Before running OneData, a few things need to be in place: a Snowflake account with the right roles, an approved way to authenticate, and the Cortex Code CLI installed locally. This page walks through each.
Start with read-only access and add write access only when you actually want the agents to create or run objects in Snowflake. Production always sits behind a separate, gated path.
Read access to the schemas and tables needed for understanding metadata, profiling sources, and validating lineage. Enough for most of the workflow.
Needed only when the flow actually creates stages, tables, or tasks, or writes generated artifacts into Snowflake.
Production execution requires explicit approval gates, query tags, row-count checks, and DBA-controlled roles.
| Prerequisite | What's needed | Why |
|---|---|---|
| Snowflake account | Account identifier / URL, warehouse, database, schema | Cortex Code needs an active Snowflake session to work in. |
| Authentication | SSO (external browser) or a Programmatic Access Token (PAT), per your policy | Keeps passwords out of files; authenticates through an approved mechanism. |
| Read role | USAGE on warehouse/database/schema + SELECT on source metadata | Enough for schema understanding, profiling, validation, and code context. |
| Write role | CREATE TABLE/STAGE/TASK, INSERT/TRUNCATE where explicitly approved | Only required if you deploy or execute generated objects. |
| Local tools | VS Code, Cortex Code CLI, Snowflake CLI (snow), Python dependencies | Needed to run the CLI and the pipeline scripts. |
Two paths depending on whether your corporate proxy allows direct terminal downloads. Run PowerShell as Administrator.
# Path 1 — browser download if a corporate proxy blocks the terminal # 1. Open: https://ai.snowflake.com/static/cc-scripts/install.ps1 # 2. Save it as: C:\Temp\install-cortex.ps1 # Run PowerShell as Administrator, then: Set-ExecutionPolicy Bypass -Scope Process -Force C:\Temp\install-cortex.ps1 # Path 2 — direct install if allowed by your proxy / IT irm https://ai.snowflake.com/static/cc-scripts/install.ps1 | iex # Verify the install cortex --version snow --version
Create a connection profile so the CLI can reach your account. Start with a read-only role.
# Create / edit: C:\Users\<USER>\.snowflake\connections.toml [onedata_demo_read] account = "YOUR_ACCOUNT.snowflakecomputing.com" user = "YOUR_USERNAME" authenticator = "externalbrowser" # SSO, no password warehouse = "COMPUTE_WH_DEV" database = "ONE_DATA_AI_DEV" schema = "SILVER" role = "ONE_DATA_AI_READ_ROLE"
# Test the connection snow connection test onedata_demo_read # Start from the workspace root so Cortex discovers the .cortex package cd C:\path\to\OneDataAI cortex --profile onedata_demo_read
Safe approach: begin with a read-only role for schema understanding and artifact generation. Add a separate write/DDL role only when you explicitly want Cortex to create stages, tables, or tasks, or to execute generated DML.
Using a PAT? An administrator enables programmatic access tokens for the user in Snowflake/Snowsight. The user generates the token, copies it once, and stores it outside the project — in a secure profile or secret manager. Never paste a PAT into config, SQL, mapping files, or logs.