⚙️

Setup & Installation

Before running OneData, a few things need to be in place: a Snowflake account with the right roles, an approved way to authenticate, and the Cortex Code CLI installed locally. This page walks through each.

Roles — least privilege first

Start with read-only access and add write access only when you actually want the agents to create or run objects in Snowflake. Production always sits behind a separate, gated path.

👁️
Read role

Discovery & profiling

Read access to the schemas and tables needed for understanding metadata, profiling sources, and validating lineage. Enough for most of the workflow.

✎️
Write / DDL role

Only if creating objects

Needed only when the flow actually creates stages, tables, or tasks, or writes generated artifacts into Snowflake.

🔐
Production guard

Separate PROD path

Production execution requires explicit approval gates, query tags, row-count checks, and DBA-controlled roles.

Prerequisites checklist

PrerequisiteWhat's neededWhy
Snowflake accountAccount identifier / URL, warehouse, database, schemaCortex Code needs an active Snowflake session to work in.
AuthenticationSSO (external browser) or a Programmatic Access Token (PAT), per your policyKeeps passwords out of files; authenticates through an approved mechanism.
Read roleUSAGE on warehouse/database/schema + SELECT on source metadataEnough for schema understanding, profiling, validation, and code context.
Write roleCREATE TABLE/STAGE/TASK, INSERT/TRUNCATE where explicitly approvedOnly required if you deploy or execute generated objects.
Local toolsVS Code, Cortex Code CLI, Snowflake CLI (snow), Python dependenciesNeeded to run the CLI and the pipeline scripts.

Install the Cortex Code CLI (Windows)

Two paths depending on whether your corporate proxy allows direct terminal downloads. Run PowerShell as Administrator.

PowerShell — install
# Path 1 — browser download if a corporate proxy blocks the terminal
# 1. Open: https://ai.snowflake.com/static/cc-scripts/install.ps1
# 2. Save it as: C:\Temp\install-cortex.ps1

# Run PowerShell as Administrator, then:
Set-ExecutionPolicy Bypass -Scope Process -Force
C:\Temp\install-cortex.ps1

# Path 2 — direct install if allowed by your proxy / IT
irm https://ai.snowflake.com/static/cc-scripts/install.ps1 | iex

# Verify the install
cortex --version
snow --version

Configure your Snowflake connection

Create a connection profile so the CLI can reach your account. Start with a read-only role.

connections.toml
# Create / edit: C:\Users\<USER>\.snowflake\connections.toml

[onedata_demo_read]
account       = "YOUR_ACCOUNT.snowflakecomputing.com"
user          = "YOUR_USERNAME"
authenticator = "externalbrowser"   # SSO, no password
warehouse     = "COMPUTE_WH_DEV"
database      = "ONE_DATA_AI_DEV"
schema        = "SILVER"
role          = "ONE_DATA_AI_READ_ROLE"
Terminal — test & launch
# Test the connection
snow connection test onedata_demo_read

# Start from the workspace root so Cortex discovers the .cortex package
cd C:\path\to\OneDataAI
cortex --profile onedata_demo_read
✅

Safe approach: begin with a read-only role for schema understanding and artifact generation. Add a separate write/DDL role only when you explicitly want Cortex to create stages, tables, or tasks, or to execute generated DML.

🔑

Using a PAT? An administrator enables programmatic access tokens for the user in Snowflake/Snowsight. The user generates the token, copies it once, and stores it outside the project — in a secure profile or secret manager. Never paste a PAT into config, SQL, mapping files, or logs.