Snowflake Tightens AI Agent Controls

Snowflake enhances its CoCo AI agent platform with new governance features for cost, access, and tool usage.

Diagram showing three layers of AI governance: query, team, and organization levels.
Visual TL;DR
AI Agent ConcernsDriver
From the article 9+ mentionsThe updates, detailed in a recent Snowflake blog post, aim to provide enterprises with granular control over how their AI agents operate, addressing concerns around cost, security, and data access.
Snowflake CoCo PlatformCore
Snowflake's existing AI agent platform where new governance features are being added
From the article 4 mentions(NYSE:SNOW) is rolling out a significant expansion of its governance capabilities for its AI agent platform, CoCo.
New Governance FeaturesCore
updates provide granular control over AI agent operations within organizations
From the article 4 mentionsThese new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls.
Cost ManagementContext
From the article 6 mentionsPer-user quotas for AI cost management are now generally available across all CoCo interfaces, including Snowsight, CLI, and Desktop.
Broader AI AdoptionOutcome
From the article 3 mentionsThese new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls.
Enhanced ControlEffect
administrators can set daily and monthly credit limits, automatically enforced by Snowflake
From the article 6 mentionsThis provides a centralized control point for AI model usage organization-wide.
Predictable AI CostsOutcome
prevents unexpected cost overruns from iterative refactoring of complex stored procedures
From the article 6 mentionsThe enhancements focus on three key areas: governing AI costs, grounding AI in enterprise context, and integrating trusted AI into existing workflows.
Contents(3)

Snowflake Inc. (NYSE:SNOW) is rolling out a significant expansion of its governance capabilities for its AI agent platform, CoCo. The updates, detailed in a recent Snowflake blog post, aim to provide enterprises with granular control over how their AI agents operate, addressing concerns around cost, security, and data access. These new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls.

The enhancements focus on three key areas: governing AI costs, grounding AI in enterprise context, and integrating trusted AI into existing workflows. Per-user quotas for AI cost management are now generally available across all CoCo interfaces, including Snowsight, CLI, and Desktop. Administrators can set daily and monthly credit limits per user, with Snowflake automatically enforcing these limits. This prevents unexpected cost overruns, such as a data engineer iteratively refactoring complex stored procedures, from becoming a surprise expense at month's end.

Layered Governance for AI Agents

Beyond cost, Snowflake is introducing three new capabilities that govern agent access and behavior. These operate across three distinct layers: query, team, and organization. At the organization level, administrators can define policies for which Model Context Protocol (MCP) servers users can connect to and which models are available. These policies are enforced consistently across all CoCo installations, and users cannot opt out of enforced settings. This provides a centralized control point for AI model usage organization-wide.

Team- or role-specific defaults are managed through agent profiles. These profiles can dictate default models, preinstalled skills, and tool access, allowing different teams, like data engineering or finance analytics, to operate with distinct CoCo configurations without individual setup. Role-based access control (RBAC) applies these profiles automatically. A critical addition is Restricted Session Scope (RSS), which is slated for general availability soon. RSS limits the SQL an agent can execute until an appropriate role is active in the session, directly addressing the 'blast radius' question by ensuring agents are not implicitly trusted with excessive permissions.

Cortex AI Gateway Enhances External Tool Access

The Snowflake Cortex AI Gateway, built on technology from Snowflake's Natoma acquisition, is central to governing how agents interact with external systems. This gateway connects agents to thousands of services like Jira, Slack, and Google Workspace. Administrators can now use the gateway to define specific policies at the tool-call level. This includes server-level allowlisting to determine which MCP servers are accessible, and tool-level policies to enable or disable specific tools, such as allowing read access to Salesforce data but disabling write operations.

Rate limits can be applied per server to prevent misconfigured agents from overwhelming external APIs. Furthermore, a comprehensive audit trail logs every tool call, recording who made the request, their permissions, whether it was allowed, and the outcome. This level of detail provides clear visibility for security reviews, which previously often led to CoCo being restricted to limited groups or manual approval processes. StartupHub.ai data shows that while Snowflake itself scores a 73/100 on our platform, the market for AI governance and orchestration tools like MCP, which Snowflake is building upon, is still developing, with MCP scoring 36/100 and having raised $20M in a Series A round in 2025. Competitors in adjacent spaces like Patreon (60/100) and HoneyBook (70/100) highlight the demand for integrated creator or business management tools.

Balancing Control and Productivity

These governance enhancements aim to strike a balance between enterprise security requirements and developer productivity. By automating policy enforcement and providing clear guardrails, Snowflake intends for administrators to feel confident opening CoCo broadly across their organizations. Builders, in turn, benefit from agents that automatically inherit these guardrails, reducing friction and the need for manual configuration or sandbox environments. Governed MCP connections and tool access will appear automatically, simplifying the developer experience.

The new controls map directly to questions security reviewers might ask: What is the AI agent allowed to access? How much will it cost? What actions can it perform? With per-user quotas, managed settings, RSS, and the Cortex AI Gateway, Snowflake provides concrete answers. This move positions Snowflake to compete more effectively in the enterprise AI platform space, where trust and control are paramount for widespread adoption. The focus on integrating AI into existing workflows, rather than requiring users to adapt to new environments, aligns with broader industry trends of making AI more accessible and less disruptive.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.