# Snowflake Tightens AI Agent Controls _Snowflake enhances its CoCo AI agent platform with new governance features for cost, access, and tool usage._ **Updated:** 2026-08-22 **Published:** 2026-08-18 **Source:** https://www.startuphub.ai/ai-news/artificial-intelligence/2026/snowflake-tightens-ai-agent-controls --- Snowflake Inc. (NYSE:SNOW) is rolling out a significant expansion of its governance capabilities for its AI agent platform, CoCo. The updates, detailed in a recent [Snowflake blog post](https://www.snowflake.com/content/snowflake-site/global/en/blog/governed-ai-enterprise-controls-snowflake-coco), aim to provide enterprises with granular control over how their AI agents operate, addressing concerns around cost, security, and data access. These new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls. AI Agent ConcernsDriver From the article 9+ mentionsThe updates, detailed in a recent Snowflake blog post, aim to provide enterprises with granular control over how their AI agents operate, addressing concerns around cost, security, and data access.Snowflake CoCo PlatformCoreSnowflake's existing AI agent platform where new governance features are being addedFrom the article 4 mentions(NYSE:SNOW) is rolling out a significant expansion of its governance capabilities for its AI agent platform, CoCo.New Governance FeaturesCoreupdates provide granular control over AI agent operations within organizationsFrom the article 4 mentionsThese new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls.Cost ManagementContextFrom the article 6 mentionsPer-user quotas for AI cost management are now generally available across all CoCo interfaces, including Snowsight, CLI, and Desktop.Broader AI AdoptionOutcomeFrom the article 3 mentionsThese new features are designed to allow broader adoption of AI tools within organizations by building trust through predictable controls.enablesEnhanced ControlEffectadministrators can set daily and monthly credit limits, automatically enforced by SnowflakeFrom the article 6 mentionsThis provides a centralized control point for AI model usage organization-wide.ensuresPredictable AI CostsOutcomeprevents unexpected cost overruns from iterative refactoring of complex stored proceduresFrom the article 6 mentionsThe enhancements focus on three key areas: governing AI costs, grounding AI in enterprise context, and integrating trusted AI into existing workflows. The enhancements focus on three key areas: governing AI costs, grounding AI in enterprise context, and integrating trusted AI into existing workflows. Per-user quotas for AI cost management are now generally available across all CoCo interfaces, including Snowsight, CLI, and Desktop. Administrators can set daily and monthly credit limits per user, with [Snowflake](https://www.snowflake.com/content/snowflake-site/global/en/blog/governed-ai-enterprise-controls-snowflake-coco) automatically enforcing these limits. This prevents unexpected cost overruns, such as a data engineer iteratively refactoring complex stored procedures, from becoming a surprise expense at month's end. ## Layered Governance for AI Agents Beyond cost, [Snowflake](https://www.snowflake.com/content/snowflake-site/global/en/blog/governed-ai-enterprise-controls-snowflake-coco) is introducing three new capabilities that govern agent access and behavior. These operate across three distinct layers: query, team, and organization. At the organization level, administrators can define policies for which Model Context Protocol (MCP) servers users can connect to and which models are available. These policies are enforced consistently across all CoCo installations, and users cannot opt out of enforced settings. This provides a centralized control point for AI model usage organization-wide. Team- or role-specific defaults are managed through agent profiles. These profiles can dictate default models, preinstalled skills, and tool access, allowing different teams, like data engineering or finance analytics, to operate with distinct CoCo configurations without individual setup. Role-based access control (RBAC) applies these profiles automatically. A critical addition is Restricted Session Scope (RSS), which is slated for general availability soon. RSS limits the SQL an agent can execute until an appropriate role is active in the session, directly addressing the 'blast radius' question by ensuring agents are not implicitly trusted with excessive permissions. ## Cortex AI Gateway Enhances External Tool Access The [Snowflake Cortex AI Gateway](https://www.snowflake.com/content/snowflake-site/global/en/blog/governed-ai-enterprise-controls-snowflake-coco), built on technology from Snowflake's Natoma acquisition, is central to governing how agents interact with external systems. This gateway connects agents to thousands of services like Jira, Slack, and Google Workspace. Administrators can now use the gateway to define specific policies at the tool-call level. This includes server-level allowlisting to determine which MCP servers are accessible, and tool-level policies to enable or disable specific tools, such as allowing read access to Salesforce data but disabling write operations. Rate limits can be applied per server to prevent misconfigured agents from overwhelming external APIs. Furthermore, a comprehensive audit trail logs every tool call, recording who made the request, their permissions, whether it was allowed, and the outcome. This level of detail provides clear visibility for security reviews, which previously often led to CoCo being restricted to limited groups or manual approval processes. StartupHub.ai data shows that while Snowflake itself scores a 73/100 on our platform, the market for AI governance and orchestration tools like MCP, which Snowflake is building upon, is still developing, with MCP scoring 36/100 and having raised $20M in a Series A round in 2025. Competitors in adjacent spaces like Patreon (60/100) and HoneyBook (70/100) highlight the demand for integrated creator or business management tools. ## Balancing Control and Productivity These governance enhancements aim to strike a balance between enterprise security requirements and developer productivity. By automating policy enforcement and providing clear guardrails, Snowflake intends for administrators to feel confident opening CoCo broadly across their organizations. Builders, in turn, benefit from agents that automatically inherit these guardrails, reducing friction and the need for manual configuration or sandbox environments. Governed MCP connections and tool access will appear automatically, simplifying the developer experience. The new controls map directly to questions security reviewers might ask: What is the AI agent allowed to access? How much will it cost? What actions can it perform? With per-user quotas, managed settings, RSS, and the Cortex AI Gateway, Snowflake provides concrete answers. This move positions Snowflake to compete more effectively in the enterprise AI platform space, where trust and control are paramount for widespread adoption. The focus on integrating AI into existing workflows, rather than requiring users to adapt to new environments, aligns with broader industry trends of making AI more accessible and less disruptive. --- Original analysis from [startuphub.ai](https://www.startuphub.ai), the #1 AI startup directory.