Dome Systems

Snowflake MCP server and Dome

Let agents search your Snowflake data. Decide which columns they get.

Connect Snowflake's managed MCP server to Dome with Snowflake OAuth. Each call runs with the default role of the person the agent acts for. Rules read every call's arguments, down to the columns a search returns.

AnalystsAgentsDomeSnowflakeCallersAnalystsAgentssupport-assistantAgentsfinance-analystAgentschurn-researcherGatewaysdata-gatewayticket-searchCortex Searchrevenue-analystCortex AnalystModel poolAny providerRulesGuardsAuditsaudit-trail
support-assistant→snowflake/ticket-search· as r.chenAllowed

How Dome helps

Dome provides a tool gateway and authorization for Snowflake

Decided on the columns

Every Cortex Search call must name the columns it wants back. Ask for customer_email and the call is refused.

Their role, their data

With per-user OAuth, each call runs with the default role of the person the agent acts for. Snowflake grants still apply.

No raw SQL

The SQL execution tool is refused for agents that don't need it. They answer questions through Cortex Search and Cortex Analyst.

Get started

Snowflake behind the Gateway in three steps

Add your MCP server's URL, sync its tools into the Gateway's catalog, and apply the rules. The URL and the tool names come from your CREATE MCP SERVER statement.

  1. 01

    Add the Snowflake MCP server

    Create a Snowflake OAuth security integration with https://api.domesystems.ai/oauth/callback as its redirect URI. Dome holds each user's tokens and injects them on calls made for them.

    $ dome tools add --name snowflake \
    --url https://myorg-myaccount.snowflakecomputing.com/api/v2/databases/SUPPORT_DB/schemas/MCP/mcp-servers/support_mcp \
    --auth-method oauth --credential-type per-user \
    --oauth-authorize-url https://myorg-myaccount.snowflakecomputing.com/oauth/authorize \
    --oauth-token-url https://myorg-myaccount.snowflakecomputing.com/oauth/token-request \
    --oauth-client-id "$SNOWFLAKE_CLIENT_ID" \
    --oauth-client-secret "$SNOWFLAKE_CLIENT_SECRET" \
    --gateway data-gateway
  2. 02

    Sync the catalog

    Run it once your own Snowflake consent is attached. Until then the sync fails, and agents get “tool not available in this gateway”.

    $ dome tools catalog sync snowflake
  3. 03

    Apply the rules

    Scope them to one agent while you try them. Simulate before you deploy.

    $ dome rules apply snowflake-columns.cedar \
    --agent churn-researcher --name snowflake-columns

Commands and rules tested against a Dome workspace on October 1, 2026. For anything about Snowflake itself, see Snowflake's documentation.

Rules

Search, without the email column

The permit opens Snowflake to the agent. The forbids refuse a search that doesn't name its columns or asks for customer_email, a search for more than 50 rows, and any call to the SQL execution tool.

permit (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when { resource.connection_name == "snowflake" };
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "snowflake" &&
resource.tool_name == "ticket-search" &&
resource has arguments &&
(!(resource.arguments has columns) ||
resource.arguments.columns.contains("customer_email"))
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "snowflake" &&
resource.tool_name == "ticket-search" &&
resource has arguments &&
resource.arguments has limit &&
resource.arguments.limit > 50
};
 
forbid (principal, action == Dome::Action::"mcp:call", resource is Dome::MCPTool)
when {
resource.connection_name == "snowflake" &&
resource.tool_name == "sql_exec_tool"
};

Try it

One call, two outcomes

Switch the caller or the argument and watch the same call decide differently. Every decision lands in audit.

Columns

agent churn-researcher · acting as r.chen
snowflake/ticket-search(query: "cancel after price change", columns: ["ticket_id", "subject", "status"], limit: 20)
  1. Agentchurn-researcher is registered and active
  2. Callerr.chen verified through Okta
  3. RuleTicket fields are allowed
DecisionAllowed

Example agents

Three agents on Snowflake

From our template library. Each one reads broadly and writes narrowly.

support-assistant

Find similar tickets

Searches past support tickets for the one in front of an agent and suggests the fix that worked.

  • snowflake/ticket-search

finance-analyst

Answer revenue questions

Asks Cortex Analyst revenue questions in plain language and gets back the SQL that answers them.

  • snowflake/revenue-analyst

churn-researcher

Research churn

Reads cancellation tickets alongside revenue by segment. Customer contact details stay out of its results.

  • snowflake/ticket-search
  • snowflake/revenue-analyst

Agent workflow

Bringing it together

Connecting Snowflake to registered agents, models, and identity in Dome completes a governed agent application.

Dome

Control point

Gateway

  • Rules
  • Guards
  • Quotas

Every call decided and audited

Tools

MCP server

Snowflake

This page

FAQ

Common questions

Does Dome work with Snowflake's managed MCP server?

Yes. Add your MCP server's URL with per-user OAuth and the client ID and secret from a Snowflake OAuth security integration.

Where do the Snowflake tool names come from?

From your CREATE MCP SERVER statement. Each tool's name field is what agents call and what rules match on.

Can I stop an agent from returning a specific Snowflake column?

Yes. A rule can require every Cortex Search call to list its columns, and refuse any call that names a restricted one.

Whose Snowflake role does an agent use?

With per-user OAuth, the default role of the person it acts for. Dome picks their token from their verified identity.

Next steps

Talk with our FDE team

Our forward deployed engineers work with your platform team to get your agents into production and under control: the first one governed on your own systems, and a pattern your teams can repeat for every agent after it.