# Snowflake AI Data Cloud — 4+1 Layer AI Infrastructure Assessment

> Mapped to the 4+1 Layer AI Infrastructure Model  
> Version: v1.1 - 4+1 v2: 1C Authority Under the Override Rule · Date: September 4, 2026  
> Source: docs.snowflake.com (release notes January to September 2026; Snowpark Container Services instance families per cloud; Cortex Agents, Cortex Search, AI Observability, agent identity, Horizon Catalog, catalog-linked databases, Openflow, Snowflake Postgres, Model Registry and Model Serving guides), Snowflake Summit 2026 press releases (June 2, 2026), Black Hat 2026 AI security announcement (July 28, 2026), Snowflake engineering blog (Horizon Catalog on Apache Polaris, Observe by Snowflake, Adaptive Compute), Apache Polaris project (top-level graduation February 2026), Hugging Face model cards (snowflake-arctic-embed, Apache 2.0), dbt Labs licensing posts, published 4+1 model. Scored on public documentation only. Layer 2C observability leg and Layer 3 read against the Observe acquisition (announced January 8, 2026; closed February 2026). Layer 1B and 1A policy-boundary findings quoted from the Cortex Search and Snowflake Postgres docs. Reconciliation (September 4, 2026): 1A statusLabel moved to capability vocabulary per the statusLabel convention; duplicated 2B incident narration trimmed to a source caveat; no grade or chip changed. Peer review (September 4, 2026; Antigravity gemini-3.1-pro-high, 4 claims; ChatGPT gpt-5.5, 6 claims; ledgers labs/reviews/snowflake-row.json and snowflake-row-chatgpt.json): Snowpipe Streaming corrected to 10 GB/s per table (docs); Graviton3 removed from the Gen2 clause; GPT-5.6 moved to the watch-list as private preview; CoWork GA corrected to November 4, 2025 with June 2, 2026 as the rename; the bundled embedding chip split into Arctic (Delegated, open weights) and Voyage (Ceded, channel substitution); DCM Projects (GA August 7, 2026) added as a Ceded 2A component; customer-created tools held Retained with the detail sharpened (tool logic is the customer's, wrapper is Snowflake's, Snowflake Scripting is the Oracle-shaped exception); 2C authority held Delegated. No layer status changed. /reconcile (September 4, 2026, override rule ratified on the Elastic row): Layer 1C authority Ceded to Delegated. Engine judgment on refresh strategy inside enterprise-authored definitions, with per-object overrides (TARGET_LAG, REFRESH_MODE) the engine must honor. Portability unchanged. No status changed.  
> Published by: The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com  
> Author: Keith Townsend

[Full interactive assessment](https://layer2c.com/assessment/snowflake) · [Methodology](https://layer2c.com/methodology) · [What Is Layer 2C?](https://layer2c.com/what-is-layer-2c)

## Executive Summary

Snowflake is a data and AI platform that floats above Layer 0, owning no silicon and renting all three clouds, and is strong across the data plane (1A, 1B, 1C), the application runtime (2B), and the value plane (3). It moderates only where it doesn't own the layer: infrastructure orchestration (2A), where compute pools are proprietary node-level scheduling on rented instances, and the reasoning plane (2C), where agent identity and observability are GA but the request-time gateway and native multi-agent orchestration aren't. Authority sits in Snowflake's opinion layer wherever Snowflake ships one; the substrate never.

Two capture generations coexist, and the buyer usually sees only one. The classic estate is coupled and visible: native tables in Snowflake's proprietary format, in Snowflake-managed storage, readable by nothing else. The new estate is decoupled and invisible, the Databricks shape exactly: Iceberg bytes in the customer's bucket, exposed to nine engines through a Polaris-based REST endpoint with read and write GA, while the governance that makes those bytes usable (Horizon's grants, masking, tags, lineage, agent identity) is Snowflake SQL that lifts to nowhere. The reach of that governance is narrower than it reads, and the docs say so: policies follow the data to Spark for reads, do not apply inside a Cortex Search service, and do not cross into a Snowflake Postgres instance. The default table type is still the coupled one. That's the finding: Snowflake's openness is real, and it's the newer, smaller half of what customers actually hold.

The status line matches Databricks on all eight layers; the DAPM profiles don't quite. Of 36 scored components, 25 are Ceded, 9 Delegated, and 2 Retained, where Databricks has none Retained. A customer-operated Apache Polaris as catalog of record, with Snowflake attached as a guest engine through a GA read-write catalog-linked database, is the first Retained catalog path among the managed data platforms on the instrument. It exists because open-source Polaris ships role-based access control and credential vending where open-source Unity Catalog doesn't. Open-weight Arctic embeddings make stored vectors portable, which no other row has earned. And agent identity models autonomous agents as a distinct principal type with the agent chain recorded per object access, the deepest identity leg on the map. Against that, Snowflake is a leg short at 2C where Databricks has a GA gateway and a GA supervisor.

The NVIDIA column is near-empty by design. Snowflake exposes whole NVIDIA GPUs through instance families on all three clouds and nothing else: no NVIDIA scheduler, no NIM, no datacenter-class H100 or Blackwell parts in the catalog. The generative chain instead borrows judgment from Anthropic, OpenAI, and Google behind a standard completions interface, with 'auto' model selection as the one place Snowflake decides invisibly.

The buyer gets a complete, GA, three-cloud data and AI platform with the most open catalog posture in its class, in exchange for ceding every opinion layer Snowflake ships: governance, pipelines, retrieval, agents, applications. You keep your Iceberg bytes and can keep your own catalog. You do not keep your policies, your pipelines, or your agents. Snowflake owns the lakehouse and the agent runtime on top of it. It does not own the silicon beneath, it does not yet gate agent traffic at a single point, and it does not reason about where inference runs.

## Layer Status

| Layer | Status | Classification |
|---|---|---|
| Layer 0 · Compute | ○ Not Snowflake's Layer (By Design) | Compute & Network Fabric |
| Layer 1A · Storage | ● Snowflake Strength: Governed Lakehouse Across Three Clouds | Data Storage & Governance |
| Layer 1B · Retrieval | ● Native Hybrid Retrieval + Governed Semantic Layer | Context Management & Retrieval |
| Layer 1C · Pipelines | ● Openflow + Streaming + Declarative Pipelines | Data Movement & Pipelines |
| Layer 2A · Orchestration | ◑ Managed Compute + GA GPU Pools; Platform-Scoped | Infrastructure Orchestration |
| Layer 2B · Runtime | ● Cortex Runtime: Any-Model Serving + GA Agents + ML Serving | Application Runtime & Execution |
| Layer 2C · Reasoning | ◑ Deep Agent Identity, No Gateway, No Native Orchestration | Agentic Infrastructure — The Reasoning Plane |
| Layer 3 (+1) · Applications | ● First-Party Agents, Observability, and Marketplace | AI Application Layer — The Value Plane |

## DAPM Portability Profile (components)

| Classification | Count | Meaning |
|---|---|---|
| Retained | 2 | I possess the capability and can operate it independently of this provider |
| Delegated | 9 | Someone else provides the capability, but I can substitute that provider without reconstructing my accumulated opinions |
| Ceded | 25 | Changing providers requires reconstructing those opinions |

**Decision authority (per layer, gaps included)**

| Reading | Layers | Meaning |
|---|---|---|
| Retained | 0 | The enterprise, or code it writes or controls, decides |
| Delegated | 4 | Vendor or model decides; the enterprise can see and override |
| Ceded | 4 | Vendor or model decides; no override, often invisible |
| Absent | 0 | Nothing offered, nothing inherited |

## Strongest Layers

- **Layer 1A** (Data Storage & Governance) — Snowflake Strength: Governed Lakehouse Across Three Clouds
- **Layer 1B** (Context Management & Retrieval) — Native Hybrid Retrieval + Governed Semantic Layer
- **Layer 1C** (Data Movement & Pipelines) — Openflow + Streaming + Declarative Pipelines
- **Layer 2B** (Application Runtime & Execution) — Cortex Runtime: Any-Model Serving + GA Agents + ML Serving
- **Layer 3 (+1)** (AI Application Layer — The Value Plane) — First-Party Agents, Observability, and Marketplace

## Gap Areas

- **Layer 0** (Compute & Network Fabric) — Not Snowflake's Layer (By Design)

## Layer-by-Layer Detail

### ○ Layer 0 · Compute: Compute & Network Fabric

*Raw compute, networking, and acceleration fabric*  
**Status:** Not Snowflake's Layer (By Design)

**Decision authority:** Ceded (decides: vendor; visible: false; overridable: false; boundary: vendor)

**Gap Analysis:** Layer 0 is not Snowflake's layer, by design. The buyer never thinks about it, and that is the pitch: Snowflake runs on AWS, Azure, and GCP, and compute arrives as Gen2 Standard Warehouses (GA on all three clouds since November 2025), Adaptive Compute, and Snowpark Container Services compute pools with GPU instance families GA on every cloud. Snowflake owns no silicon, no fabric, and no datacenter. The May 2026 $6B five-year AWS commitment, including Graviton, says where Snowflake's center of gravity sits; it is a procurement fact, not a Layer 0 capability.

The consequence for the 4+1 model is the same as Databricks', Palantir's, and Qlik's: a Snowflake adoption decision resolves no Layer 0 authority question. Whatever capture exists at silicon and fabric belongs to the chosen hyperscaler, a different row on this map. Databricks scored gap here with long-GA classic GPU clusters on the reasoning that they run on the cloud's GPU instances; Snowflake's GPU pools are architecturally identical, rented cloud GPUs behind a proprietary pool abstraction, and score the same way. The real difference between the two rows shows up at 2A, where the pools are scored, not here.

**Borrowed Judgment:** Total at Layer 0, and irrelevant to the value proposition by design. Snowflake inherits all silicon, networking, and acceleration judgment from the host cloud. The enterprise's Layer 0 authority position is set by its hyperscaler choice, and adopting Snowflake does not, by itself, resolve it.

### ● Layer 1A · Storage: Data Storage & Governance

*Durable, governed data foundation — the Governance Catalog that Layer 2C queries*  
**Status:** Snowflake Strength: Governed Lakehouse Across Three Clouds

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**Horizon Catalog (Governance Authority)** [DAPM: Ceded]  
Role-based access control, masking and row-access policies, tag-based policy inheritance, auto-classification, column-level lineage with OpenLineage feeds, data quality monitoring, Trust Center, and agent identity, all evaluated by Snowflake's engine at query time. Policies, tags, the lineage graph, quality monitors, and identity records are proprietary Snowflake objects that do not lift; the methodology's metadata-governance-catalog rule applies verbatim, matching managed Unity Catalog. Reach is narrower than exit: enforcement follows the data to Spark for reads over the REST endpoint, not into Cortex Search and not into Snowflake Postgres. Proprietary Snowflake platform: opinions captive, no open exit.

**Native Tables + Snowflake-Managed Storage (FDN Format, Time Travel, Clone, Hybrid Tables)** [DAPM: Ceded]  
The default table type and the classic estate. A single-vendor micro-partition format in Snowflake-managed storage with no second implementer; Time Travel, zero-copy clone, and Hybrid Tables (Unistore) are properties of that format. Coupled, visible capture: leaving means copying into Iceberg, not repointing. Proprietary Snowflake platform: opinions captive, no open exit.

**Apache Iceberg Tables via Horizon's Polaris-Based Iceberg REST Endpoint** [DAPM: Delegated]  
Snowflake-managed Iceberg tables in the customer's external volume (Iceberg v2 and v3 GA), plus externally managed tables through Glue, Iceberg REST, Unity Catalog, and Amazon S3 Tables catalog integrations (S3 Tables REST integration GA August 10, 2026). External engines read and write Snowflake-managed tables through the Horizon Iceberg REST Catalog API, implemented on Apache Polaris, with vended credentials; both directions GA. The consumed interface is a genuine multi-vendor standard and the bytes sit in the customer's bucket: switching catalogs is a re-registration, not a rebuild. Delegated, matching Databricks Open Lakehouse Storage and Qlik Open Lakehouse. The captive surface is Horizon, not the tables.

**Customer-Operated Apache Polaris as Catalog of Record (Snowflake as Guest Engine via Catalog-Linked Database)** [DAPM: Retained]  
GA. A catalog-linked database attaches Snowflake to an external Iceberg REST catalog (Apache Polaris, AWS Glue, Unity Catalog), polls it for namespaces and tables (default every 30 seconds), and lets Snowflake create namespaces and tables inside it. When the enterprise runs Polaris itself (Apache top-level project since February 2026; Helm charts; open-source RBAC and credential vending; PMC across Dremio, Snowflake, Google, Microsoft, Confluent, and LanceDB), it possesses the catalog and operates it independently of Snowflake, and Snowflake is one of nine substitutable engines. Retained, the first Retained catalog path among the managed data platforms on the instrument. Limits stated: Polaris RBAC is table-level, so row and column policies for other engines don't exist here; masking policies and tags on catalog-linked tables are Snowflake-side and Ceded; cloning and replication are unsupported. Availability, not occupancy: most Snowflake customers will run Horizon and land in the two shapes above.

**Snowflake Postgres (Managed PostgreSQL 16 to 18 on a Dedicated VM)** [DAPM: Delegated]  
GA February 24, 2026, on AWS (18 regions) and Azure (14 regions); no GCP. Each instance is a dedicated Snowflake-managed VM with PgBouncer, reachable by standard Postgres clients and tooling. The consumed interface is standard PostgreSQL, so database opinions lift to any Postgres, matching Databricks Lakebase Delegated. Authorization inside the instance is Postgres-native: the docs state Postgres roles 'are separate from Snowflake roles,' the managed snowflake_admin role can bypass Postgres row-level security, and no Horizon masking, row-access, or tag policy is documented as applying inside the instance. Data reaches Snowflake by copy (Data Mirroring, Postgres to Snowflake only; pg_lake to Iceberg or stages), so Snowflake policies govern the copy, not the source.

**Gap Analysis:** This is Snowflake's center of gravity and the reason it gets bought. One governed data foundation across three clouds: native tables with Time Travel, zero-copy clone, and Hybrid Tables for transactional rows; Apache Iceberg tables in the customer's own bucket, with Iceberg v3 GA at Summit 2026; Horizon Catalog doing the governance work at query time (role-based access control, masking and row-access policies, tag-based policy inheritance, auto-classification, column-level lineage including OpenLineage feeds, data quality monitoring, Trust Center); a Polaris-based Iceberg REST endpoint so Spark, Trino, Dremio, DuckDB, Flink, and four other engines read and write the same tables; and Snowflake Postgres, GA February 24, 2026, for the operational side. Agent identity is GA under Horizon as of Summit. It feels like the most open Snowflake has ever been, and it is.

Two capture generations live side by side, and the buyer usually only sees one. The classic estate is coupled and visible: native tables sit in Snowflake's proprietary micro-partition format in Snowflake-managed storage, readable by nothing else. Getting out means a copy into Iceberg, not a repoint. The new estate is decoupled and invisible, the Databricks shape exactly: Iceberg bytes are genuinely yours, but the governance that makes them usable is Horizon. Masking policies, row-access policies, tags, grants, lineage, and quality rules are Snowflake SQL objects that lift to nowhere. Data portability is the decoy here, and the default table type is still the coupled one.

The reach of the governance is narrower than it reads, and the docs state each boundary. Over the Horizon REST endpoint, masking and row-access policies are enforced for Apache Spark reads only, and writes to protected tables are unsupported. Inside Snowflake Postgres, authorization is Postgres-native: the roles page says Postgres roles 'are separate from Snowflake roles,' the instance ships a snowflake_admin role that can bypass Postgres row-level security, and no Horizon policy applies inside the instance; data crosses to Snowflake by copy (Data Mirroring one way at roughly 30-second latency, or the pg_lake extension to Iceberg or stages). Inside a Cortex Search service, source-table policies do not fire at all (scored and quoted at 1B). Assembled controls therefore reach one adjacent engine, read-only, on Snowflake's own paper. The tuples travel; the rules and the enforcement point don't.

The Polaris question decides the row's most distinctive chip, and it falls into three shapes. First, a customer-operated Apache Polaris as catalog of record, with Snowflake attached as a guest engine through a catalog-linked database (GA, read and write, automatic table discovery): the enterprise possesses the catalog and operates it independently of Snowflake, and Snowflake is one of nine substitutable engines. Retained. This is a real GA deployment shape, not a thought experiment, and it exists because Polaris graduated to an Apache top-level project in February 2026 with a PMC across Dremio, Snowflake, Google, Microsoft, Confluent, and LanceDB, ships Helm charts, and carries RBAC and credential vending in the open-source build where open-source Unity Catalog does not. Second, Snowflake-managed Iceberg tables exposed through Horizon's Polaris-based REST endpoint: someone else provides the catalog, and switching is a re-registration into another Iceberg REST catalog, not a reconstruction. Delegated. Third, Horizon's grants, masking, tags, and lineage over those same tables: changing providers means rewriting every policy. Ceded. Founding the project is irrelevant to the chip; independence from the provider and substitutability are what count. Snowflake Open Catalog, the standalone managed Polaris, is now positioned as legacy (the docs tell new customers to use Horizon) and is not scored.

Calibration: Databricks 1A is strong on the same test (governance is an authorization authority at query time, not curation metadata), Palantir strong, Qlik moderate because its governance stops at trust scoring and delegates access to IAM. Snowflake clears the Databricks bar and is more open on catalog interop. Frontier-pegged, Snowflake and Databricks define this frontier together.

**Borrowed Judgment:** Low for the governance logic: Horizon, the policy engine, lineage, and agent identity are Snowflake IP, Ceded to Snowflake, and the native table format is the coupled half of the estate. The Iceberg layer is Delegated (open standard, bytes in the customer's bucket), and a customer-run Polaris of record is the one Retained shape, with Snowflake as a substitutable engine. The capture is decoupled for the new estate and coupled for the old one, on the same paper.

### ● Layer 1B · Retrieval: Context Management & Retrieval

*Low-latency retrieval for RAG — vector/hybrid search, context windows*  
**Status:** Native Hybrid Retrieval + Governed Semantic Layer

**Decision authority:** Ceded (decides: vendor; visible: true; overridable: false; boundary: vendor)

**Cortex Search (Managed Hybrid Retrieval Service)** [DAPM: Ceded]  
GA. Vector plus keyword retrieval with semantic reranking over Snowflake tables; SQL, Python, and REST access; Batch Cortex Search GA May 18, 2026. The index, service spec, reranker, and API are proprietary and do not lift, matching Mosaic AI Vector Search. Runs with owner's rights: source-table row-access and masking policies do not apply to results, and per-user scope is an application-supplied filter. Proprietary Snowflake platform: opinions captive, no open exit.

**Arctic Embed Models (Apache 2.0 Open Weights)** [DAPM: Delegated]  
snowflake-arctic-embed-m-v1.5, -l-v2.0, and -l-v2.0-8k are Apache 2.0 open weights on Hugging Face. The instrument's embedding carve-out scores embeddings Ceded because no second vendor serves the same space; here the enterprise can serve the identical model itself, so vectors computed in Snowflake stay valid outside it without recomputation. The open-source seam makes that a portability fact. Delegated. Vectors sitting inside a Cortex Search index are captive with the service, which the first component already says.

**Voyage Embeddings via Cortex (voyage-multilingual-2)** [DAPM: Ceded]  
A proprietary Voyage AI model served through Cortex. Voyage serving its own model directly is a second channel for one proprietary space, not a second implementer, so the channel-substitution rule applies: Ceded to Voyage through Snowflake's paper, exactly as ONTAP through Lenovo scores Ceded to NetApp. The embedding carve-out holds here.

**Semantic Views + Cortex Analyst (Governed Structured Context, Text-to-SQL)** [DAPM: Ceded]  
GA. Semantic views are schema-level objects (tables, relationships, metrics, synonyms, derived measures) under RBAC and sharing; Cortex Analyst generates SQL against them, with the legacy YAML semantic model still supported. Definitions are Snowflake DDL with no second implementer: portable as a concept, not as an artifact. Cortex Analyst is transitioning into Cortex Agents (August 28, 2026 guidance). Proprietary Snowflake platform: opinions captive, no open exit.

**VECTOR Type + Similarity Functions (SQL-Native Retrieval)** [DAPM: Ceded]  
GA. Vector columns and VECTOR_COSINE_SIMILARITY and related functions for do-it-yourself retrieval in plain SQL. Vectors export as arrays and the queries rebuild on any vector-capable database, so this is Ceded with a low blast radius. Proprietary Snowflake platform: opinions captive, no open exit.

**Gap Analysis:** Retrieval-augmented generation (RAG) without a separate vector database, and structured context without a separate semantic layer. Cortex Search (GA) is hybrid retrieval: vector plus keyword plus semantic reranking over Snowflake tables, consumed through SQL, Python, or REST, with Batch Cortex Search GA May 18, 2026. Embedding choice is Snowflake's open-weight Arctic models or Voyage, or bring precomputed vectors from any model into a multi-index service. The VECTOR type and similarity functions cover the do-it-yourself path in plain SQL. On the structured side, semantic views (GA) are schema-level objects carrying tables, relationships, metrics, and business terms under RBAC, and Cortex Analyst turns them into governed text-to-SQL. Cortex Knowledge Extensions bring third-party content from the Marketplace into the same retrieval path. Nothing to stand up.

The decoupled split repeats one layer up. Source tables may be open Iceberg, but the Cortex Search index, service definition, reranker, and retrieval API are proprietary; leaving means rebuilding retrieval on pgvector or Weaviate. Semantic views are Snowflake DDL with no second implementer; every metric definition and synonym list rebuilds elsewhere. And the permission story is narrower than the marketing reads, in the docs' own words: Cortex Search services 'perform searches with owner's rights,' any role with USAGE 'may query any of the data the service has indexed, regardless of that role's privileges on the underlying objects,' and for a source table with row-level policies 'querying users will be able to see search results from rows on which the owner's role has read permission, even if the querying user's role cannot read those rows.' Per-user scope is the application's job through filters. An architect who assumed Horizon's policies follow the data into retrieval would be wrong, and the docs tell you to use caution granting USAGE for exactly that reason.

Calibration: Databricks 1B is strong on GA native vector search, hybrid retrieval, managed or BYO embeddings, and a retrieval API the enterprise builds on. Snowflake matches every leg and adds a GA semantic-view layer Databricks has no scored equivalent for at 1B. Qlik is moderate because retrieval is a closed product feature with no API or model choice; Snowflake is the opposite case. The owner's-rights finding narrows the permission-aware claim but does not move the grade, because the frontier test is retrieval infrastructure the enterprise builds on, and it clears.

**Borrowed Judgment:** Low for the retrieval mechanism: Cortex Search, the reranker, and semantic views are Snowflake IP, Ceded to Snowflake. The embedding space splits: Arctic embed is Apache 2.0 open weights, so vectors computed here remain valid outside and that chip reads Delegated on the open-source seam; Voyage through Cortex is a proprietary model on Snowflake's paper and reads Ceded to Voyage under the channel-substitution rule. Cortex Analyst puts a model in the loop choosing the SQL, gated by Horizon RBAC; the reading holds the peer convention (vendor decides, visible, not overridable) rather than splitting the cell.

### ● Layer 1C · Pipelines: Data Movement & Pipelines

*Move/transform data — ETL/ELT, lineage, cost-aware movement, KV cache tiering*  
**Status:** Openflow + Streaming + Declarative Pipelines

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**Openflow Runtime (Apache NiFi 2.x Flows, JSON Export, Standard Processors)** [DAPM: Delegated]  
GA on AWS, Azure, and GCP as a Snowflake deployment on Snowpark Container Services; BYOC GA on AWS only. Flow definitions and process groups export as JSON and are version-controllable; standard NiFi processors and controller services run on open-source NiFi. The engine is open source with real alternatives and flows lift to self-run NiFi, matching Databricks' Spark Delegated. Gen 2 (SQL-first management) is public preview.

**Openflow Connectors (Snowflake-Curated, Proprietary NiFi Components)** [DAPM: Ceded]  
GA, 25-plus connectors: SaaS (Salesforce, HubSpot, Workday, Veeva), databases with CDC (SQL Server GA August 5, 2026; MySQL, PostgreSQL, Oracle, MongoDB), streaming (Kafka, Kinesis), storage and collaboration (Box, Google Drive, SharePoint). Curated, versioned flow definitions built with open-source and proprietary NiFi components; the proprietary ones don't run outside Openflow, matching Lakeflow Connect Ceded. Proprietary Snowflake platform: opinions captive, no open exit.

**Snowpipe + Snowpipe Streaming (High-Performance Architecture)** [DAPM: Ceded]  
GA. Serverless batch and streaming ingestion; the high-performance architecture reaches 10 GB/s per table with roughly five-second latency, flat ingestion pricing, and writes to native, Iceberg, or Interactive tables. Proprietary ingest API and SDK. Low blast radius when the destination is Iceberg, since the landed data is open. Proprietary Snowflake platform: opinions captive, no open exit.

**Dynamic Tables + Streams and Tasks (Declarative Transformation and Orchestration)** [DAPM: Ceded]  
GA, with faster refresh GA and custom incrementalization and adaptive refresh in public preview. Declarative pipelines as Snowflake SQL objects with lineage in Horizon; definitions do not lift, matching Lakeflow Declarative Pipelines Ceded. Proprietary Snowflake platform: opinions captive, no open exit.

**dbt Projects on Snowflake (dbt Core Apache 2.0; dbt Fusion)** [DAPM: Delegated]  
GA November 2025; dbt Fusion GA in-platform; DBT_VERSION pinning; DAG with column-level lineage from Horizon. dbt Core is Apache 2.0 and the Fusion runtime moved into dbt Core v2 under Apache 2.0; projects run on any dbt adapter. Snowflake hosting is the convenience layer. Delegated.

**AI Functions in Pipelines (AI_PARSE_DOCUMENT, AI_EXTRACT, AI_CLASSIFY, Document AI)** [DAPM: Ceded]  
GA. Unstructured-to-structured processing as SQL pipeline stages over Snowflake-served models (Arctic-TILT for Document AI). Snowflake SQL surface; calls rebuild elsewhere. Proprietary Snowflake platform: opinions captive, no open exit.

**Gap Analysis:** The full pipeline estate is GA and mostly serverless. Openflow, the Apache NiFi engine Snowflake acquired with Datavolo, runs Snowflake-managed on all three clouds or bring-your-own-cloud on AWS, with 25-plus curated connectors spanning SaaS, databases with change data capture (SQL Server CDC GA August 5, 2026), streaming, cloud storage, and unstructured sources. Snowpipe Streaming's high-performance architecture ingests at up to 10 GB/s per table with roughly five-second latency, landing in native or Iceberg tables. Dynamic Tables are declarative transformation with GA faster refresh. dbt Projects on Snowflake (GA November 2025) run dbt Core and dbt Fusion in-platform with column-level lineage in the DAG. AI functions in SQL (AI_PARSE_DOCUMENT, AI_EXTRACT, AI_CLASSIFY) make unstructured processing a pipeline stage. Lineage threads through Horizon. Nothing to operate.

Same decoupled split as Databricks: the open engine ports, the value-bearing opinions don't. Openflow flow definitions export as NiFi JSON and standard NiFi processors run on open-source NiFi, but Snowflake's curated connectors are built with proprietary NiFi components that won't. Snowpipe Streaming's ingest API, Dynamic Table definitions, Streams, and Tasks are Snowflake objects that rebuild elsewhere. Openflow is also young: GA May 2025 on AWS, multi-cloud later, Gen 2 still in public preview. What an enterprise accumulates here is hundreds of flows, ingest clients, and dynamic-table DAGs, and only the dbt projects and raw NiFi flows leave intact. Iceberg plus catalog-linked databases make movement avoidance a real option (query in place across catalogs rather than copy), which is the cost-aware half of the layer stated as an architecture rather than a feature.

Calibration: Databricks 1C is strong (Lakeflow, the most mature data-engineering layer on the instrument), Qlik strong (CDC breadth), VAST strong (DataEngine), Palantir and Dell moderate. Rule 4's general test passes: NiFi flows take arbitrary processors, insertable stages, and any destination; the day-two requirement runs here rather than beside it. Rule 5's maturity gate attaches to Openflow, not to the layer, because Snowpipe, Dynamic Tables, Tasks, and dbt are mature. Frontier-pegged against Lakeflow, this stands.

**Borrowed Judgment:** Low: Openflow's connectors, Snowpipe, Dynamic Tables, Tasks, and the AI functions are Snowflake IP, Ceded to Snowflake. Apache NiFi and dbt are the open substrates (Delegated); the enterprise inherits Snowflake's packaging and runtime around them. Decoupled pattern: open engines underneath, captive pipeline opinions on top. Decision authority reads vendor / Delegated under the override rule (ratified September 4, 2026): the Dynamic Tables engine chooses refresh strategy and incrementalization inside definitions the enterprise wrote, and TARGET_LAG and REFRESH_MODE are per-object overrides the engine must honor; Openflow runs the enterprise's flows verbatim. Portability stays Ceded on the value-bearing objects.

### ◑ Layer 2A · Orchestration: Infrastructure Orchestration

*GPU scheduling, quotas, RBAC, fair-share scheduling, utilization optimization*  
**Status:** Managed Compute + GA GPU Pools; Platform-Scoped

**Decision authority:** Ceded (decides: vendor; visible: n/a; overridable: false; boundary: vendor)

**Virtual Warehouses + Adaptive Compute (Query Compute, Multi-Cluster, Resource Monitors, Budgets)** [DAPM: Ceded]  
Gen2 Standard Warehouses GA on all three clouds; Adaptive Compute GA (Enterprise Edition, select regions on AWS, Azure, GCP) with Snowflake choosing size, cluster count, routing, and acceleration under a customer-set ceiling and credit limits. Proprietary sizing and routing opinions; warehouse configs and cost policies rebuild elsewhere. Proprietary Snowflake platform: opinions captive, no open exit.

**Snowpark Container Services Compute Pools (CPU and GPU Node Pools, Autoscaling, Job Services)** [DAPM: Ceded]  
GA on AWS, Azure, and GCP. CREATE COMPUTE POOL with instance family and min/max nodes; GPU families on every cloud; services and job services scheduled by memory and GPU count onto single nodes; pools shared across services; auto-suspend. The consumed interface is Snowflake DDL and a Snowflake-specific spec, not a multi-vendor standard, so the pool, spec, and scheduling opinions don't port even though the OCI image does. Matches Databricks Compute and Palantir Rubix. Managed Kubernetes earns Delegated only where the Kubernetes API is the consumed interface, and it isn't here. Proprietary Snowflake platform: opinions captive, no open exit.

**DCM Projects (Declarative Infrastructure-as-Code for Snowflake Objects)** [DAPM: Ceded]  
GA August 7, 2026. DEFINE statements in SQL files describe the desired state of databases, tables, dynamic tables, tasks, and data quality expectations; Snowflake plans and applies the changes, with version-controlled deployments across environments from a Workspace, a Git repository, or a local directory, managed through Snowsight, the CLI, SQL, or CoCo. The definitions target Snowflake objects only, so the deployment opinions do not lift, matching Databricks Asset Bundles Ceded. Proprietary Snowflake platform: opinions captive, no open exit.

**Serverless Managed Compute (Snowpipe, Dynamic Tables, Cortex, Openflow-on-SPCS Capacity)** [DAPM: Ceded]  
Invisible capacity Snowflake schedules for its own serverless features; the customer sees a bill. No configuration surface, no lift. Proprietary Snowflake platform: opinions captive, no open exit.

**Gap Analysis:** Nothing to operate, on three clouds. Virtual warehouses scale per workload, and Adaptive Compute (GA, Enterprise Edition, select regions on AWS, Azure, and GCP) removes even the sizing decision: Snowflake picks warehouse size, cluster count, query routing, and acceleration, while the customer sets a performance ceiling (MAX_QUERY_PERFORMANCE_LEVEL), a throughput multiplier, and credit limits through Budgets and resource monitors. Snowpark Container Services compute pools are the AI half: GPU node pools on all three clouds with min/max autoscaling, auto-suspend, multiple services sharing a pool, and job services for finite workloads. Snowflake ML distributed training and batch inference run multi-node on those pools. DCM Projects (GA August 7, 2026) codify Snowflake objects as declarative, Git-backed definitions with a plan-then-deploy workflow, the Asset Bundles equivalent. Serverless features (Snowpipe, Dynamic Tables, Cortex) run on capacity the customer never sees. This is where the GPU catalog deferred from Layer 0 actually lands: vendor-account GPU pools, GA on three clouds, the only data platform on the instrument that ships that.

All of it is proprietary orchestration on rented hyperscaler VMs. The consumed interface for compute pools is Snowflake SQL DDL plus a Snowflake-specific service spec, not the Kubernetes API; the OCI image is the only artifact that lifts. Scheduling inside a pool is node-level bin-packing by memory and GPU count: a service instance never spans nodes, and the docs describe no queueing, priority, preemption, fair-share, or fractional GPU. Quotas are credit caps and pool node ceilings, not scheduler policy. Adaptive Compute is Snowflake exercising sizing judgment against the customer's bill, with a ceiling as the only override. And there is no path to non-Snowflake infrastructure: the pools orchestrate Snowflake-hosted containers, nothing else.

Calibration, pegged against the whole 2A column. Every strong carries at least one of three things: a multi-vendor standard scheduling interface (Kubernetes on GKE, EKS, AKS, OpenShift, VKS, NKP), a real scheduler policy surface (Run:ai fractional and fair-share, CoreWeave preemption and topology-aware placement, Supermicro GPU slicing), or whole-estate scope (VMware, Nutanix, HPE). Snowflake has none of the three. The sharper test is the moderate cohort: OCI is moderate with managed Kubernetes, MIG, and Karpenter; Lenovo is moderate with fair-share across tenants. A proprietary pool with less than either cannot read strong. Databricks is moderate on the same shape: its customer-VPC GPU clusters are GA and its vendor-account serverless GPU is preview, where Snowflake's vendor-account pools are GA on three clouds. Both are proprietary pool orchestration on rented instances; Snowflake sits at the strong end of the same cohort. A GA fair-share or fractional-GPU surface on compute pools, or a Kubernetes API exposure, is what would re-open the grade.

**Borrowed Judgment:** Moderate. The orchestration opinions (warehouse sizing, Adaptive Compute routing, pool scheduling, autoscaling) are Snowflake's and Ceded; the capacity underneath is the hyperscaler's. The enterprise inherits both without a policy surface, and in the Adaptive Compute case Snowflake's sizing judgment is exercised directly against the customer's credit spend with a ceiling as the only override.

### ● Layer 2B · Runtime: Application Runtime & Execution

*Model serving, agent execution, inference APIs, distributed inference*  
**Status:** Cortex Runtime: Any-Model Serving + GA Agents + ML Serving

**Decision authority:** Delegated (decides: model; visible: true; overridable: true; boundary: model)

**Cortex Model Access via the OpenAI-Compatible Chat Completions Endpoint** [DAPM: Delegated]  
GA. POST /api/v2/cortex/v1/chat/completions follows the OpenAI Chat Completions specification (tool calling, structured output, image input, prompt caching, reasoning) and works with the OpenAI SDK against a Snowflake token; models from Anthropic, OpenAI, Google, Meta, Mistral, DeepSeek, AI21, and Snowflake, with cross-region inference. A managed service behind a genuine multi-vendor standard interface: integration opinions lift to any compatible provider, matching Mosaic AI Model Serving and Vertex's OpenAI endpoint. Delegated.

**Customer-Created Tools (Stored Procedures, UDFs, Customer-Hosted MCP Servers, Permission Policy)** [DAPM: Retained]  
GA. The enterprise owns the code the model invokes and the approval gate in front of it: custom tools are stored procedures and user-defined functions the customer writes in Python, Java, or Scala through Snowpark, remote MCP servers the customer hosts, and a per-tool permission_policy ('always_ask' by default for state-modifying tools). This is the seam where control passes from instructing the model to executing code outside it, and the opinions are the enterprise's: the tool logic is the customer's and ports to any runtime, while the CREATE PROCEDURE wrapper, the Snowpark session, and the policy mechanism are Snowflake's and rebuild as a residual cost of the managed-Kubernetes class. The host is Snowflake's and is already Ceded under the Cortex Agents component; responsibility is carried by the 2B authority reading. Retained, matching Databricks and GCP customer-created tools, where 'outside' means outside the model, not outside the platform. The exception is a tool written in Snowflake Scripting SQL, whose procedural dialect is the Oracle stored-procedure case and would read Ceded.

**Cortex Agents (Agent Definitions, Orchestration Loop, Sandbox, Evaluations, Guardrails, Threads)** [DAPM: Ceded]  
GA. Plan, tool, reflect loop over Cortex Analyst, Cortex Search, custom tools, MCP connectors, sandboxed code execution, web search, and skills; per-agent model choice or 'auto'; async API GA August 30, 2026; Coding Agent GA August 26; evaluations GA March 13; Cortex AI Guardrails (prompt-injection and jailbreak protection) GA May 14. Agents are schema objects; definitions, tool wiring, threads, and guardrail configs do not lift, matching Mosaic AI Agent Framework. Proprietary Snowflake platform: opinions captive, no open exit.

**Snowflake ML Model Registry + Model Serving on SPCS (Distributed Training, Batch Inference)** [DAPM: Ceded]  
GA (snowflake-ml-python 1.25.0 and later) on AWS and Azure. Models logged to the registry deploy as services on compute pools with CPU or GPU, behind a Snowflake-proprietary REST inference API (dataframe_split payloads, PAT auth), with built-in horizontal scaling; distributed trainers for XGBoost, LightGBM, and PyTorch across nodes and GPUs; job-based batch inference. Registry and serving opinions are Snowflake objects and the inference API is single-vendor. Proprietary Snowflake platform: opinions captive, no open exit.

**Cortex Fine-Tuning (LoRA Adapters on Llama and Mistral)** [DAPM: Ceded]  
GA since February 2025 in four regions. FINETUNE creates, shows, describes, and cancels serverless fine-tuning jobs producing parameter-efficient adapters on a short list of base models; fine-tuned models are called through Cortex. No documented adapter export. Matches Mosaic AI Model Training Ceded. Proprietary Snowflake platform: opinions captive, no open exit.

**Customer Containers on SPCS (vLLM, TGI, Ray on GPU Pools)** [DAPM: Delegated]  
GA. Any OCI image on a compute pool, including open-source serving stacks the enterprise packages itself. The container and its configuration lift to any GPU host; the pool underneath is Snowflake's and already Ceded at 2A. Delegated, matching GCP's open frameworks on TPU.

**Snowflake-Managed MCP Servers (Snowflake as a Tool Inside External Agent Runtimes)** [DAPM: Ceded]  
GA, including in Native Apps (August 7, 2026). Expose Cortex Search services, semantic views, procedures, and UDFs as MCP tools to Claude Code, Cursor, Copilot, Bedrock, Azure AI Foundry, and custom agents, under agent identity. MCP is a standard interface, but every tool behind it is a Snowflake object, matching the VMware and HPE MCP-server components. Proprietary Snowflake platform: opinions captive, no open exit.

**Gap Analysis:** A complete, GA runtime for both halves of the layer. Model access: Claude, GPT-5.2, Gemini, Llama, Mistral, DeepSeek, AI21, and Arctic through SQL functions, and through a Cortex REST endpoint that follows the OpenAI Chat Completions specification with tool calling, structured output, image input, prompt caching, and reasoning, with cross-region inference. Agent execution: Cortex Agents (GA) is a customer-built agent platform with a plan, tool, reflect loop; tools spanning Cortex Analyst, Cortex Search, customer stored procedures and user-defined functions, remote Model Context Protocol (MCP) servers, a sandboxed code-execution tool, web search, and agent skills; model choice per agent or 'auto'; asynchronous API (GA August 30, 2026); Coding Agent (GA August 26); evaluations (GA March 13); Cortex AI Guardrails (GA May 14). Classical and custom ML: Model Registry with Model Serving on Snowpark Container Services compute pools (CPU and GPU), distributed training for XGBoost, LightGBM, and PyTorch across nodes, batch inference jobs. Custom serving: any OCI container, so vLLM on a GPU pool is a supported shape. Snowflake-managed MCP servers expose Search services, semantic views, and procedures to Claude Code, Cursor, Copilot, and custom agents. Nothing to stand up.

Open models, captive runtime, the Databricks pattern exactly. Model choice is genuinely open and the completions interface is a standard, but the agent definitions, tool wiring, threads, evaluations, and guardrail configs are Snowflake objects. An agent built here rebuilds elsewhere. Model Serving's REST interface is Snowflake's own, not OpenAI-compatible, so serving integrations don't lift the way completions integrations do. Guardrails are Llama-Guard-class model controls: they shift the distribution, they don't pin it. The runtime's determinism boundary is the tool: the model plans, the customer's stored procedure executes, and the permission policy sits between them. By default, tools that modify state require user approval ('always_ask'), and the enterprise can persist that or set 'always_allow'; the latter is the enterprise choosing to cede at runtime. As reported by third parties in March 2026, a poisoned README talked the coding agent past its confirmation flow within days of GA; that is the 'can't prompt your way to deterministic output' finding in the wild, recorded here as reported rather than as a Snowflake-confirmed fact.

Calibration: Databricks 2B is strong on GA any-model serving behind OpenAI-compatible endpoints, a GA agent framework, and managed training. Snowflake matches each leg with GA product, adds a sandboxed code-execution tool and remote MCP as first-class agent tools, and carries its scope gates named: Cortex Training in preview, Cortex Fine-tuning GA but region-limited, Model Serving GA on AWS and Azure with GCP unconfirmed. Palantir and the hyperscalers are the strong peers. Qlik is moderate because it has no serving and no constructible agents; Snowflake has both.

**Borrowed Judgment:** Low for the runtime, which is Snowflake's own (Cortex Agents, Model Registry and Serving, Fine-tuning, the MCP servers are Ceded to Snowflake), and Delegated at the model interface, where the enterprise chooses among Anthropic, OpenAI, Google, and open-weight models behind a standard completions API. The model decides which tool to call; the enterprise's own procedures and the persisted permission policy are the deterministic gate before the effect. Unlike the on-prem peers, the runtime is Snowflake's, not NVIDIA's, and it is GA.

### ◑ Layer 2C · Reasoning: Agentic Infrastructure — The Reasoning Plane

*Policy-driven placement and resource coordination — the Autonomy Layer*  
**Status:** Deep Agent Identity, No Gateway, No Native Orchestration

**Decision authority:** Delegated (decides: vendor; visible: true; overridable: true; boundary: vendor)

**Agent Identity (Delegated and Autonomous Agents, SERVICE_AGENT, Agent Audit Columns)** [DAPM: Ceded]  
GA (Summit, June 2, 2026). Delegated agents run within the invoking user's session and privileges; autonomous agents authenticate as a SERVICE_AGENT user via workload identity federation, key-pair, or programmatic access token; external agents through custom OAuth with IS_AGENTIC = TRUE. QUERY_HISTORY.agent_type and ACCESS_HISTORY.agents_info record which agent, and which chain of agents, touched each object. Records the relationship; does not yet constrain on it (session scoping is preview). Snowflake's user and audit model. Proprietary Snowflake platform: opinions captive, no open exit.

**Agent Objects Under Horizon RBAC (Registry Leg, Including Native Apps Agents and MCP Servers)** [DAPM: Ceded]  
GA. CREATE AGENT produces a schema-level governed object with grants; Native Apps can ship Cortex Agents and Snowflake-managed MCP servers (GA August 7, 2026). The registry is Horizon's object model, matching Unity Catalog agent governance Ceded. Proprietary Snowflake platform: opinions captive, no open exit.

**AI Observability + Cortex Agent Evaluations (TruLens Instrumentation, Event-Table Storage, External-App Support)** [DAPM: Delegated]  
GA (evaluations GA March 13, 2026). Traces and evaluates Agents, CoWork, CoCo, Analyst, Search, AI functions, and custom apps on Snowflake or other infrastructure, stored in SNOWFLAKE.LOCAL.AI_OBSERVABILITY_EVENTS; answer-correctness, logical-consistency, and custom LLM-scored metrics. TruLens is open source (Snowflake-owned), so the instrumentation and feedback functions lift and external apps already stream to it; the event table and evaluation UI are the captive add-on. Delegated, matching MLflow 3 tracing on Databricks.

**Trust Center: AI Security Posture Management + Strict Data-Movement Policies** [DAPM: Ceded]  
GA July 28, 2026. Continuous detection of misconfigured agent roles, unprotected columns, and exfiltration paths, with AI-guided investigation. State-legality and posture, not outcome validation. Proprietary Snowflake platform: opinions captive, no open exit.

**Gap Analysis:** Snowflake governs agents with the same objects it governs data. Agent identity (GA) is the deepest identity leg on the instrument: delegated agents run inside the invoking user's session and privileges; autonomous agents get their own SERVICE_AGENT user with workload identity federation, key-pair, or token auth; external agents entering through custom OAuth are flagged agentic; QUERY_HISTORY carries an agent_type column and ACCESS_HISTORY carries the ordered chain of agents behind every object access. Agents are schema-level objects under Horizon RBAC, and Native Apps can ship agents and MCP servers (GA August 7, 2026). AI Observability traces Agents, CoWork, CoCo, Analyst, Search, and AI functions into a Snowflake event table, and through TruLens it traces custom apps running on-prem or on other clouds. Cortex Agent evaluations (GA March 13, 2026) add answer-correctness, logical-consistency, and custom metrics. Trust Center's AI Security Posture Management and strict data-movement policies (GA July 28, 2026) watch for misconfigured agents and exfiltration paths. Agent data lineage landed September 2, 2026. The buyer gets identity, audit, and evaluation without a separate agent-governance product.

Two legs are missing, and they're the ones that make a plane a plane. The request-time gateway, Cortex AI Gateway, was announced July 28, 2026 as 'public preview soon,' with its Tools and Access Governance components in private preview. Until it ships there is no single point that grants, restricts, rate-limits, and audits model and tool access across first-party and third-party agents; Natoma's technology (acquired May 2026) is the intended basis, and 'Natoma integration GA' in the press release describes the acquisition closing, not a purchasable gateway. Cross-agent orchestration is a pattern the customer builds: a master agent calling sub-agents through Python UDF wrappers over HTTP, with Snowflake's own guide saying the approach 'may evolve as Snowflake adds native support for multi-agent workflows.' The reasoning tests come back the usual way. 'Auto' model selection is the closest thing to Infrastructure-2C, and it is single-variable routing chosen by the vendor, invisible, overridable only by pinning a model; cross-region inference is a static parameter. Routing is not reasoning. The evaluation metrics are LLM-judge scoring: assessment by a model, not deterministic validation of outcome. And the identity leg's depth stops at recording: delegated agents inherit the full grant set of the user they act for, the agent chain is written to ACCESS_HISTORY but not evaluated against, and the surfaces that would let an agent hold less than its user (Restricted Session Scope 'GA soon,' Agent Session Scoping and Context-Aware Controls in private preview) are not GA. Observe by Snowflake watches infrastructure logs, metrics, and traces with an AI SRE; it is not documented as the agent-observability surface and is scored at Layer 3.

Calibration: the September 2 criterion says strong needs either a reasoning mechanism or all five legs GA (identity, request-time gateway, registry, cross-agent orchestration, observability). Snowflake has three. Databricks is moderate, Salesforce, VMware, and Nutanix are moderate with their missing legs named, and the AWS, IBM, OCI, Cisco, HPE cohort is moderate on multi-component governance without placement. Snowflake belongs there, above the Qlik and Dell gap cohort because identity, registry, and observability are productized and GA rather than inherited plumbing. Cortex AI Gateway GA and native multi-agent workflows GA would move it; both are dated watch items.

**Borrowed Judgment:** Low for what is provided: agent identity, the agent registry, and posture management are Snowflake IP, Ceded to Snowflake; observability rides an open-source instrumentation layer (TruLens) and is Delegated. This is low borrowed judgment for partial 2C. Intelligence-2C is three legs GA; the gateway and orchestration legs are gaps, not borrowed. The live per-inference placement gap and the deterministic outcome-validator gap are universal across the instrument, noted rather than penalized.

### ● Layer 3 (+1) · Applications: AI Application Layer — The Value Plane

*AI-powered business capabilities — business logic, workflow automation*  
**Status:** First-Party Agents, Observability, and Marketplace

**Decision authority:** Ceded (decides: vendor; visible: n/a; overridable: false; boundary: vendor)

**Snowflake CoWork (Personal Agent: Skills, MCP Connectors, Deep Research, Artifacts, Mobile)** [DAPM: Ceded]  
GA November 4, 2025 as Snowflake Intelligence; renamed CoWork and expanded with skills, MCP connectors, Deep Research, mobile, and artifacts at Summit June 2, 2026. A conversational agent over governed data and connected systems, built on Cortex Agents. Agents, skills, artifacts, and automations (preview) are Snowflake objects. Proprietary Snowflake platform: opinions captive, no open exit.

**Snowflake CoCo (Coding Agent: Desktop, CLI, VS Code, Snowsight, Agent SDK)** [DAPM: Ceded]  
GA. The renamed Cortex Code: desktop app, CLI, VS Code extension (GA August 27, 2026), and in-Snowsight (GA March 9), with a local sandbox and an Agent SDK. Sessions, skills, and automations are account-bound. Proprietary Snowflake platform: opinions captive, no open exit.

**Observe by Snowflake (Observability Application + AI SRE)** [DAPM: Ceded]  
Shipping product, acquired January to February 2026. Logs, metrics, and traces with an Observability Context Graph and an AI SRE that traverses dependencies to isolate root cause; UI, CLI (coming soon), and MCP access. Proprietary graph and agent; Iceberg write path not GA. Blast radius drops when it is. Proprietary Snowflake platform: opinions captive, no open exit.

**Streamlit in Snowflake + Native Apps Framework (App Hosting)** [DAPM: Ceded]  
GA. Streamlit apps and Native Apps hosted against governed data with Snowflake session and RBAC integration. Streamlit is Apache 2.0 and the code is portable; the hosting, session model, and governance integration are captive, matching Databricks Apps. Proprietary Snowflake platform: opinions captive, no open exit.

**Snowflake Marketplace (Data, Native Apps, Agentic Products, Cortex Knowledge Extensions)** [DAPM: Delegated]  
GA. Datasets, Native Apps, agentic Native Apps, and Cortex Knowledge Extensions from substitutable third-party providers; partners reported more than $100M in first-half 2026 revenue. Delegated on the AppExchange reading (a substitutable ISV ecosystem). The channel is Secure Data Sharing, a proprietary Snowflake-to-Snowflake protocol, which is the difference from Databricks' open-protocol Marketplace: the providers substitute, the channel does not.

**Gap Analysis:** Snowflake now ships first-party applications, not just the platform underneath them. Snowflake CoWork (GA November 4, 2025 as Snowflake Intelligence; renamed and expanded June 2, 2026) is a personal agent for knowledge workers: skills, MCP connectors into Jira, Salesforce, and other systems, Deep Research, a mobile app, and reusable artifacts, with Snowflake claiming 12,000 customers and 15,000 deployed agents at Summit. Snowflake CoCo (GA, the renamed Cortex Code) is a coding agent for data teams as a desktop app, CLI, VS Code extension (GA August 27), and inside Snowsight (GA March 9), with an Agent SDK. Observe by Snowflake, the roughly $1B acquisition announced January 8, 2026 and closed the following month, is a full observability application over logs, metrics, and traces with an AI SRE that walks a dependency graph to root cause. Streamlit in Snowflake and the Native Apps framework host customer-built apps against governed data. The Marketplace carries datasets, Native Apps, agentic products, and Cortex Knowledge Extensions, with partners reporting more than $100M in first-half 2026 revenue.

The value plane is captive even where the data beneath it is open, which is the row's recurring shape. CoWork agents, skills, automations, and artifacts are Snowflake objects; CoCo sessions and skills are bound to the Snowflake account; Observe's context graph and AI SRE are proprietary, and its Iceberg write path is described as progress rather than GA, so telemetry accumulated there does not yet leave in an open format. Streamlit code is portable (Snowflake owns the Apache 2.0 project), but the Snowflake session, RBAC integration, and hosting are not, the same finding Databricks Apps carries. The Marketplace's substrate is Secure Data Sharing, a Snowflake-to-Snowflake protocol; unlike Delta Sharing there is no open protocol underneath, so the ecosystem is substitutable but the channel is not. The domain boundary Databricks and Qlik carry applies here too: CoWork answers questions and executes workflows over enterprise data; it does not run a supply chain the way Foundry does, though Observe pushes the value plane past analytics into IT operations.

Calibration: Databricks Layer 3 is strong on Genie, AI/BI, Apps, and Marketplace with the analytics-centric caveat; Qlik strong; Palantir strong and broader; Salesforce strong. Snowflake clears the platform-provided line that VMware and Nutanix (moderate) don't, with three GA first-party applications and an app-hosting surface. Not partner: nothing here is ISV-delivered.

**Borrowed Judgment:** The application opinions are Snowflake's, Ceded to Snowflake, and the enterprise's accumulated artifacts (CoWork agents and skills, CoCo automations, Observe's context graph, Streamlit apps bound to the session model) rebuild elsewhere. The Marketplace ecosystem is Delegated (substitutable providers) over a proprietary channel. The generative layer inside these applications inherits the 2B model chain behind a standard interface, and the 2B permission policy is where the model boundary was read; the application layer inherits it rather than restating it.

---
*Layer2C · AI Infrastructure Decision Intelligence · The CTO Advisor LLC (DBA The Advisor Bench) · thectoadvisor.com*
