AIToday
Large Language ModelsAI Safety & AlignmentAI Business & IndustrySnowflake AI BlogPublished: Aug 23, 2026, 16:03 JST3 min read

Snowflake expands CoCo AI guardrails to costs, access, and external tools

Snowflake expands CoCo AI guardrails to costs, access, and external tools

Key takeaway

  • Snowflake expanded its CoCo AI assistant with new cost and access controls. Per-user daily and monthly credit quotas are now live.

  • Three additional governance layers—organization policy, team profiles, and session-scope limits—are coming soon.

  • These let security teams approve broader developer access while staying confident in risk boundaries.

3 Key Points

  1. What happened

    Snowflake made per-user AI credit quotas generally available across CoCo (its enterprise AI assistant) and introduced three new governance layers set to launch soon: organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS). These controls let administrators set daily and monthly limits, define which external systems agents can reach, and constrain what SQL an agent can execute based on the user's role.

  2. Why it matters

    Before these controls, teams often restricted CoCo to limited groups or manual approval processes to manage risk, limiting productivity gains. Now administrators can write security-backed access policies—quotas make spend bounded, managed settings enforce policy consistently across all surfaces, RSS makes an agent's data reach explicit, and the Cortex AI Gateway logs and pre-approves external tool calls. Each directly answers a security reviewer's question about risk.

  3. What to watch

    The three new capabilities are generally available soon (exact date not specified). Per-user quotas are available today in Snowflake accounts; administrators can set limits via the "Cost controls for CoCo" documentation. External MCP (Model Context Protocol) tool access now flows through Tools by Cortex AI Gateway, built on technology from Snowflake's Natoma acquisition.

Ask the AI about this article →

Context & Analysis

Snowflake's July announcement of CoCo governance centered on three ideas: cost control, grounding AI in enterprise context, and bringing trusted AI to where work happens. This follow-up builds specifically on cost and access governance, recognizing a core tension in enterprise AI adoption: teams want to unlock developer productivity but security and platform teams need to limit risk exposure. Before these controls, the only way to manage both was to restrict CoCo's availability—confining it to sandboxes, limited user groups, or manual approval workflows—which defeated much of the productivity promise.

The new layered approach addresses this by making governance visible and queryable rather than reactive. Per-user quotas provide spend boundaries that update daily, preventing surprise line-item costs and removing the need for manual tracking. Organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS) each operate at a different scope and are enforced before a session starts, not audited afterward. Together with the Cortex AI Gateway—which brings managed, approved access to external systems like Jira, Slack, and Salesforce—administrators now have concrete, auditable answers to the security questions that have historically blocked broader CoCo rollout. The setup is designed to be invisible to developers in the normal case, surfacing only when a boundary is about to be crossed.

FAQ

What happens when a user hits their daily or monthly quota?
Access is blocked automatically with no custom code or manual intervention needed. Access resets at the next cycle boundary. Daily and monthly limits are evaluated independently.
How do administrators control which external systems CoCo can connect to?
Administrators use organization-wide policy (MDM) to define which Model Context Protocol (MCP) servers users can connect to, and they can disable specific tools within a server without disabling the entire server. Tool calls are logged and pre-approved through the Cortex AI Gateway.
Do developers have to configure anything to get the new governance controls?
No. Agent profiles are applied automatically by role, so the right model and skills are already loaded when a developer opens a session. Governed MCP connections appear in the client automatically once an administrator enables them.
Snowflake AI BlogRead Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleNebius raises $5B in convertible notes