
Snowflake has expanded governance capabilities for CoCo, its enterprise AI assistant, by releasing per-user spending quotas and introducing three new access-control layers that let administrators define what data the AI can reach, which external systems it can access, and which models and tools are available by role.
The goal is to give security teams the visibility and control they need to approve broader developer access without the friction of manual approval workflows—making governance work in the background so teams can move faster.
What happened
Snowflake has made per-user AI credit quotas generally available across CoCo (its AI assistant) and introduced three new governance layers—organization-wide policy through MDM, team-level agent profiles, and restricted session scope (RSS)—all designed to let administrators set limits on AI spend, data access, and external tool connections.
Why it matters
These controls address a core tension in enterprise AI: security teams need visibility to approve broad access, while developers need freedom to work. By enforcing guardrails automatically—without custom code or manual approval per request—organizations can expand CoCo use beyond sandbox environments and limited groups without compromising security or auditability.
What to watch
MDM, agent profiles, and RSS are generally available soon (not yet live); per-user quotas are available now. Tool access is governed through Cortex AI Gateway, which logs every external tool call (Jira, Slack, Google Workspace, etc.) for audit and allows administrators to allowlist servers and disable individual tools without losing entire integrations.
Ask the AI about this article →
Snowflake's expansion of CoCo governance reflects a maturing approach to enterprise AI adoption. In July, the company outlined three pillars—cost management, enterprise context, and integration with existing workflows—and today's announcement operationalizes the first two with concrete controls. The challenge it addresses is real: many organizations confine AI tools to sandboxes or limited user groups not because the technology is immature, but because security and platform teams lack the granular visibility and enforcement mechanisms needed to approve broader access responsibly.
The three-layer governance architecture—organizational policy (MDM), team-level defaults (agent profiles), and session-level constraints (restricted session scope)—reflects a shift from reactive monitoring to preventive enforcement. By enforcing quotas and access boundaries before a session starts rather than auditing usage after the fact, administrators can answer the questions security reviews typically demand: what will the AI cost, what data can it access, and what external systems can it reach? Each control maps to a different scope and risk surface, allowing organizations to tune governance granularity without adding friction to the developer experience. The integration of Tools by Cortex AI Gateway (built on Snowflake's Natoma acquisition) centralizes MCP governance, making it possible to disable a single tool or rate-limit a server without disabling entire integrations—a practical necessity in complex enterprise environments where wholesale blocks are often infeasible.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.