
Snowflake has made per-user AI credit quotas generally available for CoCo, its enterprise AI assistant. Three new governance layers—organization-wide policy, team-level profiles, and session scope restrictions—are coming soon.
A new Cortex AI Gateway lets administrators approve external tool access in advance and audit tool calls afterward.
These controls aim to let platform teams grant broader CoCo access while keeping security guardrails in place.
What happened
Snowflake is expanding governance controls for its CoCo AI assistant. Per-user daily and monthly AI credit quotas are now generally available across CoCo in Snowsight, CoCo CLI and CoCo Desktop; three additional layers—organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS)—are coming soon. A new Cortex AI Gateway (built on technology from Snowflake's Natoma acquisition) enforces governance on external tool connections through server allowlisting, tool-level policy, rate limits, and audit logging.
Why it matters
Before these controls, platform teams often confined CoCo to limited groups, sandboxes, or manual approval workflows to manage risk. The new controls map to specific security review questions: quotas make spend bounded and enforceable; managed settings ensure policy consistency across all surfaces; restricted session scope makes an agent's data reach explicit; and the AI Gateway logs external tool access. This allows administrators to approve broader access while developers inherit guardrails automatically, reducing friction without sacrificing oversight.
What to watch
MDM, agent profiles, and restricted session scope are generally available soon (timeline not specified). Per-user quotas are available today; administrators can set daily and monthly AI credit limits and monitor usage through SNOWFLAKE.ACCOUNT_USAGE. Tools by Cortex AI Gateway is in preview (PuPr soon). Organizations can define which MCP servers, models, and tool actions are available per user or team.
Ask the AI about this article →
In July, Snowflake introduced CoCo with three foundational governance ideas: controlling costs, grounding AI in enterprise context, and embedding trusted AI into existing workflows. Today's expansion addresses a central friction in enterprise AI adoption: how to grant developers broader access without exposing the organization to uncontrolled spend or unvetted external tool connections.
The per-user quota mechanism directly solves a common cost-management problem. A data engineer iterating on legacy stored procedures with dozens of prompts no longer appears as an unexplained cost spike; daily limits cap usage at an administrator-set threshold and reset predictably. This transforms cost governance from a month-end surprise into a bounded, enforceable constraint.
The three new governance layers operate at different scopes but share a common design: enforcement happens before a session starts, not through reactive monitoring. Organization-wide policy (MDM) enforces consistency across all CoCo surfaces; agent profiles apply role-based defaults so developers inherit the right model and skills without configuration; and restricted session scope constrains SQL execution to match the user's active role, answering the "blast radius" question explicitly. Together with the Cortex AI Gateway—which provides server allowlisting, tool-level policy, rate limits, and audit trails for external connections—these controls give security teams concrete answers to the questions they ask during approval workflows. The result is that administrators can confidently expand CoCo access beyond sandbox environments, while developers see governance as transparent infrastructure rather than friction.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
Thomson Reuters Corp. today launched Thomson, its first proprietary large language model, combining its legal…
Xiaomi is expanding its in-house semiconductor push from smartphones into AI acceleration and autonomous drivi…

Amazon told investors it now expects to spend $220 billion in 2026, which is $20 billion more than its prior c…

BMO Capital started coverage of AMD with an Outperform rating and a $550 price target

More than 500 seed- or venture-backed private companies have sold to other private, venture-backed companies s…

Cerebras has introduced its CS-4 AI accelerator, a rack-scale product that CEO Andrew Feldman calls the fastes…
