AIToday
Snowflake AI BlogPublished: Aug 19, 2026, 19:01 JST3 min read

Snowflake expands CoCo AI governance: quotas, access controls, tool policies now available

Snowflake expands CoCo AI governance: quotas, access controls, tool policies now available

Key takeaway

  • Snowflake is expanding AI governance for its CoCo platform by making per-user cost quotas generally available and introducing three new control layers—organization-wide policy, role-based agent profiles, and session scope restrictions—that let administrators enforce security boundaries while giving developers broader production access.

  • External tool connections now flow through a centralized gateway with server allowlisting, tool-level policies, rate limits, and audit trails, turning governance from a friction point into an enabler of safer, faster development.

3 Key Points

  1. What happened

    Snowflake has made per-user daily and monthly AI credit quotas generally available across CoCo (its AI agent built into Snowflake's platform), and is rolling out three new governance layers soon: organization-wide policy enforcement via Managed settings, team/role-based agent profiles, and Restricted Session Scope to limit what SQL an agent can execute. The company is also releasing Tools by Cortex AI Gateway to control which external systems (Jira, Slack, Google Workspace, internal APIs, etc.) agents can access.

  2. Why it matters

    Administrators now have concrete controls to answer security review questions—spend bounds, consistent policy across all surfaces (Snowsight, CLI, Desktop), explicit data reach limits, and auditable external tool access—without forcing teams into sandboxes or manual approval workflows. Builders gain access to production environments because guardrails are automatic and role-based; governance remains invisible in normal use.

  3. What to watch

    Per-user quotas are available now; Managed settings, agent profiles, Restricted Session Scope, and Tools by Cortex AI Gateway are generally available soon. Cost limits reset at daily and monthly cycle boundaries, and all usage is queryable through SNOWFLAKE.ACCOUNT_USAGE by user, model, and token type.

Ask the AI about this article →

Context & Analysis

Snowflake's expansion of CoCo governance reflects a shift in how enterprise AI platforms balance access with control. In July, the company had outlined three pillars—governing costs, grounding AI in enterprise context, and bringing AI into existing workflows—but cost management alone was insufficient for security reviews. The new layers address distinct pain points: per-user quotas make spend bounded and enforceable, Managed settings ensure policy consistency across three different interfaces (Snowsight, CLI, Desktop), Restricted Session Scope limits the data an agent can touch based on active roles, and Cortex AI Gateway (built on technology from Snowflake's Natoma acquisition) makes external tool access auditable and pre-approved.

The architecture is notable because each control operates at a different scope—query level, team level, organization level—and enforcement happens before a session starts rather than after the fact. This means administrators can answer specific security questions with concrete evidence: what did the user spend, what data could they reach, what external systems did they touch. For builders, the appeal is that governance becomes automatic and role-based; a developer opening a session inherits the right model, skills, and tool access without manual configuration, making the control layer invisible in normal use. The result is intended to expand access beyond sandboxes and manual approval workflows by making it easier for security teams to approve production environments.

FAQ

What happens when a user hits their AI credit limit?
When a user reaches their daily or monthly limit, their access is blocked automatically with no custom code, stored procedures, or manual intervention required. Access resets at the next cycle boundary.
Can users bypass organization-wide governance policies?
No. Managed settings push organization-wide policy to every CoCo installation, and users cannot opt out of an enforced setting. Policy applies consistently whether a developer launches CoCo in Snowsight, CoCo CLI, or CoCo Desktop.
How do external tool connections work now?
CoCo now connects to external systems (Jira, Slack, Google Workspace, internal APIs, etc.) through MCP servers via Tools by Cortex AI Gateway, a centralized gateway. Administrators can allowlist servers, disable individual tools, set rate limits per server, and maintain a comprehensive audit trail of all tool calls.
Snowflake AI BlogRead Original Article

Get AI news like this every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Next articleFlock's New AI Tool Identifies Drivers Without License Plates

The AI news that matters, in one minute each morning.

Sign up free