Yes, There Is a Today-Shippable Cross-Tenant Path, But Only One of the Two Is Generally Available: Native Apps Carrying a Cortex Agent Went GA 2026-08-07, While Direct Agent Sharing Is Still Open Preview
The question
"Is there a today-shippable cross-tenant path to publish a phData Cortex Agent (or agent + skills bundle) to Snowflake Marketplace / as a Native App so a different org's CoWork surfaces it, and what is the partner listing / validation / security-review process?"
This is open follow-up #2 from [[2026-07-08-cortex-agent-cowork-skill-native-publish]], which confirmed in-account surfacing but left the cross-tenant publish path explicitly UNCONFIRMED. Closing that gap is the whole point of this brief. Naming note for traceability: the internal phData program that older vault docs call "CAF" was renamed on 2026-08-10; the current framing is the Organizational Intelligence (OI) umbrella.
Headline: As of 2026-09-23, Snowflake documents two distinct cross-tenant paths. Packaging a Cortex Agent inside a Snowflake Native App is generally available (GA) as of the 2026-08-07 release note, the app-created agent appears in the consumer's Snowflake CoWork, and it travels through the standard Native App listing chain (automated security scan triggered by DISTRIBUTION = EXTERNAL, then a Marketplace Operations functional review). Directly sharing a standalone agent object via a share or listing is documented but carries a Preview Feature - Open banner, and it explicitly cannot carry skills, procedures, or Model Context Protocol (MCP) connector tools. So the "agent + skills bundle" half of the question splits: skills ride the Native App path, not the direct-share path.
What we already know (from the vault)
- The parent brief concluded that native CoWork surfacing is a per-account capability and that "there is no confirmed 'publish once, every client's CoWork users discover it' marketplace for agents today; that productized-reuse path (Marketplace / Native App / Cortex Knowledge Extensions / Agentic Resource Discovery) is real in direction but under-documented and partly preview." That conclusion is now out of date for the Native App path. See [[2026-07-08-cortex-agent-cowork-skill-native-publish]].
- The parent brief also fixed the vocabulary: an agent surfaces as an agent object added to the account's Snowflake Intelligence Object, while a skill is a separate
SKILL.mdcapability package an agent consumes. This brief keeps that split, because Snowflake's own sharing limits fall exactly along it. See [[2026-07-08-cortex-agent-cowork-skill-native-publish]] and [[2026-07-05-brigade-skills-snowflake-cortex-code]]. - The GA-vs-preview matrix rates the core CoWork agent and Cortex Agents as GA, User Skills as public preview (2026-08-18), and the Skill Catalog as not confirmed shipped (no release note). That matters here: cross-tenant skill discovery independent of an agent is not a shippable claim even though skills can ride inside an app. See [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]].
- House naming is settled: say "Snowflake CoWork," recognize "Snowflake Intelligence," and keep it apart from Anthropic's Claude Cowork. The SQL object is still named the Snowflake Intelligence Object. See [[2026-09-15-snowflake-intelligence-vs-cowork-naming-standard]].
- phData is a Snowflake Elite Consulting Partner per Snowflake's own partner directory, with no AI/ML workload specialization listed. That is the public partner standing any provider-side listing motion would start from. See [[2026-09-11-phdata-snowflake-partnership-warm-start-map]].
- phData's delivery spine already builds at the agent layer (
setuptocreate-viewstocreate-semantic-viewtocreate-agenttodeploy, wrapped in golden-set and TruLens evaluation). Nothing in that spine currently produces an application package. See [[2026-05-20-phdata-cortex-agents-practice]].
What the web says
- Native App path is GA. Snowflake's release note dated 2026-08-07 is titled "Snowflake Native Apps: Cortex Agents and MCP servers (General availability)" and states that providers can create a Cortex Agent in an app's setup script "so the app offers a conversational experience over its shared data and functionality," plus Snowflake-managed and Snowpark Container Services-hosted MCP servers, and inter-app agent calls. (release note) Evidence note: this was read from the Snowflake documentation release-note index and search result text on
docs.snowflake.com, not a direct page fetch, because the fetch budget was spent on the developer guide and the listing requirements. - How the provider builds it, and what the consumer sees. The developer guide says the agent is created with
CREATE AGENT"in the app's setup script, or at runtime in a code entity," supports Cortex Analyst tools over semantic views, Cortex Search services, procedures, user-defined functions, agent skills viaSKILL.mdfiles on internal stages, and thecode_executionsandbox toolset. App-created agents appear "in Snowflake CoWork" and are "callable from the REST, Python, and SQL APIs, just like standalone agents." They run under restricted caller's rights; owner's-rights agents are not supported, and reaching consumer-owned objects needs an explicitGRANT CALLER ... TO APPLICATION. The page carried no preview banner. (Use Cortex Agents and MCP servers in an app) - Direct agent sharing exists but is open preview, and is narrower. The "Share Cortex Agents" page carries a Preview Feature - Open banner and states "You can share your Cortex Agents either on Snowflake Marketplace or with designated accounts," using
GRANT USAGE ON AGENT my_agent TO SHARE my_shareplus grants on every linked object, which must sit in the same database as the agent. Consumers add it to CoWork by keeping the "Add to Snowflake CoWork" toggle enabled when they get the listing. Hard limits: "Agents that use other tool types, such as procedures, skills, or MCP connectors, can't be shared," Python user-defined table functions cannot be shared, and new tools added to a shared agent are not automatically added to the share. (Share Cortex Agents) - The listing process for apps is a documented five-phase chain. Design and develop to the enforced requirements; test by installing from a separate consumer account; pass the automated security review, triggered by setting "the application package's DISTRIBUTION to EXTERNAL"; submit the listing with the scanned package attached; then a functional review in which "Marketplace Operations installs and tests your app as a new consumer." A provider profile is required, with Stripe Express for payouts. (Guidelines and requirements for listing Apps on Snowflake Marketplace)
- Cortex-specific listing requirements are explicit. An app that calls Cortex "must declare SNOWFLAKE.CORTEX_USER as a required privilege in the application package manifest.yml, rather than requesting broad IMPORTED PRIVILEGES"; apps pinning a specific model "must document the model name(s) in the listing" and note regional availability; all account-level privileges and references must be declared in the manifest; and consumer Snowflake username/password prompts are banned, with Programmatic Access Tokens, OAuth, or key pair as the acceptable authentication methods. (listing guidelines)
- A separate, stricter track exists for Connected Applications, and it is not the Native App track. Connected Application providers "must be active members of the Snowflake Partner Network (SPN), be enrolled in the AI Data Cloud Products Partner Program, and hold a Connected Application Select tier designation or higher," register a Connection String Identifier, complete technical validation through the SPN portal, and sign a Security and Data Handling Attestation; those reviews conclude "within 10 business days." Do not quote the SPN tier gate or the 10-day timeline as the Native App requirement. (listing guidelines)
- No formal certification badge. The listing guidelines describe security scan plus functional review as the gate; approval equals listing eligibility, with no separate agent or artificial intelligence certification framework beyond the Cortex requirements above. (listing guidelines)
Convergences and contradictions
- The parent brief's "not supported yet" verdict has been overtaken by a shipped feature. On 2026-07-08 the vault concluded the cross-tenant agent-publish path was undocumented. Snowflake shipped it GA on 2026-08-07, one month later. The vault claim was accurate on its date and is wrong today; anything citing it for the Native App path needs correcting.
- The two paths disagree about skills, and the docs never reconcile them. The sharing page says agents using skills "can't be shared." The Native App developer guide lists
SKILL.md-backed agent skills as a supported tool type inside an app. Read literally these are consistent (one describes sharing a standalone agent object, the other describes an agent the app itself creates in the consumer account), but no primary page states that a skills-bearing app-created agent survives Marketplace review. Treat "agent + skills bundle, cross-tenant, GA" as partly unconfirmed. - GA at the feature layer, preview at the surrounding surfaces. The agent-in-app capability is GA, while User Skills is public preview and the Skill Catalog has no release note per [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]]. A client-facing promise should be scoped to "an agent, delivered as an installable app, appearing in your CoWork," not to a skill-marketplace story.
- "Surfaces it in a different org's CoWork" is now literally true, with a consent step. Both paths end in the consumer's CoWork: the shared-agent path via an "Add to Snowflake CoWork" toggle at get-listing time, the app path automatically for app-created agents. Neither is zero-touch: the app path requires consumer-side caller grants under restricted caller's rights before the agent can reach consumer-owned objects.
Synthesis for RDCO
The productized-accelerator motion the parent brief called premature is now buildable, and the load-bearing change is the packaging unit, not the agent. Between 2026-07-08 and today, the answer flipped from "no documented path" to "GA path, one specific shape." The shape is an application package, not an agent object: the accelerator becomes a Snowflake Native App whose setup script runs CREATE AGENT, ships its own semantic views, Cortex Search services, procedures and skills, and installs into a client account where the agent shows up in that client's CoWork alongside their own agents. That is a genuinely different artifact from what phData's delivery spine produces today. The spine ends at a deployed agent in the client's account; the listing motion ends at a versioned, security-scanned app package with a manifest that declares every privilege it needs. For a Deal Solutions Architect and Technical Account Lead, the new competencies are application-package versioning, the restricted-caller's-rights grant model, and manifest privilege declaration, none of which appear in the current create-agent to deploy workflow.
The precise claim to make, and the two claims to avoid. Sayable today: "we can package the accelerator as a Snowflake Native App that creates a Cortex Agent in your account, distribute it through a Marketplace or private listing, and your users reach it in CoWork." Not sayable: (1) "we can publish the agent object itself to the Marketplace," since that path still carries an open-preview banner and drops skills, procedures and MCP connectors; (2) "your teams will discover our skills in the Skill Catalog," since the Skill Catalog has no release note at all. The distinction is commercially real, because the preview path is the cheap one (a GRANT USAGE ON AGENT ... TO SHARE plus linked-object grants) and the GA path is the expensive one (build an app, pass a security scan, pass a human functional review). Anyone reading only a Summit announcement or a partner blog would collapse those and over-promise the cheap path.
The review chain is the real cost line, and it is a company-level motion, not a project-level one. Automated security scan plus a Marketplace Operations human install-and-test means a listed accelerator has a release process with an external gate, a regression surface across app versions, and an owner for re-submission. That is a product-management function, which lands squarely on the Organizational Intelligence umbrella rather than on any single engagement. It also suggests a staging strategy worth pricing separately: use a private listing to a named client account as the first cross-tenant step and keep public Marketplace exposure as a later decision, since a private listing avoids public discovery even if it does not obviously avoid the security scan (see follow-ups). The Cortex-specific requirements are cheap to satisfy but easy to fail on review: declare SNOWFLAKE.CORTEX_USER rather than broad imported privileges, document any pinned model name in the listing, and never prompt for the consumer's Snowflake credentials.
One partner-standing correction to carry forward. The stricter gate found in the listing guidelines (Snowflake Partner Network membership, AI Data Cloud Products Partner Program enrollment, Connected Application Select tier or higher, Connection String Identifier, Security and Data Handling Attestation, ten-business-day review) belongs to the Connected Application track, not the Native App track. phData's public Elite Consulting Partner standing per [[2026-09-11-phdata-snowflake-partnership-warm-start-map]] is a services tier and should not be presented as satisfying, or as required by, the Native App listing path. Conflating the two tracks would put a fabricated prerequisite into a deal conversation.
Why this is in the vault
It closes the single unconfirmed item that gated the packaging half of [[2026-07-08-cortex-agent-cowork-skill-native-publish]]: whether phData can build reusable Cortex accelerators as distributable intellectual property or only as per-account builds. The answer changes the artifact an Organizational Intelligence accelerator has to produce (an application package, security-scanned and functionally reviewed) and gives the DSA a precise GA-versus-preview line so a client conversation does not promise the open-preview agent-sharing path as shippable.
Open follow-ups
- Does a skills-bearing app-created agent survive Marketplace review, or does the "skills can't be shared" restriction from the agent-sharing page reappear as a listing-review constraint? No primary page joins those two statements, and it decides whether phData's
SKILL.mdintellectual property is distributable cross-tenant at all. - Does a private listing to a single named consumer account require the same
DISTRIBUTION = EXTERNALautomated security scan and Marketplace Operations functional review as a public Marketplace listing, or is the human functional review public-listing-only? The listing guidelines describe the chain without separating the two listing types. - Is there a Snowflake release note or roadmap statement for standalone Cortex Agent sharing leaving open preview, and does the preview banner cover the Marketplace listing route specifically or only the
GRANT USAGE ON AGENT ... TO SHAREroute? - What exact consumer-side administrative steps stand between installing the app and the app-created agent appearing in CoWork: is it automatic, or does it require Snowflake Intelligence Object curation in addition to the
GRANT CALLERgrants, and is that per agent or per app? - What edition, region and cross-region-inference constraints apply to app-created Cortex Agents and to shared agents? This sets the addressable installed base for any listing and was not covered by the pages read here.
- Does Snowflake Marketplace monetization support paid or consumption-based listings for agent-bearing Native Apps, i.e. can an accelerator be sold rather than only distributed, and what does the payout mechanism require of the provider entity?
- How does the Native App route compare with Cortex Knowledge Extensions and with the Agentic Resource Discovery
ai-catalog.jsonmechanism for the same cross-tenant goal? Deliberately out of scope here; two sibling questions in the research queue already own those.
Related
- [[2026-07-08-cortex-agent-cowork-skill-native-publish]] - parent brief; its open follow-up #2 is this question, and its "no confirmed cross-tenant path" conclusion is superseded for the Native App route
- [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]] - the GA-versus-preview discipline this brief applies; source for User Skills preview and the unconfirmed Skill Catalog
- [[2026-09-15-snowflake-intelligence-vs-cowork-naming-standard]] - house naming rule for CoWork versus Snowflake Intelligence versus Anthropic's Claude Cowork
- [[2026-09-11-phdata-snowflake-partnership-warm-start-map]] - phData's public Snowflake Elite Consulting Partner standing, used here to keep the Connected Application tier gate from being misattributed
- [[2026-05-20-phdata-cortex-agents-practice]] - the current delivery spine, which stops at a deployed agent and produces no application package
- [[2026-07-05-brigade-skills-snowflake-cortex-code]] - SKILL.md skills as native Cortex Code packages; the intellectual property whose cross-tenant distributability is the open question above
- [[2026-07-07-snowflake-intelligence-vs-cortex-ai-boundary]] - the CoWork app layer versus Cortex Agents orchestration split that frames both paths
Sources
Vault:
- [[2026-07-08-cortex-agent-cowork-skill-native-publish]] -
~/rdco-vault/06-reference/research/2026-07-08-cortex-agent-cowork-skill-native-publish.md - [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]] -
~/rdco-vault/06-reference/research/2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix.md - [[2026-09-15-snowflake-intelligence-vs-cowork-naming-standard]] -
~/rdco-vault/06-reference/research/2026-09-15-snowflake-intelligence-vs-cowork-naming-standard.md - [[2026-09-11-phdata-snowflake-partnership-warm-start-map]] -
~/rdco-vault/06-reference/research/2026-09-11-phdata-snowflake-partnership-warm-start-map.md - [[2026-05-20-phdata-cortex-agents-practice]] -
~/rdco-vault/06-reference/research/2026-05-20-phdata-cortex-agents-practice.md - [[2026-07-05-brigade-skills-snowflake-cortex-code]] -
~/rdco-vault/06-reference/research/2026-07-05-brigade-skills-snowflake-cortex-code.md - [[2026-07-07-snowflake-intelligence-vs-cortex-ai-boundary]] -
~/rdco-vault/06-reference/research/2026-07-07-snowflake-intelligence-vs-cortex-ai-boundary.md
Web (all Snowflake primary documentation, read 2026-09-23):
- Use Cortex Agents and MCP servers in an app (provider build path, supported tool types incl. SKILL.md skills, restricted caller's rights, appears in CoWork): https://docs.snowflake.com/en/developer-guide/native-apps/agents-mcp-servers
- Share Cortex Agents (Preview Feature - Open banner; Marketplace or designated accounts; skills/procedures/MCP tools excluded): https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-agents-sharing
- Guidelines and requirements for listing Apps on Snowflake Marketplace (five-phase chain, DISTRIBUTION = EXTERNAL security scan, Marketplace Operations functional review, Cortex privilege and model-documentation rules, Connected Application track requirements): https://docs.snowflake.com/en/collaboration/guidelines-reqs-for-listing-apps
- Snowflake Native Apps: Cortex Agents and MCP servers (General availability), release note 2026-08-07 - read via the docs.snowflake.com release-note index and search result text, not a direct page fetch: https://docs.snowflake.com/en/release-notes/2026/other/2026-08-07-native-apps-agents-mcp-ga
- Not fetched, flagged for a future run: Use app-created Cortex Agents and MCP servers (consumer-side steps) https://docs.snowflake.com/en/developer-guide/native-apps/ui-consumer-agents-mcp ; Use inter-app agents and MCP servers https://docs.snowflake.com/en/developer-guide/native-apps/inter-app-agents