DATA OPS
Flag runaway Snowflake queries and page the author
Checks Snowflake every few minutes for in-flight or just-finished queries that burned more credits than a threshold.
How it runs
The automated pipeline, trigger to output.
- TriggerEvery 5 minutes schedule
- ActionRead recent QUERY_HISTORY and estimate creditsSnowflake
- LogicFilter queries over credit threshold, drop already-alerted
- ActionOpen PagerDuty incident per offenderPagerDuty
- OutputDM the query author on SlackSlack
What it does
Polls Snowflake's `QUERY_HISTORY` on a short interval for queries whose credits-consumed (derived from elapsed time and warehouse size) exceed a configurable threshold. For each offender it opens a PagerDuty incident tagged with the author and warehouse, and sends the author a direct Slack message with the query ID and cost.
When to use it
Use this for warehouses where a single accidental cross-join or unbounded scan can cost hundreds of dollars in minutes. Near-real-time detection lets on-call cancel or coach before the credits are gone, rather than discovering it on next month's invoice.
How it works
- 1A scheduled trigger runs every 5 minutes.
- 2A Snowflake action selects recent rows from `QUERY_HISTORY` and computes estimated credits per query.
- 3A logic step filters to queries above the credit threshold and de-duplicates ones already alerted on.
- 4A PagerDuty action opens an incident per offending query, keyed to avoid duplicates.
- 5A Slack action DMs the query author with the cost and a link to the query profile.
Set it up
What you configure once, before turning it on.
- 1Connect SnowflakeWarehouses, queries, shares.
- 2Connect PagerDutyIncidents, on-call, escalations.
- 3Connect SlackChannels, DMs, threads, mentions.
- 4Set each agent's modelWe leave models unset so you pick the tier — fast + cheap, or top-quality.
- 5Tune it to your dataEdit the prompts, filters, and field mappings so it matches how your team works.
- 6Test, then turn it onRun once against a sample, confirm the output, then enable the trigger.
More Data Ops workflows
Weekly BigQuery Cost Trend Sheet and Exec Digest
Compiles week-over-week BigQuery scheduled-query cost by owner and dataset into a Google Sheet with trend columns.
Daily BigQuery Scheduled-Query Cost Attribution to Owners
Each morning, totals the prior day's on-demand bytes-billed per scheduled query, maps each query to its owner from a label, and posts a per-owner cost leaderboard to Slack.
BigQuery Per-Team Budget Breach Alert to PagerDuty
Tracks month-to-date BigQuery scheduled-query spend per team and, when a team crosses its monthly budget, pages the team's on-call in PagerDuty and snapshots the spend breakdown…
dbt source freshness watcher with severity-routed alerts
Checks Snowflake loaded-at timestamps against each dbt source's freshness SLA, then routes warnings to Slack and hard breaches to a PagerDuty incident so stale data never…
dbt orphan model detector with Linear cleanup tickets
Scans your dbt manifest for models that no other model, exposure, or BI tool consumes.
Raw Sensor Telemetry Archive to BigQuery
Captures every incoming building sensor reading via webhook, normalizes the payload into a consistent schema.
Run it inside a business
This workflow drops into a full company template. Import the org, and this is one of the playbooks its agents run.

Run this workflow in your colony.
14-day trial. No DevOps. No Sales call. Provisioned in under a minute.
