Snowflake · Explain and govern Snowflake spend

Credit Guardian

Which workloads are consuming credits, why, and who is accountable for the spend?

Operational failure

The monthly bill is visible after the fact, while idle capacity, poor suspension settings, workload ownership and contract trajectory remain hard to explain.

Read-only by default · evidence required · human approval before change

From source evidence to a reviewable finding.

01 · Source evidence

  • WAREHOUSE_METERING_HISTORY
  • QUERY_HISTORY
  • WAREHOUSE_EVENTS_HISTORY
  • Resource monitors
  • Users, roles, tags and allocation rules

02 · Analysis path

  1. 01
    Establish spend and workload baseline
  2. 02
    Attribute consumption to owners and purposes
  3. 03
    Detect idle, sizing and configuration waste
  4. 04
    Forecast commitment trajectory
  5. 05
    Rank evidence-backed recommendations

03 · Product outputs

  • Warehouse waste findings
  • Chargeback and showback allocation
  • Highest-cost query evidence
  • Contract-consumption forecast
  • Human-reviewed remediation drafts

Security contract

The boundary is part of the product.

Data residency
Snowflake Native mode keeps the product workflow in the customer Snowflake account. Microsoft Foundry mode moves selected metadata or telemetry into the customer-controlled Azure boundary.
Permissions required
A dedicated scoped Snowflake role · Read access only to the listed metadata and telemetry views
Write scope
No write capability by default. Any remediation requires human approval and separately granted permissions.
Audit trail
Model calls, retrievals, source evidence, findings, recommendations and approvals are recorded for review.

Deployment choice

Native by default. Azure when the enterprise standard requires it.

Default for sensitive data

Snowflake Native App

  • Runs in the customer Snowflake account.
  • Uses Snowpark Container Services when a container runtime is required.
  • Customer controls installation, grants, compute and network policy.
  • Private listing first; Marketplace availability is not implied.

For Azure-standardised enterprises

Microsoft Foundry

  • Agent runtime, model routing, evaluation and tracing in customer Azure.
  • Snowflake access through customer-controlled OAuth or key-pair authentication.
  • Selected metadata or telemetry crosses into the designed Azure boundary.
  • Identity, network, retention and regional placement are explicit design decisions.

Pilot evidence

Decide from a baseline, not a demo.

  1. 01
    Credits attributed to an owner
  2. 02
    Idle or avoidable consumption identified
  3. 03
    Forecast error against actual spend
  4. 04
    Recommendations accepted after evidence review

Evaluate Credit Guardian against your account.

Describe the decision, platform or operating risk that is slowing you down. We will identify the evidence required and whether consulting, training or a scoped agent is the right response.

Discuss the context