06-reference/research

cortex code client deployable surface p3 p4

2026-09-13·research-brief·source: deep-research·by Ray Data Co (deep-research synthesis)
snowflake-cococortex-codedeployment-profilesorganizational-intelligencephdata

Which CoCo surface can a client deploy today for P3/P4? The CLI on SPCS, using skills rather than a plugin. Cloud Agents is still not deployable. The new GA Coding Agent sandbox is the one to watch.

The question

"For CAF deployment profiles P3/P4, which Cortex Code surface is client-deployable today given preview gating - CoCo CLI-in-SPCS vs Cloud Agents (private preview) vs Snowsight?" This was a follow-up in [[2026-07-05-brigade-skills-snowflake-cortex-code]], which found that CoCo reads Claude Code plugins and skills. That brief left open which surface can actually carry the Brigade inside a client account.

What we already know (from the vault)

What the web says

All sources below were fetched or searched on 2026-09-13. The CoCo overview page and the CLI page carry no page date. Release notes carry their own dates.

Surface matrix (hand this one to a client):

Surface Status (Sep 2026) Primary source + date Region / cloud What the client admin must enable Skills / subagents / hooks / plugins / MCP
CoCo CLI GA CoCo overview (undated); CoCo CLI (undated) Commercial accounts only (not Gov, VPS or Sovereign). Not on standard trial accounts Cross-region inference (CORTEX_ENABLED_CROSS_REGION, set by ACCOUNTADMIN) when models are not in-region. SNOWFLAKE.CORTEX_USER or CORTEX_AGENT_USER database role, which comes through PUBLIC by default unless revoked Skills, subagents, hooks, custom tools, profiles and AGENTS.md: listed without a preview label. Plugins: Preview. MCP: Preview. ACP: Preview.
CoCo CLI inside SPCS No doc covers it. It is a phData-built pattern (GA CLI in a GA SPCS container) None. The CLI page never mentions SPCS, containers, CI or headless mode Same as CLI, plus SPCS Everything the CLI needs, plus compute pool, image repository and service grants from ACCOUNTADMIN Same as CLI. Headless or non-interactive use is UNVERIFIED at a primary source
CoCo in Snowsight GA since 2026-03-09 (preview from 2026-02-02) GA release note, Mar 9 2026; Snowsight doc Widest reach: Commercial, FedRAMP Moderate and High, DoD, KSA sovereign Cross-region inference Plugins, skills and hooks are not documented for this surface on the overview page. Shared-skill install through the CoWork Skill Catalog is claimed in vault-cited Summit material; UNVERIFIED for Snowsight
CoCo Desktop GA CoCo overview; Desktop doc Commercial (not Gov, VPS or Sovereign). macOS and Windows Cross-region inference Plugins, skills, hooks and MCP
CoCo in VS Code extension GA 2026-08-27 (private preview in April) Release note, Aug 27 2026 (title seen, not fetched) UNVERIFIED UNVERIFIED UNVERIFIED
CoCo automations (CLI + Snowsight) Preview 2026-08-21 Release note, Aug 21 2026 (title seen, not fetched) UNVERIFIED UNVERIFIED Scope, including whether it schedules unattended runs, is UNVERIFIED
Cortex Agents Coding Agent (code_toolset_all) GA 2026-08-26 Release note, Aug 26 2026 Not stated in the note Not stated in the note A Snowflake-managed sandbox "backed by the same runtime that powers Snowflake CoCo", with bash, file operations, grep, glob, web search, SQL and skills. Subagents, hooks and plugins are not mentioned
Cortex Agents code execution tool Preview 2026-08-20 Release note, Aug 20 2026 (title seen) UNVERIFIED UNVERIFIED Cannot be combined with code_toolset_all in one request
CoCo Cloud Agents Private preview (last primary statement is from April 2026. No GA or public-preview note found in the release notes as of 2026-09-13) Snowflake blog: One Governed Agent; press release, 2026-04-21 UNVERIFIED Enrollment path UNVERIFIED (private previews normally go through the Snowflake account team) "Dedicated and isolated compute inside Snowflake". Extensibility UNVERIFIED
CoCo Agent SDK (Python/TypeScript) Preview CoCo overview UNVERIFIED UNVERIFIED Reads files, runs commands, searches the codebase, runs SQL, edits code
Claude Code plugin / CoCo MCP server Preview (April 2026) Snowflake blog UNVERIFIED UNVERIFIED Lets Claude-side seats call CoCo

Supporting points:

Convergences and contradictions

Synthesis for RDCO

Verdict for the Organizational Intelligence (OI) deployment profiles (P3/P4 were drafted under the old "CAF" name): today, the only client-deployable way to run the Brigade inside the client's Snowflake boundary is the GA CoCo CLI inside a client-owned SPCS container, carrying the Brigade as loose skills, subagents and hooks. Snowsight is GA and has the widest regional reach, but it is interactive and has no documented plugin or skill loading, so it is not a service-loop runtime. Use it for the human operator's seat and for demos. Cloud Agents is still private preview with no public GA signal, so a phData architect should not put it in a statement of work. It is "roadmap, via the Snowflake account team." The CLI-in-SPCS path is built from GA parts, but Snowflake does not document it as a deployment pattern. That means phData owns its support burden: the image build, authentication inside the container, the headless invocation, and upgrades. It also needs ACCOUNTADMIN for three things: cross-region inference, compute-pool and service grants, and the image repository.

P4 needs less than it seemed. P4's seats are Anthropic Claude Cowork, so CoCo only answers the service-loop question, and the answer is the same as P3. The one P4-specific piece is the Claude Code plugin / CoCo MCP server (Preview), which lets Claude-side seats reach into Snowflake. That is a preview dependency, so for P4 in production, keep the matrix's single remote MCP server as the port-crossing mechanism.

The option to put in front of the client is the Aug 26 GA Cortex Agents Coding Agent. It is a Snowflake-managed sandbox on the CoCo runtime that runs skills and SQL, which removes phData's container-ownership burden. If a future check confirms it loads subagents and hooks (Gate-A lint lives in a hook), it replaces CLI-in-SPCS as the recommended P3 runtime, and it replaces Cloud Agents too. Until that check, the matrix should read: P3 = CoCo CLI in SPCS (GA parts, phData-assembled, skills not plugin); upgrade path = Coding Agent sandbox (GA, extensibility unconfirmed); watch = Cloud Agents (private preview). The pitch to Snowflake AEs also gets simpler, because the egress objection is now a cross-region-inference and residency question for every CoCo surface.

Two corrections to carry into client material: (1) say "skills, subagents and hooks, GA" rather than "native plugin," unless the client accepts Preview features; (2) use Snowflake's current names, "CoCo" and "CoWork." Say "formerly Cortex Code / Snowflake Intelligence" once, because RFPs still use the old names.

Why this is in the vault

It settles the runtime cell for P3 (and P4's service loop) in the OI deployment matrix ([[2026-07-07-hex-deployment-matrix-v2]]). It also corrects the parent brief's "native plugin" framing before a phData DSA uses it in a client or Snowflake AE conversation.

Open follow-ups

Related

Sources