The preview residue after App Runtime GA is real but tiny, and none of it sits on the build path — it sits on the governance path
The question
Verbatim: "Which Snowflake SPCS App Runtime capabilities remain in PREVIEW after the 2026-09-01 GA of the core runtime (the 2026-08-31 app.yml v2 release note is still flagged Preview) — and does depending on any of them re-introduce the account-wide SYSTEM$ENABLE_PREVIEW_ACCESS toggle that GA just removed?"
Context: [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] concluded that App Runtime is now promisable as a phase-2 Statement of Work (SOW) deliverable rather than carried as a risk. That conclusion holds only if the reference architecture avoids still-preview sub-features, because a single open-preview dependency would put the account-wide, all-or-nothing preview toggle back in the critical path.
Method note, stated because it bears on how much weight the inventory carries. Every status claim below comes from docs.snowflake.com or an official Snowflake release note, read 2026-09-29. Building a per-capability inventory required more primary pages than the standard three-WebFetch research cap allows, so the additional fetches were routed through two zero-context sub-agents that read raw HTML and ran regular-expression passes for admonition markup, rather than trusting a summarizer to preserve callout boxes. Fourteen distinct primary pages were read. No blog, Medium post, analyst note, or community thread was used for any status claim.
What we already know (from the vault)
- The parent brief's recommendation is narrower than "commit it." [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] holds that profile P2.5 stays the default design and App Runtime is the phase-2 upgrade, committable "with an enablement checklist as the gating milestone, instead of carrying it as a hope," and never on the critical path of a dated deliverable at an account whose enablement state has not been personally confirmed.
- That brief left this exact question open and unanswered. It recorded the app.yml v2 note as "flagged Preview" with no URL and no verification pass, and posed the toggle question as a follow-up. [[2026-09-26-spcs-brigade-external-access-anthropic-reachability]] closed several sibling follow-ups but treated the toggle half as a dead premise for the core runtime only, noting "there is no per-feature identifier string to pin."
- The toggle's mechanics were already pinned. [[2026-07-12-spcs-app-runtime-enablement-partner-managed]] documents
SYSTEM$ENABLE_PREVIEW_ACCESSas an ACCOUNTADMIN-only, all-or-nothing, all-users-all-previews account setting, and the 2026-09-25 brief adds that turning it on carries acceptance of Snowflake's Preview Terms of Service, whose whole point is that preview features are not for production systems or production data. That is why one open-preview dependency is expensive out of proportion to its size. - The vault already has a contract rule for exactly this. [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]]: "the release note is the evidence; the press release is not" — a feature is SOW-promisable only when a docs.snowflake.com release note says General availability and the feature doc carries no preview banner.
- The surrounding stack is already understood. [[2026-09-13-cortex-code-client-deployable-surface-p3-p4]] establishes that preview features can sit behind the account-wide toggle and that several adjacent CoCo surfaces (plugins, MCP, ACP) are still Preview, so the toggle question is not hypothetical for the wider architecture even where it is settled for App Runtime.
What the web says
All citations below are docs.snowflake.com, read 2026-09-29.
- The core runtime GA is unambiguous and enumerated. "Snowflake App Runtime is now generally available and is no longer in Preview." The note enumerates the GA capability set: a single app.yml manifest for deploy and remote-build configuration including named targets and personal databases; querying Snowflake as the service or as the signed-in user; SQL commands for Application Services and artifact repositories; and sharing, privileges, and account administrator setup (Sep 01, 2026 GA note).
- The 2026-08-31 app.yml note's Preview label is a stale artifact, not a live status. The page still reads "August 31, 2026: app.yml for Snowflake App Runtime (Preview)" in both the H1 and the title tag. But a structural query of the article body returns zero admonition elements: no Preview Feature callout, no preview-terms box, no feature-flag instruction, and no mention of
SYSTEM$ENABLE_PREVIEW_ACCESSanywhere in the body (Aug 31, 2026 note). The next day's GA note folds that same manifest, named targets and personal databases into the GA capability list. A dated release note is a snapshot of the day it was written; it is not a living status page. - Exactly two genuine preview items survive in the App Runtime surface area, and both carry verbatim badges. (1) Conditional feature policy rules: "For conditional rules (for example, blocking Application Services only in a specific schema), see Feature policy rules, which is in private preview" (security controls). (2) Three parameters on artifact repository creation: "INDEX_URL, AUTHENTICATION_SECRET, and PACKAGE_RETENTION apply to customer-hosted Python artifact repositories, which are in public preview" (CREATE ARTIFACT REPOSITORY).
- Nothing else in the section carries a preview badge. Across the App Runtime overview, the app.yml manifest reference (all 23 documented field sections), deploy targets, security controls, account administrator setup, and the Application Services SQL command index, the literal string "preview" does not appear in the body of four of the six pages, and where it does appear it is either the two badges above or a Snowsight button labelled "Preview SQL". No page in the section mentions a feature flag, "enable preview access", or "contact Snowflake support".
- The toggle documentation is silent on general availability, and that silence is the crux.
SYSTEM$ENABLE_PREVIEW_ACCESSsays "Enables access to open preview features", "Only account administrators (users with the ACCOUNTADMIN role) can execute this function", "This is an all-or-nothing setting that affects all users and all previews within an account", "SYSTEM$ENABLE_PREVIEW_ACCESS only can enable open preview features", and "Contact Snowflake Support to enable or re-enable private preview features" (function reference). A regular-expression pass over the full article text for "general availability", "generally available" and "GA" returns zero matches. The companion status function is silent on the same point (SYSTEM$GET_PREVIEW_ACCESS_STATUS). The preview features list likewise contains no statement about what happens to the toggle requirement when a feature reaches GA, and lists no App Runtime entry. - App Runtime is Node.js only, and that is a hard absence rather than a preview. "Deployable projects use Node.js (typically Next.js). Support for Python is planned" (limitations). Python is not behind a toggle; it does not exist. The same page confirms the surviving GA exclusions: no government regions, no trial accounts, AWS/Azure/Google Cloud commercial regions only.
The inventory
Status column: GA (asserted) means the 2026-09-01 GA release note names the capability explicitly. GA (inferred) means the docs page carries no preview badge but also never says "generally available" — Snowflake does not stamp GA pages, so this is inference from a missing badge and is the weaker of the two. Preview entries quote a verbatim badge.
| Capability | Status | Primary source, read 2026-09-29 | Re-arms SYSTEM$ENABLE_PREVIEW_ACCESS? |
|---|---|---|---|
| App Runtime core runtime | GA (asserted) | 2026-09-01 GA release note | No |
app.yml manifest v2, incl. version: 2 |
GA (asserted) | 2026-09-01 GA note; app-yml reference, no badge | No. The 2026-08-31 (Preview) title is stale; the body has no admonition and no flag instruction |
Named deploy targets, --target, default_target |
GA (asserted) | 2026-09-01 GA note; deploy-targets page | No |
Personal databases (database: USER$) |
GA (asserted) | 2026-09-01 GA note; deploy-targets page | No |
Querying Snowflake as service or as signed-in user; execute_as_role |
GA (asserted) | 2026-09-01 GA note | No |
Application Service SQL commands (CREATE / ALTER / DESCRIBE / DROP / SHOW, SYSTEM$GET_APPLICATION_SERVICE_LOGS) |
GA (asserted) | 2026-09-01 GA note; commands-snowflake-apps index, no badge | No |
| Artifact repository SQL commands (base form) | GA (asserted) | 2026-09-01 GA note; command index | No |
| Sharing, privileges, account administrator setup | GA (asserted) | 2026-09-01 GA note; account-admin-setup page | No |
Remote build service, install / build / run, build_eai, build_job_location |
GA (inferred) | app-yml reference, no per-field badge; limitations page documents build behaviour without a badge | No, on current evidence |
external_access_integrations field and egress via external access integrations |
GA (inferred) | app-yml reference, no badge; limitations page | No, on current evidence |
Service endpoints and authenticated ingress (BIND SERVICE ENDPOINT) |
GA (inferred) | security controls page (admonitions are operational, not preview) | No, on current evidence |
Scale and suspend (min_instances / max_instances, auto_suspend_secs, auto_resume) |
GA (inferred) | app-yml reference, no badge | No, on current evidence |
| Observability via the account event table | GA (inferred) | App Runtime observability page, no badge | No, on current evidence |
Feature policies, database-scoped (block APPLICATION_SERVICES / ARTIFACT_REPOSITORIES) |
GA (inferred) | security controls page, no badge on the non-conditional form | No, on current evidence |
| Feature policy rules, conditional (e.g. block Application Services only in a specific schema) | Private Preview | security controls page, verbatim: "which is in private preview" | No — and that is worse, not better. The toggle cannot enable private preview at all; the documented path is a Snowflake Support request |
Customer-hosted Python artifact repositories: INDEX_URL, AUTHENTICATION_SECRET, PACKAGE_RETENTION |
Open (public) Preview | CREATE ARTIFACT REPOSITORY, verbatim: "which are in public preview" | Yes, by the documented general rule — open preview is what the toggle gates. But no page connects these parameters to the toggle in one sentence; see the calibration note below |
| Python application support | Not available (not preview) | limitations page: "Support for Python is planned" | Not applicable |
| Government regions, trial accounts | Excluded | limitations page; GA release note | Not applicable |
Convergences and contradictions
- Convergence. The vault's contract rule from [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]] — release note says GA, feature doc carries no preview banner — is satisfied for every capability on the default App Runtime path. That rule was written for a different feature family and it held up cleanly when applied here.
- Contradiction, resolved. The vault's unverified note that "the 2026-08-31 app.yml v2 release note is flagged Preview" is literally true and materially misleading. The label is real and still on the page today. The status it implies is contradicted by the next day's GA note, which lists that exact manifest among GA capabilities, and by the page's own lack of any preview admonition or enablement instruction. Resolution: dated release notes are not restated when a feature is promoted. Read the newest note, not the oldest.
- Open gap the docs will not close for us. No Snowflake page read here states that a capability which has reached general availability is outside the scope of
SYSTEM$ENABLE_PREVIEW_ACCESS. The toggle documentation never uses the words "general availability" at all. The practical conclusion is still solid, because the GA note says App Runtime "is no longer in Preview" and the toggle only ever gated previews, but the clean one-sentence statement an SOW reviewer would want does not exist in the documentation.
Synthesis for RDCO
The headline: the parent brief's recommendation survives, and it survives for a slightly different reason than expected. The fear was that App Runtime GA was a partial GA with preview sub-features scattered through the build path, so that any realistic reference architecture would trip one of them and re-arm the account-wide toggle. That is not what the documentation shows. The default path for a Node.js or Next.js application deployed from an app.yml v2 manifest, with named targets, a personal-database development target, external access integration egress, an authenticated service endpoint, autoscaling and event-table logging, is entirely GA-asserted or GA-by-absent-badge. The preview residue is two items, and neither is on that path. Depending on nothing outside that path means the toggle stays out of the architecture, and the enablement conversation with a client security team stays what [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] said it became: a role-based access control and region conversation, not a preview-terms conversation.
The non-obvious finding is where the preview residue actually sits: in the governance path, not the build path. The one private-preview item is conditional feature policy rules, which is the mechanism for blocking Application Services everywhere except a named schema. That is precisely the control a cautious client security reviewer is most likely to ask for during the enablement conversation, because it is the natural counter-offer to "grant the deploy role CREATE COMPUTE POOL at account level." Today the answer is that database-scoped feature policies exist and schema-scoped conditional rules do not, and the account-wide preview toggle cannot buy them, since private preview is only reachable through a Snowflake Support request. So the enablement checklist that the parent brief made the gating milestone needs one more line, and it is a line about what we cannot offer rather than what we need granted. Saying that before the client asks is strictly better than discovering it mid-review.
The second item is a real toggle trap, but it is easy to steer around and easy to walk into by accident. Customer-hosted Python artifact repositories, configured through INDEX_URL, AUTHENTICATION_SECRET and PACKAGE_RETENTION, are labelled public preview on an otherwise unbadged GA command page. Open preview is exactly what SYSTEM$ENABLE_PREVIEW_ACCESS gates, so reaching for those parameters would pull the all-or-nothing, all-users, preview-terms-accepting account toggle back into the path for the sake of a dependency-hosting convenience. The saving grace is that App Runtime does not support Python applications at all yet, so a Node.js deployment has no reason to touch them. The risk is not this quarter; the risk is the day Python support ships and someone wires up a private package index without checking the parameter's badge. Worth writing into the architecture note now, while the reason is fresh.
Calibration, because this is the kind of claim that gets quoted into an SOW. Two weaknesses are worth stating plainly rather than smoothing over. First, "GA (inferred)" is doing real work in the inventory above. Snowflake badges previews but does not badge GA, so for capabilities the GA release note did not enumerate by name — external access integration egress, autoscaling, observability, the build configuration fields — the evidence is an absent badge, not an affirmative statement. That is good enough to design on and thin for a contractual promise. The eight capabilities the GA note enumerates are the ones that can be quoted directly. Second, the assertion that a GA feature does not require the preview toggle is not documented anywhere; it follows from the GA note's "no longer in Preview" plus the toggle's own scope statement, which is a two-source inference rather than a single sentence. Both of those are honest limits on the answer, and neither changes the recommendation: App Runtime stays committable as a phase-2 deliverable with an enablement checklist as the gating milestone, and it does not revert to carried risk.
Why this is in the vault
This closes the single open follow-up that [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]] left load-bearing: whether its phase-2 SOW recommendation depends on preview sub-features that would re-arm the account-wide toggle. It also supplies the concrete addition to the enablement checklist that brief made the gating milestone — schema-scoped conditional feature policy rules are private preview and cannot be offered — and flags the customer-hosted Python artifact repository parameters as a future toggle trap for whenever App Runtime Python support ships.
Open follow-ups
- Does Snowflake document anywhere — on the preview features page, a release lifecycle page, or in the Preview Terms of Service — that capabilities which have reached general availability are outside the scope of
SYSTEM$ENABLE_PREVIEW_ACCESS? Today that is a two-source inference, and a single cited sentence would be worth having before an SOW reviewer asks. - What does the Preview Terms of Service text actually prohibit, and does accepting it account-wide carry any consequence for the GA workloads already running in that account? This is the real cost of the toggle and the vault currently holds it as a paraphrase, not as quoted contract language.
- What is the documented enablement path for the "Feature policy rules" private preview, and is there a release note or behaviour change bundle tracking its promotion? If it is close to GA, the enablement-checklist line changes from "cannot offer" to "not yet".
- Does the customer-hosted Python artifact repository preview appear on the Snowflake preview features list with an Open versus On Request designation, and with a listed date? Open and On Request are enabled differently, and the distinction decides whether that dependency is a toggle call or a support ticket.
- When Snowflake promotes a feature to general availability, does it ever amend the older Preview-labelled release note, or is a stale label the norm? Sampling prior promotions in the 2025 and 2026 release-note archive would settle how much weight any Preview-labelled note deserves, and would generalise well beyond App Runtime.
- Is App Runtime Python support tracked anywhere with a lifecycle label, or is "planned" the full public position? That determines whether the Python artifact repository toggle trap is a next-quarter concern or a next-year one.
Related
- [[2026-09-25-spcs-app-runtime-client-account-enablement-gate]]
- [[2026-09-26-spcs-brigade-external-access-anthropic-reachability]]
- [[2026-07-12-spcs-app-runtime-enablement-partner-managed]]
- [[2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix]]
- [[2026-09-13-cortex-code-client-deployable-surface-p3-p4]]
Sources
Vault:
~/rdco-vault/06-reference/research/2026-09-25-spcs-app-runtime-client-account-enablement-gate.md~/rdco-vault/06-reference/research/2026-09-26-spcs-brigade-external-access-anthropic-reachability.md~/rdco-vault/06-reference/research/2026-07-12-spcs-app-runtime-enablement-partner-managed.md~/rdco-vault/06-reference/research/2026-09-14-snowflake-cowork-cortex-ga-vs-preview-matrix.md~/rdco-vault/06-reference/research/2026-09-13-cortex-code-client-deployable-surface-p3-p4.md
Primary sources, all docs.snowflake.com, all read 2026-09-29:
- https://docs.snowflake.com/en/release-notes/2026/other/2026-09-01-snowflake-app-runtime-ga
- https://docs.snowflake.com/en/release-notes/2026/other/2026-08-31-app-yml-v2
- https://docs.snowflake.com/en/sql-reference/functions/system_enable_preview_access
- https://docs.snowflake.com/en/sql-reference/functions/system_get_preview_access_status
- https://docs.snowflake.com/en/release-notes/preview-features
- https://docs.snowflake.com/en/release-notes/new-features
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/about-snowflake-app-runtime
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/app-yml
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/deploy-targets
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/security
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/account-admin-setup
- https://docs.snowflake.com/en/developer-guide/snowflake-app-runtime/limitations
- https://docs.snowflake.com/en/sql-reference/commands-snowflake-apps
- https://docs.snowflake.com/en/sql-reference/sql/create-artifact-repository