cortex Agent action: plan, SQL, retrieval, model, result. Auditors, regulators, malpractice carriers, and customer security teams all read the same signed record. The trust story Snowflake already tells about data becomes the trust story you tell about agents.
When a Cortex Agent in the consumer's account queries a share from the provider's account, both sides sign. The provider attests to the data version. The consumer attests to the use. Marketplace becomes a true two-sided market with settlement you can check underneath.
Cortex Search already grounds answers in retrieved chunks. Hive signs the chunk, the embedding version, the rerank score, and the answer. Instead of "trust the model," you get "here is the signed source."
SpectralZK runs analyses across columns Cortex never sees in plain text. Bulk redaction, bulk PII detection, bulk classification: all checkably correct without exposing the content. Built for healthcare, financial services, and other regulated workloads inside Snowflake.
Horizon governs data, lineage, and semantic views. Hive governs the agent actions taken on top. Same governance posture, same admin surface, with one extra column in the audit log: "signed receipt." It is a new revenue line that lives inside the catalog the customer already pays for.
Entity-specific budget gates, jurisdiction-aware data residency rules, and one unchangeable record across 50-plus Snowflake accounts. The same Fortune 500 buying motion Cortex already enables, now with the audit trail a global CISO will actually sign off on.
When one customer's Cortex Agent calls another customer's published data product, somebody owes somebody money. Hive ships the signed billing receipt, with usage, attribution, and settlement all locked down together. Marketplace stops being a catalog and becomes a metered exchange. See /gcai/billing/ for the envelope schema.
Cortex auto-selects between Claude, GPT, Llama, and Mistral. Hive signs the model version used for each action. Now you go from "we believe it was Claude 4.5" to "here is the signed receipt for which model ran what query, and when." This is the audit line every regulated customer will demand by 2027.
Run Cortex Analyst over PHI, PII, M&A cap tables, or federal clearance data, and the model never sees the row. Bulk classification, bulk obligation extraction, bulk diligence: all checkably correct without exposing the content. Built for HIPAA, FedRAMP, and GLBA workloads.
EU AI Act Article 12 (logging) and Article 50 (transparency) ask for exactly what SMSH already produces: unchangeable agent action logs and proof the user can see. Snowflake becomes the answer the regulated buyer can hand to their compliance team, instead of a question they have to answer themselves.
Cortex Agents already plan multi-step. Cortex Analyst writes the SQL. Cortex Search retrieves. Hive adds the signature on every step. The ten types below are common starting shapes, but the system supports any number of them. Whatever shape the customer's data team needs, the floor is the same: post-quantum signed, audit ready, billable on credit consumption.
Sits on top of Cortex Analyst. Turns plain-language questions into SQL against governed semantic views. Every query signed, every row read attested to, every result hashed. In any "show me your work" audit, the defense becomes a single browser link.
Cortex Search over the unstructured corpus: PDFs, contracts, support tickets, board decks. Every answer carries a signed, checkable citation back to the source chunk, the embedding version, the rerank score, and the timestamp.
Lives inside Horizon Catalog. Surfaces lineage, classifies sensitive columns, tags semantic-view drift. Every classification is a signed receipt that the compliance team can hand to an auditor without an Excel export.
Manages cross-account data shares. Every consumer-side agent that reads from the shared semantic view sends a countersigned receipt back to the provider. Marketplace publishers get attribution. Consumers get a defensible audit trail.
Sits over the SMSH receipt stream and answers the auditor's questions in real time. Ask "show me every Cortex Agent action that touched PII in the last 90 days" and get an answer in seconds, backed by signed proof. SOC 2 evidence collection drops from weeks to hours.
A PHI, PII, GDPR, and HIPAA specialist. SpectralZK processes regulated columns without Cortex ever touching the plain text. Bulk redaction, bulk classification, DSAR responses: all checkably correct, none exposed.
Owns the model version chain. Cortex auto-selects between Claude, GPT, Llama, and Mistral, and Modeler signs every selection. Now you go from "we believe it was Claude 4.5" to "here is the receipt for the exact model run at this exact time."
M&A diligence across structured and unstructured data: cap tables, contracts, financial records, customer data. Every finding signed, every privileged column processed without exposing it. The kind of answer outside counsel charges $300 an hour for.
A regulated-industry sentinel. Monitors every Cortex Agent action against firm-specific compliance rules like Reg-BI, MiFID II, GDPR, and HIPAA. SHOD gates catch a non-compliant action before it runs. SMSH signs every clean pass. The compliance officer's first cup of coffee just got shorter.
Lives between data providers and data consumers on Snowflake Marketplace. Provides metered, signed, billable access. Provider proves the data they delivered; consumer proves what they used; settlement is a signed receipt either side can hand to finance.
A board member emails the CFO: "I want every supplier we paid in Q1 that also did business with our top competitor, with revenue impact." CFO asks Snowflake Intelligence. The Analyst owns it end-to-end.
What got proven: the data was governed, the access was authorized, the citation checked out, and the cross-account share was countersigned. Five signed receipts, one human action, and an auditor can check the entire chain.
Twelve consumer banks subscribe. Each one runs Cortex Agents against the share. The provider needs to attribute usage, the consumers need a defensible record, and Snowflake needs both to settle in credits without disputes.
What got proven: the data provider got credited, the consumer's access stayed in scope, the model version was signed, and the settlement was machine readable. Marketplace becomes a true two-sided market with signed settlement underneath.
Healthcare. Financial services. Federal. Regulated manufacturing. Each one of these gets cheaper, faster, and easier to defend once signed proof of agent action is the floor, instead of the "trust me" posture every competitor still ships.
| Compliance line item | Without Hive | With Hive |
|---|---|---|
| SOC 2 Type II | 6-12 month audit · $200K+ | Cryptographically enforced from Day 1 · audit in 6 weeks |
| EU AI Act Art. 12 (logging) | Application-level log stitching | Immutable SMSH receipt per Cortex Agent action |
| EU AI Act Art. 50 (transparency) | Manual disclosure framework | User-facing receipt with model version and provenance |
| HIPAA / PHI | Trust-based BAAs · access controls | SpectralZK zero-knowledge column processing |
| FedRAMP / High | Custom audit packages | Cryptographic action attestation, drop-in |
| D&O insurance | Standard premiums | 20-30% reduction (cryptographic attestation) |
| Diligence posture (any path) | "We take security seriously" | "Post-quantum cryptographic proof per Cortex Agent action" |
Hive does not compete with Snowflake and does not sell to Snowflake's customers directly. We are the substrate underneath Cortex. You keep every customer, every credit, every Marketplace share, and you gain a foundation that gets stronger as the regulatory landscape gets harder.
Receipts read "Cortex Verified." Hive does not appear in the UI or the customer contract. You own brand, renewal, expansion.
Hive ships as a first-class capability inside Horizon Catalog. "Action governance" sits next to "data governance." Same admin surface, same audit posture, new column in the audit log: signed receipt.
Snowflake gets exclusive use of the Hive substrate in the AI data cloud category for a defined term. No competing data platform can ship the same primitives during the window.
Hive is a signing layer. It does not compete with Snowflake, does not store the customer's data, and does not run queries. It signs agent actions. Think of a notary: they do not own the documents they sign, but the signature still matters. The Simpson GC has explicitly cleared this conversation, and the build is mine. The Snowflake deployment Simpson runs is more protected with Hive underneath, not less.
Give us twenty minutes. No deck, no pitch, just a walkthrough of which of the ten pieces fit the Cortex roadmap and what a first engagement could look like. Bring whoever you want in the room.
Pick a 20-minute window →This newer receipt makes a governed agent action comparable when records meet across account boundaries. The code is complete, but it is not yet deployed, and the runs below show that state.
When the same agent action has a record on each side of an account boundary, this receipt compares their committed fingerprints. It records the named cursor and time for both observations, and checks that distinct attestor keys committed the same declared fields. The service recalculates the outcome from those fingerprints and the declared time window. Your platform and governance teams can use the result to spot an agreement or a divergence without opening the data in the records.
What it does not do. It does not reveal positions, balances, identities, account identifiers, or the data behind either fingerprint. It does not verify that either fingerprint faithfully represents its named record, decide which side is right when they differ, assign fault, judge an underlying transfer, register update, or settlement, or change any record or settlement; an exceeded time window is simply inconclusive.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.
Search the explorer for Snowflake use case