Snowflake agent blast radius: CoCo automations run-as identity and the two month evidence window · Enterprise Agentic AI Insights
Snowflake CoCo automations run as the creator's default role plus all secondary roles, with approval prompts off and 61 days of run history. Run the numbers.
What the CDO is staring at this week
There is a new object in the data estate that nobody put on the platform roadmap. On 21 August 2026, Snowflake moved CoCo automations to public preview in both the CoCo CLI and Snowsight. An automation turns a saved prompt into a recurring, unattended run that executes in a Snowflake-managed sandbox, on a schedule, whether or not anyone has a browser open. Minimum frequency is once per hour. It does not need a warehouse. VERIFIED C01
That last detail is the one that skips the usual review. A scheduled agent consumes standard task billing plus CoCo tokens per run, and none of it lands in the warehouse credit review where the data platform team looks for surprises. VERIFIED C01
So the first honest answer to "how many autonomous processes are running against our data estate" is that most teams do not know, and the place they would normally look does not show it.
---
The mechanic that is strained
Three sentences from Snowflake's product documentation define the whole exposure. They are worth reading in the vendor's words rather than anyone's summary.
One. The run does not use the role you had active.
> "A run does not use the role that was active in your CoCo session when you created the automation. > That role is not recorded on the agent task. Each run starts a task session whose primary role is > your user's default role, with your user's default secondary roles activated." VERIFIED C01
Two. Snowflake states the reach plainly.
> "If the user's default secondary roles include every role granted to them, a run can reach any > object that the user can reach through any of their roles." VERIFIED C01
Three. The approval model is switched off.
> "Automation runs are unattended, so interactive tool permission prompts are disabled. Tools that > are available to the run can execute without waiting for approval." VERIFIED C01
Put those together and the picture is specific rather than alarming. Role-based access control still applies. Row access policies still apply. Masking policies still apply. What is gone is the human at the confirmation dialog, which means the only boundary left standing is the exact boundary set by a field most organizations have treated as a login convenience for a decade.
DEFAULT_ROLE was never a security control. It just became an execution identity.
Two smaller items compound it. The privilege that permits scheduling, EXECUTE AGENT TASK, is granted to the PUBLIC role by default, so every user in the account has it unless an administrator changes the grant. VERIFIED C01 And a pre-run or post-run hook that exits non-zero does not fail the run. Task history records success. The guardrail you wrote can silently not execute while your monitoring reports green. VERIFIED C01
---
The number nobody has run yet: evidence half-life
This is where the data estate problem becomes a board problem, and it is arithmetic rather than opinion.
Snowflake's documentation sets a preview limit: automation threads and run history are retained for two months. VERIFIED C01 The SNOWFLAKE_COCO_USAGE_HISTORY view carries usage telemetry for a year. The TASK_HISTORY table function returns roughly the past seven days. CITED C02
Now line those windows up against how long an enterprise is expected to be able to explain an action.
| Evidence window | Duration | What it covers | |---|---|---| | TASK_HISTORY table function | ~7 days | Run state, error, query ID CITED C02 | | CoCo automation thread and run history | ~61 days | Tool calls, results, final response VERIFIED C01 | | SNOWFLAKE_COCO_USAGE_HISTORY | ~365 days | User, request, token credits, role metadata CITED C02 | | EU AI Act Article 19 log floor, high-risk | 180 days minimum | Automatically generated logs CITED C03 | | SEC Rule 17a-4 books and records | ~1,095 days and up | Broker-dealer records CITED C04 | | HIPAA documentation retention | ~2,190 days | Covered entity documentation CITED C05 |
The transcript is the only artifact that shows what the agent actually did, which tools it called, and what came back. That artifact has a two month half-life. Every duty in the lower half of that table outlives it by a factor of three to thirty-six.
The failure is not that an agent does something wrong. The failure is being asked, eleven months later, to explain an action and having only a token count left.
---
Interactive: unattended agent blast radius calculator
Run your own numbers. Nothing is sent anywhere. The inputs map to queries you can run yourself in the control sheet below.
<div id="ad-blast-calc" style="font-family:Roboto,'Helvetica Neue',Arial,sans-serif;background:#0D0F12;border:1px solid rgba(7,163,209,0.35);border-radius:16px;padding:28px;margin:32px 0;box-shadow:0 18px 50px rgba(0,0,0,0.45), inset 0 1px 0 rgba(255,255,255,0.08);"> <div style="font-size:13px;font-weight:600;letter-spacing:0.14em;text-transform:uppercase;color:#07A3D1;margin-bottom:8px;">Ariana.Digital · AEGIS Diagnostic tool</div> <h3 style="font-family:Radley,Georgia,serif;font-size:28px;line-height:1.25;color:rgba(237,232,227,1);margin:0 0 8px;">Unattended agent blast radius calculator</h3> <p style="font-size:16px;font-weight:500;line-height:1.55;color:rgba(237,232,227,0.88);margin:0 0 24px;">Five inputs. Two of them you can pull with a single query. The output is the sentence you owe your risk committee.</p>
<div style="display:grid;grid-template-columns:repeat(auto-fit,minmax(240px,1fr));gap:20px;"> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Users able to schedule an agent <input id="adc-users" type="number" min="1" value="400" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> </label> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Average roles granted per user <input id="adc-roles" type="number" min="1" value="7" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> </label> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Percent with secondary roles set to ALL <input id="adc-all" type="number" min="0" max="100" value="95" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> </label> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Scheduled runs per day, estate wide <input id="adc-runs" type="number" min="0" value="120" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> </label> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Your record-keeping duty <select id="adc-duty" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> <option value="6">6 months, EU AI Act Art. 19 floor</option> <option value="36" selected>36 months, SEC 17a-4 style</option> <option value="72">72 months, HIPAA style</option> <option value="84">84 months, SOX style</option> </select> </label> <label style="display:block;font-size:15px;font-weight:600;color:rgba(237,232,227,0.88);">Transcripts exported to durable storage <select id="adc-export" style="width:100%;margin-top:8px;padding:12px;font-size:16px;font-family:Roboto,sans-serif;font-weight:500;color:#0D0F12;background:#EDE8E3;border:2px solid rgba(7,163,209,0.4);border-radius:8px;min-height:44px;"> <option value="0" selected>No, we rely on platform retention</option> <option value="1">Yes, on a cadence under 61 days</option> </select> </label> </div>
<button id="adc-run" style="margin-top:24px;padding:14px 28px;min-height:44px;font-family:Roboto,sans-serif;font-size:16px;font-weight:600;color:#0D0F12;background:linear-gradient(180deg,#FF8A1A 0%,#FF4F00 100%);border:none;border-radius:10px;cursor:pointer;">Calculate blast radius</button>
<div id="adc-out" style="margin-top:26px;"></div>
<p style="font-size:13px;font-weight:500;line-height:1.5;color:rgba(237,232,227,0.72);margin:20px 0 0;">Method: identities = users × percent with ALL. Role surface = identities × roles per user. Unreviewed tool calls = runs per day × 365, since approval prompts are disabled on unattended runs. Evidence gap = duty in days minus 61 days of retained run history, and falls to zero once transcripts are exported to durable storage. Retention and approval behavior are from Snowflake product documentation, VERIFIED C01.</p> </div>
<script> (function () { var root = document.getElementById('ad-blast-calc'); if (!root) { return; } var btn = root.querySelector('#adc-run'); var out = root.querySelector('#adc-out'); function n(id, d) { var v = parseFloat((root.querySelector(id) || {}).value); return isFinite(v) ? v : d; } function fmt(x) { return Math.round(x).toLocaleString('en-US'); } function card(label, value, note, color) { return '<div style="background:rgba(255,255,255,0.04);border:1px solid ' + color + ';border-left:4px solid ' + color + ';border-radius:12px;padding:18px;">' + '<span style="display:block;font-size:13px;font-weight:600;letter-spacing:0.1em;text-transform:uppercase;color:' + color + ';margin-bottom:8px;">' + label + '</span>' + '<span style="display:block;font-family:Radley,Georgia,serif;font-size:34px;line-height:1.1;color:rgba(237,232,227,1);margin-bottom:6px;">' + value + '</span>' + '<span style="display:block;font-size:14px;font-weight:500;line-height:1.5;color:rgba(237,232,227,0.88);">' + note + '</span></div>'; } function run() { var users = n('#adc-users', 400), roles = n('#adc-roles', 7); var pct = Math.min(Math.max(n('#adc-all', 95), 0), 100), runs = n('#adc-runs', 120); var duty = n('#adc-duty', 36); var exported = n('#adc-export', 0) === 1; var ids = users (pct / 100); var surface = ids roles; var calls = runs 365; var gap = exported ? 0 : Math.max(0, Math.round(duty 30.4) - 61); var band, bandColor, bandNote; if (gap === 0 && surface < 500) { band = 'Contained'; bandColor = '#1DAA64'; bandNote = 'Transcripts outlive the duty and the role surface is small enough to enumerate. Keep it that way with a quarterly recheck of default secondary roles.'; } else if (gap === 0) { band = 'Attributable but wide'; bandColor = '#07A3D1'; bandNote = 'You can explain any action for the full period. The remaining exposure is reach, not evidence. Narrow default secondary roles on the accounts at the top of your list.'; } else if (gap < 400) { band = 'Exposed'; bandColor = '#F5A623'; bandNote = 'You can answer most questions, but not the oldest ones. Turning on transcript export closes this entire column.'; } else { band = 'Undefendable'; bandColor = '#FF4F00'; bandNote = 'An action taken today cannot be explained for most of the period you are required to explain it. Export the transcript or do not schedule the agent.'; } out.innerHTML = '<div style="display:grid;grid-template-columns:repeat(auto-fit,minmax(220px,1fr));gap:16px;">' + card('Effective agent identities', fmt(ids), 'Users whose default role becomes an execution identity the moment they schedule a run.', '#07A3D1') + card('Role grants reachable', fmt(surface), 'Role grants an unattended run can activate across the estate. This is the blast radius.', '#FF7900') + card('Unreviewed tool calls per year', fmt(calls), 'Approval prompts are disabled on unattended runs, so no human sees any of these.', '#FF7900') + card('Evidence gap', fmt(gap) + ' days', 'Days of your record-keeping duty with no transcript left to explain what an agent did.', '#FF4F00') + '</div>' + '<div style="margin-top:16px;background:rgba(255,255,255,0.04);border:1px solid ' + bandColor + ';border-radius:12px;padding:20px;">' + '<span style="display:block;font-size:13px;font-weight:600;letter-spacing:0.1em;text-transform:uppercase;color:' + bandColor + ';margin-bottom:8px;">Posture band: ' + band + '</span>' + '<span style="display:block;font-size:16px;font-weight:500;line-height:1.55;color:rgba(237,232,227,0.88);">' + bandNote + '</span></div>'; } btn.addEventListener('click', run); root.addEventListener('keydown', function (e) { if (e.key === 'Enter') { run(); } }); run(); })(); </script>
---
Side by side: what identity does a scheduled agent get?
Every platform shipping agents this quarter is answering the same question, and each one reached for an identity that already existed.
| Platform | Default run-as identity | Separate service identity available | Approval prompts on unattended runs | |---|---|---|---| | Snowflake CoCo automations | Creator's default role plus default secondary roles VERIFIED C01 | Not offered. Narrow the human instead VERIFIED C01 | Disabled VERIFIED C01 | | Databricks jobs | Job creator, set as Run as | Yes, change Run as to a service principal CITED C06 | Not applicable, jobs are non-interactive by design | | AWS Bedrock AgentCore | Execution role on the runtime, persistent instances added 21 Aug 2026 VERIFIED C07 | Yes, IAM role per runtime | Not applicable | | Microsoft Agent 365 with Entra | Agent identity in Entra, Conditional Access for Agents CITED C08 | Yes, agent is a first-class directory object | Policy driven |
The row that matters for a CDO is column three. On three of the four platforms, you can shrink the agent without shrinking a person. On the fourth, Snowflake's own guidance is to narrow the default role and default secondary roles of the user who owns the automation. VERIFIED C01 That is a real trade: you degrade an engineer's interactive access to constrain their scheduled job.
---
And here is why it is a board matter
The operational story above is a platform hygiene problem. Three regulatory facts turn it into a liability the CRO has to hold.
One. The transparency duty is live now. EU AI Act Article 50 became applicable on 2 August 2026 for systems that interact directly with people or generate synthetic content. It is not limited to high-risk systems. Penalties reach 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. VERIFIED C09 A scheduled agent that posts a digest into a channel a person reads sits inside that duty, and the artifact that proves what it posted expires in two months.
Worth stating plainly, because vendor commentary keeps getting it wrong: 2 August 2026 brought Article 50 into application. Annex III high-risk obligations are proposed for deferral to December 2027 and Annex I to August 2028 under the Digital Omnibus package. VERIFIED C09 The Article 19 six month log floor attaches to that deferred high-risk set. We use it here as the published European view of how long an AI system's own logs should survive, not as a duty that binds today.
Two. Your model risk register does not cover this. OCC Bulletin 2026-13, jointly designated SR 26-2 and issued 17 April 2026 with the Federal Reserve and FDIC, replaced SR 11-7 and states that generative and agentic AI models are outside its scope, directing institutions to apply broader risk management practices to systems it does not cover. VERIFIED C10 A scheduled agent is not a model under that guidance. It is also not nothing. The gap is yours to close by policy.
Three. Somebody already closed it. The Monetary Authority of Singapore confirmed on 5 August 2026 that autonomous AI agents fall inside its binding supervisory guidelines. CITED C11 When the first regulator writes the sentence, the sentence tends to travel.
Read against the AEGIS Framework, the Agentic Enterprise Governance and Intelligence Standard, this is a control failure at the identity and evidence layers at once. The agent has a name. It does not have scoped authority, and the record of what it did has a shorter life than the question it will be asked.
---
The move
Four steps. The first two are reversible in one statement each, which is a good argument for doing them before the debate rather than after it.
1. Find out whether the capability is already live. Run SHOW GRANTS TO ROLE PUBLIC; and look for EXECUTE AGENT TASK on the account. If it is there and nobody decided it should be, you have an open capability, not a deployed one.
2. Take the grant back and re-issue it narrowly. Snowflake documents the exact pair: revoke EXECUTE AGENT TASK on account from PUBLIC, then grant it to a named role for the teams that need it. Existing run history survives the revoke, and automations resume if access is restored later. VERIFIED C01
3. Inventory the identities before you inventory the agents. Pull NAME, DEFAULT_ROLE and DEFAULT_SECONDARY_ROLE from SNOWFLAKE.ACCOUNT_USAGE.USERS and sort by how many roles each user holds. The people at the top of that list are your largest potential agent identities whether or not they have created one yet. Set secondary roles to an empty list on service-shaped and contractor accounts first. Those cost the least in daily friction and remove the most reach. CITED C02
4. Write the evidence rule before the first production automation. Export the run transcript to durable storage on a cadence shorter than the two month window. Sixty-one days of vendor-held history is a product limit, not a retention policy. The policy sentence most teams are missing reads: a scheduled agent may not run under a human's default role, and its transcript is exported before the platform drops it.
That fourth one is the whole piece in a sentence. Everything else is configuration.
---
Download: the unattended agent run control sheet
A one-page control sheet for the data platform lead and the AI implementation consultant. Five preflight queries, the run-as identity comparison, the evidence export rule, and the four sign-offs to collect before an automation goes into production.
[Download the control sheet](https://ariana.digital/ai-success-pack.html) · [Book a 30-minute AEGIS Diagnostic](https://ariana.digital/ai-governance.html)
---
Sources
- C01 · VERIFIED · Snowflake, CoCo automations in CLI and Snowsight (Preview), product documentation.
Run-as identity, secondary roles, disabled approval prompts, EXECUTE AGENT TASK on PUBLIC, hook failure behavior, two month retention, revoke syntax. https://docs.snowflake.com/en/user-guide/cortex-code/cortex-code-automations
- C01 · VERIFIED · Snowflake release note, 21 August 2026.
https://docs.snowflake.com/en/release-notes/2026/other/2026-08-21-cortex-code-automations-preview
- C02 · CITED · Snowflake account usage and task history references, retention windows and user role columns.
https://docs.snowflake.com/en/sql-reference/account-usage/users · https://docs.snowflake.com/en/sql-reference/functions/taskhistory · https://docs.snowflake.com/en/sql-reference/account-usage/snowflakecocousagehistory
- C03 · CITED · EU AI Act Article 19, automatically generated logs, six month minimum for high-risk providers.
https://artificialintelligenceact.eu/article/19/
- C04 · CITED · SEC Rule 17a-4 books and records retention for broker-dealers.
https://www.sec.gov/rules-regulations/2022/10/electronic-recordkeeping-requirements-broker-dealers
- C05 · CITED · HIPAA documentation retention, 45 CFR 164.316(b)(2).
https://www.hhs.gov/hipaa/for-professionals/security/laws-regulations/index.html
- C06 · CITED · Databricks, configure Run as identity for jobs, service principal recommendation.
https://docs.databricks.com/aws/en/jobs/privileges
- C07 · VERIFIED · AWS Bedrock AgentCore Web Search and Payments general availability, persistent runtimes, 21 August 2026.
https://aiagentstore.ai/ai-agent-news/this-week
- C08 · CITED · Microsoft Entra Conditional Access for Agents and Agent 365 agent identity.
https://learn.microsoft.com/en-us/entra/identity/conditional-access/
- C09 · VERIFIED · EU AI Act Article 50 applicability 2 August 2026, transparency guidelines 20 July 2026,
Digital Omnibus deferral of Annex III to December 2027 and Annex I to August 2028. https://artificialintelligenceact.eu/article/50/ · https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content · https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026
- C10 · VERIFIED · OCC Bulletin 2026-13 / SR 26-2, 17 April 2026, replaces SR 11-7, generative and agentic AI out of scope.
https://www.occ.gov/news-issuances/bulletins/2026/bulletin-2026-13.html
- C11 · CITED · MAS places autonomous AI agents inside binding supervisory guidelines, 5 August 2026.
https://www.techtimes.com/articles/323283/20260806/mas-confirms-agentic-ai-inside-binding-bank-rules-us-eu-fall-behind.htm
---
Method and correction policy
Every edition is researched fresh against sources published within the preceding seven days where the item is time-sensitive. Figures carry a chip: VERIFIED means named, dated and publicly checkable; CITED means named source, not independently re-verified; FLAG means contested and pending re-verification. Where market commentary conflicted with primary legal sources this week, notably on EU high-risk applicability, we followed the primary legal sources and said so.
© Ariana Digital LLC. All rights reserved. Not legal advice. Regulatory positions summarized here should be confirmed with counsel before reliance. Produce with Frontier AI and HITL.