
Snowflake expanded its CoCo AI assistant with new cost and access controls. Per-user daily and monthly credit quotas are now live.
Three additional governance layers—organization policy, team profiles, and session-scope limits—are coming soon.
These let security teams approve broader developer access while staying confident in risk boundaries.
What happened
Snowflake made per-user AI credit quotas generally available across CoCo (its enterprise AI assistant) and introduced three new governance layers set to launch soon: organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS). These controls let administrators set daily and monthly limits, define which external systems agents can reach, and constrain what SQL an agent can execute based on the user's role.
Why it matters
Before these controls, teams often restricted CoCo to limited groups or manual approval processes to manage risk, limiting productivity gains. Now administrators can write security-backed access policies—quotas make spend bounded, managed settings enforce policy consistently across all surfaces, RSS makes an agent's data reach explicit, and the Cortex AI Gateway logs and pre-approves external tool calls. Each directly answers a security reviewer's question about risk.
What to watch
The three new capabilities are generally available soon (exact date not specified). Per-user quotas are available today in Snowflake accounts; administrators can set limits via the "Cost controls for CoCo" documentation. External MCP (Model Context Protocol) tool access now flows through Tools by Cortex AI Gateway, built on technology from Snowflake's Natoma acquisition.
Ask the AI about this article →
Snowflake's July announcement of CoCo governance centered on three ideas: cost control, grounding AI in enterprise context, and bringing trusted AI to where work happens. This follow-up builds specifically on cost and access governance, recognizing a core tension in enterprise AI adoption: teams want to unlock developer productivity but security and platform teams need to limit risk exposure. Before these controls, the only way to manage both was to restrict CoCo's availability—confining it to sandboxes, limited user groups, or manual approval workflows—which defeated much of the productivity promise.
The new layered approach addresses this by making governance visible and queryable rather than reactive. Per-user quotas provide spend boundaries that update daily, preventing surprise line-item costs and removing the need for manual tracking. Organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS) each operate at a different scope and are enforced before a session starts, not audited afterward. Together with the Cortex AI Gateway—which brings managed, approved access to external systems like Jira, Slack, and Salesforce—administrators now have concrete, auditable answers to the security questions that have historically blocked broader CoCo rollout. The setup is designed to be invisible to developers in the normal case, surfacing only when a boundary is about to be crossed.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Thomson Reuters Corp. today launched Thomson, its first proprietary large language model, combining its legal…
Xiaomi is expanding its in-house semiconductor push from smartphones into AI acceleration and autonomous drivi…

Amazon told investors it now expects to spend $220 billion in 2026, which is $20 billion more than its prior c…

BMO Capital started coverage of AMD with an Outperform rating and a $550 price target

More than 500 seed- or venture-backed private companies have sold to other private, venture-backed companies s…

Cerebras has introduced its CS-4 AI accelerator, a rack-scale product that CEO Andrew Feldman calls the fastes…
