AIToday
Large Language ModelsAI Safety & AlignmentAI Business & IndustrySnowflake AI BlogPublished: Aug 23, 2026, 13:00 JST3 min read

Snowflake expands AI governance: quotas, access controls, tool approval

Snowflake expands AI governance: quotas, access controls, tool approval

Key takeaway

  • Snowflake has made per-user AI credit quotas generally available for CoCo, its enterprise AI assistant. Three new governance layers—organization-wide policy, team-level profiles, and session scope restrictions—are coming soon.

  • A new Cortex AI Gateway lets administrators approve external tool access in advance and audit tool calls afterward.

  • These controls aim to let platform teams grant broader CoCo access while keeping security guardrails in place.

3 Key Points

  1. What happened

    Snowflake is expanding governance controls for its CoCo AI assistant. Per-user daily and monthly AI credit quotas are now generally available across CoCo in Snowsight, CoCo CLI and CoCo Desktop; three additional layers—organization-wide policy (MDM), team-level agent profiles, and restricted session scope (RSS)—are coming soon. A new Cortex AI Gateway (built on technology from Snowflake's Natoma acquisition) enforces governance on external tool connections through server allowlisting, tool-level policy, rate limits, and audit logging.

  2. Why it matters

    Before these controls, platform teams often confined CoCo to limited groups, sandboxes, or manual approval workflows to manage risk. The new controls map to specific security review questions: quotas make spend bounded and enforceable; managed settings ensure policy consistency across all surfaces; restricted session scope makes an agent's data reach explicit; and the AI Gateway logs external tool access. This allows administrators to approve broader access while developers inherit guardrails automatically, reducing friction without sacrificing oversight.

  3. What to watch

    MDM, agent profiles, and restricted session scope are generally available soon (timeline not specified). Per-user quotas are available today; administrators can set daily and monthly AI credit limits and monitor usage through SNOWFLAKE.ACCOUNT_USAGE. Tools by Cortex AI Gateway is in preview (PuPr soon). Organizations can define which MCP servers, models, and tool actions are available per user or team.

Ask the AI about this article →

Context & Analysis

In July, Snowflake introduced CoCo with three foundational governance ideas: controlling costs, grounding AI in enterprise context, and embedding trusted AI into existing workflows. Today's expansion addresses a central friction in enterprise AI adoption: how to grant developers broader access without exposing the organization to uncontrolled spend or unvetted external tool connections.

The per-user quota mechanism directly solves a common cost-management problem. A data engineer iterating on legacy stored procedures with dozens of prompts no longer appears as an unexplained cost spike; daily limits cap usage at an administrator-set threshold and reset predictably. This transforms cost governance from a month-end surprise into a bounded, enforceable constraint.

The three new governance layers operate at different scopes but share a common design: enforcement happens before a session starts, not through reactive monitoring. Organization-wide policy (MDM) enforces consistency across all CoCo surfaces; agent profiles apply role-based defaults so developers inherit the right model and skills without configuration; and restricted session scope constrains SQL execution to match the user's active role, answering the "blast radius" question explicitly. Together with the Cortex AI Gateway—which provides server allowlisting, tool-level policy, rate limits, and audit trails for external connections—these controls give security teams concrete answers to the questions they ask during approval workflows. The result is that administrators can confidently expand CoCo access beyond sandbox environments, while developers see governance as transparent infrastructure rather than friction.

FAQ

What happens when a user reaches their AI credit limit?
Access is blocked automatically with no custom code, stored procedures, or manual intervention required. Access resets at the next cycle boundary (daily or monthly, evaluated independently).
Can users bypass the governance policies that administrators set?
No. Organization-wide policy (MDM) applies consistently across CoCo in Snowsight, CoCo CLI and CoCo Desktop, and users cannot opt out of an enforced setting. Managed settings also prevent users from configuring their own MCP servers.
How can administrators monitor AI credit usage?
Usage is fully queryable through SNOWFLAKE.ACCOUNT_USAGE with per-request detail by user, model and token type. Administrators can also ask CoCo directly 'Which users are consuming the most credits this month?' and receive an answer with the underlying data.
Snowflake AI BlogRead Original Article

Get the latest Large Language Models news every morning

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · takes 30 seconds · unsubscribe anytime

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleChess AI's queen sacrifice found in single attention head