Everything StreamGen does
for your Snowflake apps.
See the apps you already have, build new ones by describing them, and keep control of both. Everything on this page is live today.
Who owns every app, who still uses it and what it costs. And the apps people built by hand, brought under the same roof.
Your analysts describe an app and watch it run on real data. StreamGen writes it, fixes it and deploys it to Snowflake.
Many builders, one set of rules: who can do what, what needs approval, which AI is allowed, and a record of every change.
Know what you have.
Who owns every app, who still uses it and what it costs. And the apps people built by hand, brought under the same roof.
App inventory Every Snowflake app in your account in one list, with its owner, viewers and warehouse credits.
Admin → Inventory lists every Streamlit and App Runtime app your Snowflake role can see, whether StreamGen built it or not. For each one: the owner, whether it is live, the last deploy and last use, who viewed it in the last 30 days and the warehouse credits it used. Tiles at the top add it up: apps live, apps idle, AI build cost and warehouse credits.
- •Usage comes from your account's own records (Snowflake's account usage views), read through your Snowflake connection.
- •App Runtime apps that StreamGen didn't deploy are listed without usage figures: Snowflake doesn't record those per app.
- •StreamGen's own apps also show what they cost to build with AI.
Health check of every app Find the apps that will break, a missing column or a lost grant, before their users do.
Every night, and whenever you press "Check all now" in the inventory, StreamGen checks every app: its code, and its queries run on Snowflake with the owner's connection. Each app gets a badge, healthy, warnings or failing, and one click shows the exact problem in each environment, in Snowflake's own words.
- •Failing means the app will break: a syntax error, a missing table or column, a lost grant, a missing package.
- •Checks the deployed version of each environment, or the latest if nothing is deployed.
- •No AI is used; a whole fleet takes seconds.
- •After the nightly check the workspace admins get one email, only when there is something to say: what is failing or vulnerable, what changed since yesterday, and fixes waiting for review.
Security advisories for app dependencies See which apps use a package with a known security hole, and the version that fixes it.
The health check also reads each app's dependencies and looks up the pinned versions in osv.dev, the open vulnerability database. An app on a version with a known hole is marked vulnerable in the inventory, with the advisory, how serious it is and the version that fixes it.
- •Reads pyproject.toml, environment.yml, requirements files and package.json (with its lock file).
- •Only pinned versions can be checked; a dependency resolved at deploy time is listed as not checked.
- •Only package names and versions are sent to osv.dev, never your code or data.
Fix in dev, reviewed before it goes live One click asks the agent to fix what the health check found, in a separate environment you review.
"Fix in dev" hands a failing or vulnerable app to the AI agent with the exact findings. It works in a fix environment cloned from production, never in someone's dev work in progress, saves its change as a version and checks the app again. Nothing goes live until a person promotes it, or approves the deploy request.
- •The agent only reads data while fixing (read-only SQL) and cannot deploy on its own.
- •Uses AI tokens, like any other agent turn.
Idle apps and how to retire them Apps nobody has opened for 60 days are flagged, with what it takes to retire them.
An idle badge marks every app nobody has opened for 60 days, and an "idle only" switch shows just those. For each, StreamGen shows what it takes to retire it. It never drops an app itself: the decision stays with you.
Bring existing apps in Copy the Streamlit apps you already have into StreamGen, next to the originals.
Under "Other Snowflake apps you can see", every app StreamGen doesn't manage yet has a "Bring into StreamGen" button. It copies the app next to the original, so the apps people built by hand, in Snowsight or anywhere else, come under the same roles, approvals and history as everything new. The original keeps running while people move over; its remaining viewers and credits show under the copy, and after 30 quiet days StreamGen shows how to retire it.
- •For Streamlit apps your Snowflake role owns.
- •The copy runs on the container runtime, Snowflake's default for new apps.
- •The copy gets a new name by default; it exists in Snowflake once you deploy it.
Hand apps over Give an app to a new owner when someone leaves.
An admin can open any app read-only and transfer it to a new owner, so an app doesn't become an orphan when the person who built it moves on.
Describe it. Watch it run.
Your analysts describe an app and watch it run on real data. StreamGen writes it, fixes it and deploys it to Snowflake.
An AI agent that builds the app Describe the app in plain English and the agent writes it, querying your schema as it goes.
Say what the app should do, or upload a screenshot of a report you already have. The agent explores your Snowflake schema, runs SQL to check its work and writes the app. Plan mode, edit mode and bypass mode decide how much it does before you look.
- •Runs on Cortex with the models your Snowflake account offers, so your data stays in Snowflake.
- •Web search too, where your Snowflake account allows it.
Live preview on your real data Watch the app run on your real data while it is being built.
The app runs next to the chat as it is written, on your real data, read-only and with a row cap. Change it by asking, or edit the code yourself.
Streamlit on either runtime Deploy to the container runtime (Snowflake's default) or the warehouse runtime, chosen per app.
Snowflake now creates new Streamlit apps on the container runtime, and the warehouse runtime stays supported. StreamGen deploys to either, on every plan, and writes the dependency file each needs.
- •Container runtime: PyPI packages through uv, compute pools, external access integrations.
- •Warehouse runtime: Snowflake's Anaconda channel and an environment.yml.
Web apps on Snowflake App Runtime Next.js web apps that query as each viewer, so your row access policies apply.
Beyond Streamlit, StreamGen builds Next.js web apps and deploys them to Snowflake App Runtime. An app can query as the person viewing it (caller's rights), so your row access policies apply to everyone who opens it, and StreamGen sets up the grants this needs when it deploys.
- •Offered only on Snowflake accounts that have App Runtime.
- •If StreamGen's role can't grant what is needed, the deploy still works and shows the SQL for an admin to run.
- •Apps use the same helper shape as Snowflake's own templates, so they stay ordinary Snowflake apps.
Fixes its own deploy errors When a deploy fails, StreamGen reads the error, fixes the code and tries again.
If a deploy fails, StreamGen reads Snowflake's error, fixes the code and redeploys. Most issues clear in one retry.
Templates and skills Start from a template, and teach the agent your own coding standards.
Start from templates for sales, analytics, data entry, predictions and more. Skills (SKILL.md files, built in, your own or imported from GitHub) give the agent your domain knowledge and coding standards on every build.
Scheduled reports Professional Reports on a schedule or a threshold, by email or webhook.
Run reports on a cron schedule or when a threshold is crossed, with cooldown periods, and deliver them by email or webhook.
Many builders, one set of rules.
Many builders, one set of rules: who can do what, what needs approval, which AI is allowed, and a record of every change.
Roles, groups and policies Who can build, who can only view, and what each group may touch.
Workspace roles, groups and policies decide who builds and who only views. Admins can open any app read-only.
Sharing, deploy approvals and change history Professional Share with a permission grid, ask for approval before a deploy, and see every change.
Share an app with a per-area permission grid, require an approval before anything is deployed, see who else is working on it, and keep a changelog of every change.
Review before production Professional Every request to deploy to production comes with a review of its code, queries, cost and sensitive data.
When someone asks to put a version into production, StreamGen reviews it before anyone approves: what breaks in the code, known vulnerabilities, the queries the app really ran in its test environment, full scans of big tables, what a visit costs on its warehouse, and the sensitive columns it reads that nothing masks. The approver sees what to look at first; approving stays a person's call.
- •Works from Snowflake's metadata (query history, EXPLAIN, masking policies and tags) with the owner's connection. It never reads the data itself.
- •Queries built while the app runs are covered too: they come from the app's own query history in its test environment, so open it there once before asking.
- •Sensitive columns: Snowflake's classification tags, your own tags, and personal-looking column names that nothing masks.
- •Not yet for App Runtime (Next.js) apps' query cost; their code and packages are reviewed.
The AI models you allow A model allowlist that covers every AI call StreamGen makes.
Choose which AI models StreamGen may use. The allowlist covers every AI call, in every workspace.
Audit log A record of who did what, for the people who have to answer for it.
An audit log records the actions taken in the workspace, alongside each app's own change history.
Versions and dev, test, prod Professional Every version kept and comparable; each app with its own dev, test and prod.
Every generation is a version linked to its chat: compare them, roll back in one step. Each app has its own environments, so a change is made in dev, checked, then promoted.
Single sign-on Professional SSO / SAML for your workspace; your own OIDC when you run StreamGen yourself.
Sign in with your company's identity provider. When StreamGen runs on your own network, it uses your own single sign-on (OIDC).
Everything above works today. For what's coming, and roughly when, see the roadmap.
Try it on a sample company
Two hours, no sign-up, no Snowflake account needed.