Snowflake gave your agents something most agent stacks lack: a governed definition of what your data means. A semantic view encodes business logic (logical tables, relationships, facts, dimensions, metrics, synonyms, and verified query examples) and Cortex Analyst reads it, rather than raw tables, to turn plain-English questions into governed SQL. Roles apply. Definitions are consistent. Answers are repeatable.
But a conversation isn’t a query. A user’s intent moves turn by turn, and the semantic view doesn’t. When the two disagree, the governed default can quietly win, and the user never hears about it.
This post covers where Cortex Agents and Snowflake Intelligence break in multi-turn use, and how Turn3 finds the turn that broke.
Governance protects the data. It doesn’t protect the conversation.
Cortex Analyst honors Snowflake’s role-based access control, so the SQL it generates and runs respects your existing access rules. That’s a real guarantee about who can see what. It is not a guarantee that the answer matches what the user meant. Those are different questions, and only the first one has a control today.
Four ways Cortex sessions break
- The semantic default beats the user’s override. Cortex Analyst uses verified SQL to learn how your organization defines a term like “active.” If a user says “I count active as the last 30 days” and the view says 90, the agent may answer from the view and never mention the mismatch.
- Right data, wrong tool. The agent decides which tool to use based on the question it’s given. Snowflake Intelligence agents connect to semantic views, Cortex Search services, and other tools. A policy question answered from a metrics view, or a metrics question answered from a document, sounds plausible either way.
- Retrieval that’s best, not current. Cortex Search blends vector and keyword search with semantic reranking. It returns the closest match, which can be a superseded policy document.
- Semantic-layer edits that change every conversation. Adding a verified query, renaming a metric, or adjusting a synonym shifts answers across every session using that view. Snowflake can even optimize a semantic view by generalizing from its verified queries. The layer evolves, and the agent evolves with it.
One session, end to end
This is an illustrative composite: a finance team using Snowflake Intelligence to ask about customer metrics.
→ Turn 2: User asks how many active customers there were last quarter, specifying that active means a purchase in the last 30 days.
→ Turn 3: The agent answers using the semantic view’s 90-day definition. The number looks right, and the mismatch is never surfaced. This is the breaking turn.
→ Turns 4–8: “Split by segment.” “Compare to the prior quarter.” “What churn does that imply?” Each returns valid SQL and a fluent answer, all inheriting the wrong definition.
→ Turn 9: The churn figure goes into a forecast review.
Every query ran under the right role against the right view, and the session still failed.
What Turn3 does with it
Turn3 pulls the governed telemetry your Cortex workloads already emit, with no exporter changes. Cortex AI Observability, powered by TruLens, evaluates and traces agents on Snowflake. Turn3 builds on that foundation at the session level:
- See the session. Reconstruct the conversation across Analyst calls, Search calls, and the agent’s reasoning, in order.
- Judge the outcome. Frontier-model judges score whether the user’s goal was met and attribute the failure to turn 3, where their definition was overridden, not turn 9.
- Cluster failures. Every session where a user-stated definition lost to a semantic default becomes one tracked issue: active, resolved, or regressed.
- Stop the regression. The failure becomes an eval that gates CI. Treat semantic-view edits like code: run the suite before they go live.
Turnguard, Turn3’s inline guardrail layer, evaluates responses in the live path in under 200ms at p99. Policies are written in CEL, it fails open by default, and it drops in via SDK or gateway.
Where this matters most
- “Ask your data” assistants used by finance, sales, and operations
- KPI and board reporting, where one definition error becomes a number in a deck
- Customer-facing analytics embedded through the API
- Regulated workflows where a wrong answer or a leaked identifier is an incident
Start from what you already emit
Turn3 ingests with no proprietary SDK and no lock-in. If your Cortex workloads are already emitting traces, you’re about 20 minutes from your first reconstructed session. Deploy in Turn3’s cloud, or self-host in your VPC with prompts redacted at the edge so sensitive data never leaves your boundary.
Your semantic view knows what “active” means. The question is whether your agent kept using it after the user said otherwise.
👉 Start free at klimber.io or write to turn3@klimber.io. If your agents touch customers and money, ask about Turnguard.
