CertSafari
    Snowflake SnowPro Specialty: Gen AI (GES-C02)· Lessons

    Domain 3 · Lesson 10/15

    Monitoring Cortex Spend: Usage Views, Compute Pools, Alerts and Tag-Based Budgets

    Manage, monitor, and optimize Snowflake Cortex costs.

    9 min read
    7.25% of exam
    9 sources
    Published 5 Oct 2026
    Docs as of 4 Oct 2026

    What you will be able to do

    • Choose the right ACCOUNT_USAGE view for AI functions, Analyst, Search, the REST API, provisioned throughput and metering
    • Track Snowpark Container Services compute pool spend and know which pool states are billed
    • Set up a monthly spending alert and per-user limits on Cortex AI functions
    • Attach a tag-based resource budget to a Cortex Agent, and know when per-user quotas fit better

    1.Which usage view answers which question

    Snowflake records Cortex consumption in several ACCOUNT_USAGE views. Each view covers one service at its own level of detail. Monitoring starts with picking the right one. METERING_DAILY_HISTORY, filtered to SERVICE_TYPE = 'AI_SERVICES', gives the account-wide total. The service-specific views then show where those credits went.

    Cortex usage views and what each one reports
    ViewWhat it reports
    CORTEX_AISQL_USAGE_HISTORYAI function credits per hour, one row per function, model, query and warehouse; excludes AI_PARSE_DOCUMENT
    CORTEX_AI_FUNCTIONS_USAGE_HISTORYAll AI Functions invoked via SQL, including AI_PARSE_DOCUMENT; maximum latency of five minutes
    CORTEX_ANALYST_USAGE_HISTORYREQUEST_COUNT and CREDITS per USERNAME in hourly windows
    CORTEX_SEARCH_DAILY_USAGE_HISTORYDaily EMBED_TEXT and serving credits per service; no warehouse usage yet
    CORTEX_REST_API_USAGE_HISTORYTokens and credits per REST API request, with MODEL_NAME and INFERENCE_REGION
    CORTEX_PROVISIONED_THROUGHPUT_USAGE_HISTORYPTU_COUNT and PTU_CREDITS per billing interval
    METERING_DAILY_HISTORY / METERING_HISTORYCredits by SERVICE_TYPE, such as AI_SERVICES or SNOWPARK_CONTAINER_SERVICES

    Watch the gaps between views. CORTEX_AISQL_USAGE_HISTORY records usage in the hour the query completed. It does not include AI_PARSE_DOCUMENT, so use CORTEX_AI_FUNCTIONS_USAGE_HISTORY when you need every function. The Search daily view does not yet include the warehouse that runs refreshes, so check warehouse metering for that part. CORTEX_FUNCTIONS_QUERY_USAGE_HISTORY breaks down a single query with one row per model. The query below finds the functions and models behind a spike:

    Daily AI function credits by function and modelsql
    SELECT
        DATE_TRUNC('day', START_TIME) AS usage_date,
        FUNCTION_NAME,
        MODEL_NAME,
        SUM(CREDITS) AS total_credits,
        COUNT(DISTINCT QUERY_ID) AS query_count
    FROM SNOWFLAKE.ACCOUNT_USAGE.CORTEX_AI_FUNCTIONS_USAGE_HISTORY
    WHERE START_TIME >= DATEADD('day', -30, CURRENT_TIMESTAMP())
    GROUP BY 1, 2, 3
    ORDER BY usage_date DESC, total_credits DESC;

    Checkpoint 1 of 5· Fill the gap

    Which SERVICE_TYPE value returns credits used by AI Services, including LLM functions?

    SELECT *
      FROM SNOWFLAKE.ACCOUNT_USAGE.METERING_DAILY_HISTORY
      WHERE SERVICE_TYPE=' ? ';

    Checkpoint 2 of 5· Exam question

    A cost analyst wants to see, for the last 30 days, how much a Cortex Search service is spending on maintaining its always-on index versus what it spent generating embeddings during data refreshes. Which view provides this breakdown by consumption type?

    Sources123456

    2.Tracking Snowpark Container Services compute pools

    Models and AI apps that run in Snowpark Container Services bill through compute pools. A pool is a set of VM nodes, and its credit consumption depends on how many nodes it has and their instance family. A pool is billed in IDLE, ACTIVE, STOPPING and RESIZING, and is not billed in STARTING or SUSPENDED. An idle pool therefore costs money until it suspends, which is why the docs point to AUTO_SUSPEND. Container services also incur storage costs (image repository stage, event-table logs, block storage) and data transfer costs.

    For tracking, SNOWPARK_CONTAINER_SERVICES_HISTORY reports hourly credits for Snowpark Container Services only. In METERING_DAILY_HISTORY and METERING_HISTORY, filter on service_type = SNOWPARK_CONTAINER_SERVICES. For data transfer, DATA_TRANSFER_HISTORY labels outbound container traffic with transfer_type SNOWPARK_CONTAINER_SERVICES.

    Checkpoint 3 of 5· Check yourself

    Which ACCOUNT_USAGE view reports hourly credit usage for Snowpark Container Services only?

    Sources7

    3.Alerts and per-user limits for AI functions

    Watching the views is passive. Snowflake's cost-management guide turns them into controls. The first is an account-wide monthly spending alert: an hourly ALERT checks the month-to-date SUM(CREDITS) in CORTEX_AI_FUNCTIONS_USAGE_HISTORY and calls a procedure that emails administrators. The procedure writes to a state table so the same alert fires only once a month. Because the view can lag by up to five minutes, the alert detects overspend after it happens and does not block it.

    Hourly alert that fires once month-to-date AI function credits pass a thresholdsql
    CREATE OR REPLACE ALERT ai_functions_monthly_spend_alert
        WAREHOUSE = <your_warehouse>
        SCHEDULE = 'USING CRON 0 * * * * UTC'  -- Runs every hour
        IF (EXISTS (
            SELECT 1
            FROM SNOWFLAKE.ACCOUNT_USAGE.CORTEX_AI_FUNCTIONS_USAGE_HISTORY
            WHERE START_TIME >= DATE_TRUNC('month', CURRENT_TIMESTAMP())
            HAVING SUM(CREDITS) > 1000  -- adjust the limit accordingly
        ))
        THEN
            CALL SEND_MONTHLY_SPEND_ALERT(1000);  -- please adjust the limit accordingly

    The second control is a per-user monthly limit. Users get AI functions through a custom AI_FUNCTIONS_USER_ROLE. An hourly task removes that role from anyone over budget, and a monthly task gives it back. This only works if SNOWFLAKE.CORTEX_USER is first revoked from PUBLIC, because by default every user inherits Cortex access through PUBLIC.

    Checkpoint 4 of 5· Put it in order

    Put the steps for building the monthly spending alert in order

    1. 1.Resume the alert
    2. 2.Create the procedure that checks spend and sends the email
    3. 3.Create an email notification integration
    4. 4.Create the alert-state table that prevents duplicate alerts
    5. 5.Create the hourly alert that calls the procedure

    Sources8

    4.Object tagging and resource budgets for Cortex Agents

    For Cortex Agents, Snowflake attributes cost through object tags. You create a tag, set it on the agent, and attach that tag to a budget that has a monthly credit limit. Snowflake then counts the credits consumed by the tagged object against the budget.

    Tag the agent with a cost centersql
    ALTER AGENT IF EXISTS my_agent SET TAG cost_mgmt_db.tags.cost_center = 'org-level';
    Give the budget a 10,000-credit monthly limitsql
    CALL my_budget!SET_SPENDING_LIMIT(10000);

    Thresholds are set as a percentage of the limit, and each one can run a stored procedure. A common setup emails at 80% and revokes the agent role at 100%. Thresholds can go up to 500%, so an administrator can restore access for a few users and keep a second hard stop at 200%. A cycle-start action restores access when the next month begins, and trigger type PROJECTED acts on forecast spend rather than actual spend. Enforcement is not immediate: it can take up to eight hours with a standard budget, or two hours with the low-latency option.

    A resource budget caps one object. To give every user the same credit limit across Cortex Agents and other AI features, and to block users who reach it, the docs point to per-user quotas instead.

    Checkpoint 5 of 5· Check yourself

    An administrator wants every user to have the same monthly credit limit across Cortex Agents and other AI features, with users blocked at their limit. Which mechanism fits?

    Sources9

    Exam traps

    Each one states something that sounds right. Open it to see what is actually true.

    1. 1.CORTEX_AISQL_USAGE_HISTORY shows usage for every AI function, including document parsing.Why is that wrong?

      That view leaves out AI_PARSE_DOCUMENT. CORTEX_AI_FUNCTIONS_USAGE_HISTORY covers all functions.

      Covered in Which usage view answers which question

    2. 2.CORTEX_SEARCH_DAILY_USAGE_HISTORY gives the full cost of a search service, including refresh warehouses.Why is that wrong?

      It reports embedding and serving credits. Warehouse usage is only planned for a future release.

      Covered in Which usage view answers which question

    3. 3.A Cortex Agent resource budget cuts off access the moment spending passes 100%.Why is that wrong?

      Budgets are evaluated periodically, so enforcement can lag by hours.

      Covered in Object tagging and resource budgets for Cortex Agents

    Practise it for real

    Get an email when month-to-date Cortex AI function credits pass a threshold

    1. 1.As ACCOUNTADMIN, grant your role IMPORTED PRIVILEGES ON DATABASE SNOWFLAKE, CREATE INTEGRATION, EXECUTE ALERT, warehouse USAGE, and CREATE TABLE/PROCEDURE on a schema

      Why: The alert reads ACCOUNT_USAGE and must own the objects it runs

      You should see: The grants succeed and you can USE ROLE <your_role>

    2. 2.CREATE OR REPLACE NOTIFICATION INTEGRATION ai_cost_alerts with TYPE = EMAIL and your verified address in ALLOWED_RECIPIENTS

      Why: SYSTEM$SEND_EMAIL can only deliver to addresses the integration allows

      You should see: The integration exists and is ENABLED

    3. 3.Create the AI_FUNCTIONS_ALERT_STATE table and the SEND_MONTHLY_SPEND_ALERT procedure, using your address in place of admin@company.com

      Why: The state table stops the alert from emailing more than once a month

      You should see: Calling the procedure with a high threshold returns 'Threshold not exceeded'

    4. 4.Create ai_functions_monthly_spend_alert with a threshold of 0, then run ALTER ALERT ai_functions_monthly_spend_alert RESUME

      Why: A threshold of 0 fires straight away, which proves the whole chain works

      You should see: Within the hour an email arrives and ALERT_HISTORY shows the alert ran

    5. 5.Delete this month's row from AI_FUNCTIONS_ALERT_STATE and recreate the alert with your real threshold

      Why: Otherwise the test row blocks this month's real alert

      You should see: SHOW ALERTS lists the alert with the new threshold

    Stuck? Get a nudge

    If the email call fails with 'recipients ... are not allowed', the address is missing from ALLOWED_RECIPIENTS, the procedure body, or a verified user EMAIL field.

    Sources

    Every claim above is drawn from one of these pages, quoted as it was written on the date shown.

    1. 1.
      “To track credits used for AI Services including LLM Functions in your account, use the METERING_HISTORY view:”
      ↩︎ Which usage view answers which question
    2. 2.
      “Each row in the view represents the usage for a specific combination of function, model, query, and warehouse.”
      ↩︎ Which usage view answers which question
      “Use CORTEX_AI_FUNCTIONS_USAGE_HISTORY to view all functions including AI_PARSE_DOCUMENT.”
      ↩︎ Exam trap 1
    3. 3.
      “The information in the view includes the number of tokens processed and credits consumed for each REST API request.”
      ↩︎ Which usage view answers which question
    4. 4.
      “This Account Usage view lets you retrieve billing data for provisioned throughputs.”
      ↩︎ Which usage view answers which question
    5. 5.
      “CORTEX_SEARCH_DAILY_USAGE_HISTORY view contains daily totals for EMBED_TEXT tokens compute and serving credit compute usage per service.”
      ↩︎ Which usage view answers which question
      “Snowflake intends to also provide virtual warehouse usage in this view in the future.”
      ↩︎ Exam trap 2
    6. 6.
      “The CORTEX_ANALYST_USAGE_HISTORY view can be used to query the usage history of Cortex Analyst.”
      ↩︎ Which usage view answers which question
    7. 7.
      “but not when it is in a STARTING or SUSPENDED state”
      ↩︎ Tracking Snowpark Container Services compute pools
      “To optimize compute pool expenses, you should leverage the AUTO_SUSPEND feature”
      ↩︎ Tracking Snowpark Container Services compute pools
      “In the METERING_DAILY_HISTORY view, query for rows in which the service_type column contains the value SNOWPARK_CONTAINER_SERVICES.”
      ↩︎ Tracking Snowpark Container Services compute pools
      “You incur charges for a compute pool in the IDLE, ACTIVE, STOPPING, or RESIZING state”
      ↩︎ Prediction
      “The SNOWPARK_CONTAINER_SERVICES_HISTORY view offers credit usage information (hourly consumption) exclusively for Snowpark Container Services.”
      ↩︎ Checkpoint
    8. 8.
      “The view has a maximum latency of five minutes, although data may be available in as few as two minutes after function execution begins.”
      ↩︎ Alerts and per-user limits for AI functions
      “When a user exceeds their budget for the month, an hourly task revokes their access to AI Functions by removing AI_FUNCTIONS_USER_ROLE.”
      ↩︎ Alerts and per-user limits for AI functions
      “To enforce per-user limits, you must revoke SNOWFLAKE.CORTEX_USER from PUBLIC”
      ↩︎ Alerts and per-user limits for AI functions
      “First, create a notification integration if one does not already exist.”
      ↩︎ Checkpoint
    9. 9.
      “You create a tag, apply it to a Cortex Agent object, and then associate that tag with a budget.”
      ↩︎ Object tagging and resource budgets for Cortex Agents
      “You can configure thresholds beyond 100%, up to 500%, to handle these exception scenarios.”
      ↩︎ Object tagging and resource budgets for Cortex Agents
      “you can set the trigger type to PROJECTED”
      ↩︎ Object tagging and resource budgets for Cortex Agents
      “it might take up to eight hours with standard budget (or two hours with latency optimized option)”
      ↩︎ Exam trap 3
      “optionally block users who reach a limit on Cortex Agents and other AI domains, use per-user quotas”
      ↩︎ Checkpoint

    Ready to test yourself?

    Practise the 26 questions on this subdomain.

    Spotted a mistake, or was something unclear? Tell us.