Sealed brief · for Baris Gultekin · revisited

Snowflake built the data engine for AI. Hive seals the agent action.

Cortex Agents plan. Cortex Analyst writes the SQL. Cortex Search retrieves. Horizon Catalog governs the data. But the action the agent takes, what it queried, against whose semantic view, when, with what result, and on whose behalf, is still ungoverned the moment it crosses an account boundary. Hive signs every Cortex Agent action before it leaves the perimeter. Same Snowflake on top. A stronger, signed floor underneath. The governance story Snowflake already tells about data becomes the governance story you tell about agents.

Live mint · today PQ · ML-DSA-65 FRE 901(b)(9) / 902(13) to (14) EU AI Act Art. 12 + 50 ready NIST AI RMF aligned USPTO provisional · 2026-05-23
What Baris has already said matters

You said context is everything. Hive is the layer that makes context provable when it leaves the account.

From Baris on the Snowflake VP of AI podcast: "Agents need access to governed, well-modeled data, and a powerful context engine to deliver real business value." Horizon Catalog already governs the data. Cortex Analyst already grounds in semantic views. The next layer is the one that says "this agent, in this account, queried this semantic view, on behalf of this user, against this consumer share, at this timestamp." That is the receipt. That layer is still missing. We built it.

Data is governed

Horizon Catalog

Today
Lineage, semantic views, vector search, RBAC
With Hive
Every agent read against governed data gets a signed receipt, so an auditor can check the access in a browser.
Action is not yet governed

The agent action

Today
Cortex Agent plans, fires SQL, returns answer
With Hive
Plan hashed. SQL signed. Result attested. Cross-account hand-off countersigned. Same agent, governed end-to-end.
Context is grounded

Cortex Analyst + Search

Today
Semantic views, embeddings, hybrid retrieval
With Hive
Every grounded answer carries a Cryptographically Verified Citation back to the row, the document, the embedding version.
Sharing is the unsolved part

Cross-account agent calls

Today
Data shared via Snowflake Marketplace and direct shares
With Hive
Agent-to-agent calls across accounts get a countersigned receipt: the provider signs the data, the consumer signs the acceptance.
Where Snowflake wins the agent decade: three structural advantages

Databricks wants the lakehouse. Salesforce wants the agent. Snowflake already owns the governed data, and Hive is the layer that turns governed data into governed agent action.

This is not about catching anyone. It is about deepening three advantages that get stronger the longer Snowflake runs the agent stack inside Horizon Catalog's perimeter.

Distribution
Already inside the account
Cortex Agents already run inside the customer's Snowflake account, inside Horizon governance, inside the security perimeter that ten thousand enterprises already trust. Hive layers underneath without touching a single UX surface or integration Snowflake has shipped. Databricks cannot match this distribution. Salesforce does not have the data underneath.
Substrate
Governance becomes provability
Horizon governs data. Hive governs action. Together, Snowflake's answer to the AI trust question becomes the most complete one in the market: post-quantum signed receipts for every Cortex Agent action, zero-knowledge processing of privileged columns, and unchangeable audit trails across cross-account shares. A foundation auditors can check in a browser.
Economics
A line on the P&L, not a war chest
Signed proof of agent actions ships as a Cortex add-on or a Horizon-level capability. It is a modest infrastructure line that scales with credit consumption, the same shape Snowflake already prices. No capex, no separate procurement path, no rebuilding what Cortex already does well.
How it works, in plain terms

Four building blocks. One system. Every Cortex Agent action sealed before it crosses an account boundary.

Same Snowflake on the surface. A stronger floor underneath. You can pick up any one of these building blocks on its own, or run them as a full stack. Your call, not ours.

PRIMITIVE 01

SHOD gates

Six checks run on every Cortex Agent action: budget, scope, identity, time, location, chain. Privileged columns never leave their jurisdiction and never train a model. Every access gets signed and logged underneath Horizon RBAC.

PRIMITIVE 02

SMSH indexing

A signed receipt for every Cortex Agent action. The plan hash, semantic view version, SQL fired, model version, result fingerprint, user, and timestamp all get locked down together. Admissible in court under FRE 901(b)(9) and 902(13) to (14). Easy for auditors and insurers to work with.

PRIMITIVE 03

SpectralZK

A way to process privileged columns without exposing them. Cortex Search can answer questions over a corpus the model never sees in plain text. If a subpoena comes, the answer is simple: we cannot produce what we never had.

PRIMITIVE 04

ViewKey

Disclosure built for each consumer across data shares. Prove that every agent in the consumer account that touched your shared semantic view stayed within scope, without exposing the share itself. This is the receipt data providers have never been able to hand back to data consumers, until now.

Ten ways Hive strengthens what Snowflake already shipped

Each one is a real product. Pick the ones that fit the Cortex roadmap. We deliver underneath the UX.

Think of this as a menu, not a feature list. Every line below is something we ship today on top of the same four building blocks, and those four building blocks support any number of agent shapes underneath Cortex.

VICTORY 01 · ACTION PROVENANCE

From "Cortex Agent answered" to "Cortex Agent answered, signed."

Signed proof for every Cortex Agent action: plan, SQL, retrieval, model, result. Auditors, regulators, malpractice carriers, and customer security teams all read the same signed record. The trust story Snowflake already tells about data becomes the trust story you tell about agents.

VICTORY 02 · CROSS-ACCOUNT RECEIPTS

The countersigned receipt for data shares.

When a Cortex Agent in the consumer's account queries a share from the provider's account, both sides sign. The provider attests to the data version. The consumer attests to the use. Marketplace becomes a true two-sided market with settlement you can check underneath.

VICTORY 03 · CITATION INTEGRITY

From RAG answer to a signed, checkable citation.

Cortex Search already grounds answers in retrieved chunks. Hive signs the chunk, the embedding version, the rerank score, and the answer. Instead of "trust the model," you get "here is the signed source."

VICTORY 04 · PRIVILEGE PRESERVING

Processing privileged columns without exposing them.

SpectralZK runs analyses across columns Cortex never sees in plain text. Bulk redaction, bulk PII detection, bulk classification: all checkably correct without exposing the content. Built for healthcare, financial services, and other regulated workloads inside Snowflake.

VICTORY 05 · HORIZON EXTENSION

Horizon Catalog, extended to actions.

Horizon governs data, lineage, and semantic views. Hive governs the agent actions taken on top. Same governance posture, same admin surface, with one extra column in the audit log: "signed receipt." It is a new revenue line that lives inside the catalog the customer already pays for.

VICTORY 06 · MULTI-ACCOUNT GOVERNANCE

Multinational Snowflake operations.

Entity-specific budget gates, jurisdiction-aware data residency rules, and one unchangeable record across 50-plus Snowflake accounts. The same Fortune 500 buying motion Cortex already enables, now with the audit trail a global CISO will actually sign off on.

VICTORY 07 · A2A BILLING UNDER CORTEX

Agent-to-agent billing rails for Marketplace.

When one customer's Cortex Agent calls another customer's published data product, somebody owes somebody money. Hive ships the signed billing receipt, with usage, attribution, and settlement all locked down together. Marketplace stops being a catalog and becomes a metered exchange. See /gcai/billing/ for the envelope schema.

VICTORY 08 · MODEL DRIFT ATTESTATION

A signed chain of custody for model versions.

Cortex auto-selects between Claude, GPT, Llama, and Mistral. Hive signs the model version used for each action. Now you go from "we believe it was Claude 4.5" to "here is the signed receipt for which model ran what query, and when." This is the audit line every regulated customer will demand by 2027.

VICTORY 09 · ZK-PROCESSING

Processing regulated data without exposing it.

Run Cortex Analyst over PHI, PII, M&A cap tables, or federal clearance data, and the model never sees the row. Bulk classification, bulk obligation extraction, bulk diligence: all checkably correct without exposing the content. Built for HIPAA, FedRAMP, and GLBA workloads.

VICTORY 10 · EU AI ACT READY

The compliance story for every regulated industry.

EU AI Act Article 12 (logging) and Article 50 (transparency) ask for exactly what SMSH already produces: unchangeable agent action logs and proof the user can see. Snowflake becomes the answer the regulated buyer can hand to their compliance team, instead of a question they have to answer themselves.

Stand up signed Cortex Agents inside the account before lunch

Set up as many signed agents underneath Cortex as you need. Any shape, any specialty, any depth. Every action sealed against Horizon governance.

Cortex Agents already plan multi-step. Cortex Analyst writes the SQL. Cortex Search retrieves. Hive adds the signature on every step. The ten types below are common starting shapes, but the system supports any number of them. Whatever shape the customer's data team needs, the floor is the same: post-quantum signed, audit ready, billable on credit consumption.

Lives inside Cortex Inside Horizon governance Every action a signed receipt Bills against credits
Agent 01 · Analyst

Analyst.

Sits on top of Cortex Analyst. Turns plain-language questions into SQL against governed semantic views. Every query signed, every row read attested to, every result hashed. In any "show me your work" audit, the defense becomes a single browser link.

Agent 02 · Librarian

Librarian.

Cortex Search over the unstructured corpus: PDFs, contracts, support tickets, board decks. Every answer carries a signed, checkable citation back to the source chunk, the embedding version, the rerank score, and the timestamp.

Agent 03 · Steward

Steward.

Lives inside Horizon Catalog. Surfaces lineage, classifies sensitive columns, tags semantic-view drift. Every classification is a signed receipt that the compliance team can hand to an auditor without an Excel export.

Agent 04 · Sharer

Sharer.

Manages cross-account data shares. Every consumer-side agent that reads from the shared semantic view sends a countersigned receipt back to the provider. Marketplace publishers get attribution. Consumers get a defensible audit trail.

Agent 05 · Auditor

Auditor.

Sits over the SMSH receipt stream and answers the auditor's questions in real time. Ask "show me every Cortex Agent action that touched PII in the last 90 days" and get an answer in seconds, backed by signed proof. SOC 2 evidence collection drops from weeks to hours.

Agent 06 · Privacy

Privacy.

A PHI, PII, GDPR, and HIPAA specialist. SpectralZK processes regulated columns without Cortex ever touching the plain text. Bulk redaction, bulk classification, DSAR responses: all checkably correct, none exposed.

Agent 07 · Modeler

Modeler.

Owns the model version chain. Cortex auto-selects between Claude, GPT, Llama, and Mistral, and Modeler signs every selection. Now you go from "we believe it was Claude 4.5" to "here is the receipt for the exact model run at this exact time."

Agent 08 · Diligence

Diligence.

M&A diligence across structured and unstructured data: cap tables, contracts, financial records, customer data. Every finding signed, every privileged column processed without exposing it. The kind of answer outside counsel charges $300 an hour for.

Agent 09 · Risk

Risk.

A regulated-industry sentinel. Monitors every Cortex Agent action against firm-specific compliance rules like Reg-BI, MiFID II, GDPR, and HIPAA. SHOD gates catch a non-compliant action before it runs. SMSH signs every clean pass. The compliance officer's first cup of coffee just got shorter.

Agent 10 · Marketplace

Marketplace.

Lives between data providers and data consumers on Snowflake Marketplace. Provides metered, signed, billable access. Provider proves the data they delivered; consumer proves what they used; settlement is a signed receipt either side can hand to finance.

What an agent actually does: two day-in-the-life walkthroughs

Same system underneath. Different shape on top. Each step below is a signed receipt that Snowflake bills against on credits, and an auditor can check it in a browser.

A day with the Analyst

Tuesday, 9:00 AM. A Fortune 100 CFO's office.

A board member emails the CFO: "I want every supplier we paid in Q1 that also did business with our top competitor, with revenue impact." CFO asks Snowflake Intelligence. The Analyst owns it end-to-end.

  1. 9:01: The Analyst gets the question. The SHOD gate checks it: CFO role, board-prep scope, no PII, audit flagged. Signed receipt #1.
  2. 9:02: Cortex Analyst turns it into SQL against the governed semantic view. Hive signs the SQL, the semantic view version, the row count, and the result fingerprint. Signed receipt #2.
  3. 9:03: Cortex Search pulls supplier diligence memos from the unstructured corpus, with signed, checkable citations to each source chunk. Signed receipt #3.
  4. 9:04: A cross-account share from the M&A team's competitor-intelligence Snowflake account fires. Sharer countersigns: the provider attests to the data version, the CFO's Analyst attests to the use. Signed receipt #4.
  5. 9:05: A one-page memo goes to the CFO. Every claim cites a receipt, and every receipt can be checked in a browser. The board call at 10:00 AM has its answer, and opposing counsel cannot dispute the methodology two years later.

What got proven: the data was governed, the access was authorized, the citation checked out, and the cross-account share was countersigned. Five signed receipts, one human action, and an auditor can check the entire chain.

A day with the Marketplace agent

Wednesday, 2:15 PM. A Marketplace data provider publishes a new credit-risk model.

Twelve consumer banks subscribe. Each one runs Cortex Agents against the share. The provider needs to attribute usage, the consumers need a defensible record, and Snowflake needs both to settle in credits without disputes.

  1. 2:16: The Marketplace Agent in the provider account signs the publication: model version, semantic view shape, pricing curve. Receipt #1 locked in.
  2. 2:31: The first consumer bank's Cortex Agent queries the share. The SHOD gate checks the consumer side, ViewKey scopes the disclosure, and SMSH issues receipts on both sides. The provider sees attributable usage, the consumer sees signed access. Receipt #2.
  3. 3:14: By end of day, 412 Cortex Agent calls have crossed the share. Each one gets a signed receipt on both sides. Settlement is a single hash that finance teams on both sides can check against each other instantly.
  4. Friday morning: The monthly invoice runs. Snowflake settles credits between accounts. Provider attribution can be checked, consumer usage can be checked, and disputes drop to zero. Marketplace stops being a catalog and becomes a metered exchange.

What got proven: the data provider got credited, the consumer's access stayed in scope, the model version was signed, and the settlement was machine readable. Marketplace becomes a true two-sided market with signed settlement underneath.

An action layer inside the data layer.
Each customer sets up exactly the agents they need: ten, fifty, two hundred, shaped for their own workload. Every mint is a signed receipt against credits. Every action is a metered event. Snowflake keeps the platform margin, Hive provides the substrate, and the customer gets governed agents that sign their own work and grow with the data estate.
Walk through the substrate →
Whatever the next chapter looks like

Compliance readiness for every Cortex customer Snowflake wants to win next.

Healthcare. Financial services. Federal. Regulated manufacturing. Each one of these gets cheaper, faster, and easier to defend once signed proof of agent action is the floor, instead of the "trust me" posture every competitor still ships.

Compliance line itemWithout HiveWith Hive
SOC 2 Type II6-12 month audit · $200K+Cryptographically enforced from Day 1 · audit in 6 weeks
EU AI Act Art. 12 (logging)Application-level log stitchingImmutable SMSH receipt per Cortex Agent action
EU AI Act Art. 50 (transparency)Manual disclosure frameworkUser-facing receipt with model version and provenance
HIPAA / PHITrust-based BAAs · access controlsSpectralZK zero-knowledge column processing
FedRAMP / HighCustom audit packagesCryptographic action attestation, drop-in
D&O insuranceStandard premiums20-30% reduction (cryptographic attestation)
Diligence posture (any path)"We take security seriously""Post-quantum cryptographic proof per Cortex Agent action"
Cheaper · faster · provable
Signed proof of agent actions improves every regulated-buyer conversation Snowflake wants to be in. You pick the workload. The floor is the same.
Twenty minutes →
Three structures, your pick

You pick the shape of the relationship. We ride underneath either way.

Hive does not compete with Snowflake and does not sell to Snowflake's customers directly. We are the substrate underneath Cortex. You keep every customer, every credit, every Marketplace share, and you gain a foundation that gets stronger as the regulatory landscape gets harder.

White-label OEM.

Hive invisible

Receipts read "Cortex Verified." Hive does not appear in the UI or the customer contract. You own brand, renewal, expansion.

  • Per-action infrastructure fee in the cost stack
  • Cleanest path through enterprise procurement
  • Hive backs you on regulatory questions, silently
Scope a call →

Horizon-layer integration.

Closest fit to the catalog

Hive ships as a first-class capability inside Horizon Catalog. "Action governance" sits next to "data governance." Same admin surface, same audit posture, new column in the audit log: signed receipt.

  • Net-new revenue line inside the catalog the customer already pays for
  • Co-presented to enterprise prospects and partners
  • The compliance answer every regulated buyer demands by 2027
Scope a call →

Category exclusive.

12 to 24 months

Snowflake gets exclusive use of the Hive substrate in the AI data cloud category for a defined term. No competing data platform can ship the same primitives during the window.

  • Highest license cost · highest moat
  • Clean room for 12 to 24 months on signed agent action
  • Strengthens whichever direction you choose next
Scope a call →
About the Simpson side of this

Worth saying plainly: Hive is infrastructure, not a data platform.

Hive is a signing layer. It does not compete with Snowflake, does not store the customer's data, and does not run queries. It signs agent actions. Think of a notary: they do not own the documents they sign, but the signature still matters. The Simpson GC has explicitly cleared this conversation, and the build is mine. The Snowflake deployment Simpson runs is more protected with Hive underneath, not less.

You built the data engine the enterprise already trusts. Let us help you make every agent action on top of it provable.

Give us twenty minutes. No deck, no pitch, just a walkthrough of which of the ten pieces fit the Cortex roadmap and what a first engagement could look like. Bring whoever you want in the room.

Pick a 20-minute window →
new in the canon · runnable on this page

Make two governed records comparable

This newer receipt makes a governed agent action comparable when records meet across account boundaries. The code is complete, but it is not yet deployed, and the runs below show that state.

ledger.parity · Code complete, not deployed

Compare records on the same governed agent action

When the same agent action has a record on each side of an account boundary, this receipt compares their committed fingerprints. It records the named cursor and time for both observations, and checks that distinct attestor keys committed the same declared fields. The service recalculates the outcome from those fingerprints and the declared time window. Your platform and governance teams can use the result to spot an agreement or a divergence without opening the data in the records.

What it does not do. It does not reveal positions, balances, identities, account identifiers, or the data behind either fingerprint. It does not verify that either fingerprint faithfully represents its named record, decide which side is right when they differ, assign fault, judge an underlying transfer, register update, or settlement, or change any record or settlement; an exceeded time window is simply inconclusive.

POST /verify/ledger-parity · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/ledger-parity · case diverge, the two records disagree

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/ledger-parity · case fail, a forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.