
Snowflake is rolling out enterprise governance controls for its CoCo AI assistant, starting with per-user credit quotas that are available immediately and three additional controls—organization-wide policy, role-based profiles, and SQL scope limits—coming soon.
These features let administrators set spending caps, approve which external systems agents can access, and maintain an audit trail, while builders get simplified setup because approved tools and models load automatically based on their role.
What happened
Snowflake made per-user AI credit quotas generally available across all CoCo surfaces (Snowsight, CLI, Desktop), and announced three additional governance controls coming soon: organization-wide policy enforcement (MDM), role-based agent profiles, and restricted session scope (RSS) that limits what SQL an agent can execute. The company also introduced Tools by Cortex AI Gateway to centralize and audit external tool access through Model Context Protocol (MCP) servers.
Why it matters
These controls let administrators set spending limits, restrict which external systems agents can reach, and audit all actions without requiring custom code or manual approvals—addressing the security and cost concerns that previously forced teams to sandbox CoCo or limit access. Builders benefit because governance can operate in the background: agent profiles auto-load the right model and skills by role, and approved MCP connections appear automatically, reducing friction while keeping risk bounded.
What to watch
Per-user quotas are available now; MDM, agent profiles, and restricted session scope are generally available soon (the company flags these as forward-looking statements subject to risks). Organizations can query usage details through SNOWFLAKE.ACCOUNT_USAGE or ask CoCo directly which users are consuming the most credits.
Ask the AI about this article →
Snowflake's expansion of CoCo governance reflects a shift in how enterprises approach AI assistants: moving from sandboxing or limiting access to defining clear, enforceable boundaries that let builders operate more freely. The July announcement established three pillars—cost governance, enterprise context, and workplace integration—and today's release operationalizes the first pillar (quotas, now live) while introducing structural controls around access and behavior (coming soon).
The architecture is layered: per-user quotas handle spend; organization-wide policies (MDM), agent profiles, and restricted session scope handle data access and permissions; and Tools by Cortex AI Gateway governs external tool calls. Each control maps to a specific security question an administrator or reviewer might ask. By enforcing these boundaries before a session starts rather than monitoring after the fact, Snowflake positions governance as a prerequisite, not a reaction. This design also reduces friction for builders: approved MCP servers appear automatically, role-based profiles pre-configure the agent, and developers no longer need to manually configure server URLs or manage credentials per service. The result is that governance operates invisibly in the normal case, surfacing only when a user approaches a boundary that would have required approval regardless.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Blackstone, NVIDIA, and several global financial institutions signed memorandums of understanding to develop l…

Nvidia reported Q1 FY27 revenue of $82 billion (up 85% year-over-year), with Data Center revenue at $75 billio…

Nvidia is in talks to potentially tie up with Rebellions, a Korean AI chip designer, according to a Friday rep…

Anthropic plans to "match or beat" the size of SpaceX's $75 billion IPO (or $86.2 billion including the over-a…

Pew Research released a study on Thursday finding that over one-third (35%) of English-language web pages publ…

The article argues that non-expert managers and consultants—people whose only exposure to AI comes from ChatGP…
