As AI coding agents move from experimental side projects into everyday engineering workflows, the question facing every enterprise is no longer “Can the agent write useful code?” but “Can we let every builder use it safely and affordably?” Snowflake’s answer is a set of native governance controls now available for CoCo (Cortex Code): per-user quotas, layered configuration and agent profiles, and Restricted Session Scope. Together they give platform, security, and AI leaders the levers needed to scale agentic development without sacrificing cost discipline or least-privilege principles.
These controls matter because CoCo inherits the user’s identity and, by default, the privileges attached to that identity. Without additional guardrails, a powerful agent acting on behalf of a highly privileged user can perform actions far broader than the task requires. The new capabilities introduce explicit ceilings on both spend and privilege, making governed AI practical for every builder.
Core Governance Capabilities
Per-User Quotas and Cost Controls
- Set daily and monthly credit limits per user (or tag-filtered groups of users).
- Receive notifications as users approach thresholds.
- Optionally block further AI usage automatically when a limit is reached; blocks release when the cycle resets or the limit is raised.
- Cover CoCo across CLI, Desktop, and Snowsight surfaces, and optionally other AI features.
- Complementary daily estimated-credit limits can be applied per surface for simpler use cases.
Configuration and Agent Profiles
Administrators can define consistent CoCo experiences—model defaults, tool access, and behavioral settings—and roll them out centrally. This reduces configuration drift and ensures that teams operate under approved patterns rather than ad-hoc individual setups.
Restricted Session Scope (RSS)
Restricted Session Scope introduces a privilege ceiling that limits what an agent can do on behalf of a user without requiring changes to the underlying role hierarchy. Defined in a structured YAML-style document, an RSS can:
- Allow only specific privilege categories (for example, data read across the account, data write only in designated sandbox databases).
- Block powerful roles such as ACCOUNTADMIN, SYSADMIN, or SECURITYADMIN from being assumed by the agent.
- Disable role switching if desired.
Predefined scopes (such as a data-read-only scope) and custom scopes give organizations flexible, reusable guardrails. The agent still acts as the user, but only within the declared ceiling.
Why These Controls Enable Safe Scale
Earlier generations of coding assistants either ran entirely outside the data platform (creating governance and data-exfiltration concerns) or inherited full user privileges with no additional throttle. CoCo’s new controls address both dimensions:
- Cost predictability — Quotas turn open-ended token consumption into managed, observable spend. Finance and platform teams gain early warning and automatic enforcement.
- Least privilege for agents — Restricted Session Scope lets organizations keep human role designs intact while ensuring agents cannot exercise the full breadth of those roles.
- Consistent experience — Profiles and centralized settings reduce the risk that individual developers operate with overly permissive or non-compliant configurations.
The result is an environment in which every builder can use a powerful, data-aware coding agent while security and platform teams retain clear, enforceable boundaries.
Comparisons to Earlier CoCo Capabilities and External Agents
In earlier CoCo releases the primary governance model was the same role-based access control already used for human users, supplemented by basic surface-level enablement. That model was necessary but insufficient once agent usage became widespread and continuous.
External coding agents (GitHub Copilot, Cursor, Claude Code, and others) typically rely on separate identity, secret, and policy systems. They may offer organizational policies or spend controls, yet they rarely inherit live Snowflake RBAC, tag-based policies, or data-movement rules. CoCo’s advantage is that governance remains inside the same control plane that already protects the data the agent is asked to work with.
Restricted Session Scope further differentiates CoCo by providing a native, declarative privilege ceiling specifically designed for agent sessions—something most external tools cannot express against Snowflake’s authorization model.
Implications for AI Risk Management
Security and Platform Teams
- Agents no longer automatically receive the full power of the invoking user.
- Spend becomes visible and controllable at the individual level before it becomes a surprise.
- Audit trails can distinguish human actions from agent actions operating under an RSS.
AI and Engineering Leaders
- Developers retain a high-productivity experience while operating inside approved guardrails.
- Organizations can expand CoCo adoption with clearer answers to risk and compliance questions.
- Cost allocation and chargeback become feasible at user or team granularity.
Actionable Insights
- Define a small set of Restricted Session Scopes that match common agent use cases (read-only analysis, sandbox development, controlled production writes).
- Apply per-user quotas first in observation mode, then enable enforcement once baselines are understood.
- Use configuration profiles to standardize model selection, tool access, and safety settings across teams.
- Combine RSS with existing data-movement policies and tag-based controls for defense in depth.
- Educate developers on the difference between their full human privileges and the agent’s restricted ceiling.
- Monitor quota utilization and blocked-session metrics as leading indicators of adoption and risk.
What This Signals for Responsible Agentic Adoption in 2026
The arrival of quotas, profiles, and Restricted Session Scope in CoCo reflects a broader industry recognition: agentic tools will only reach production scale when governance is native, granular, and low-friction. Platforms that treat cost control and privilege limitation as first-class features—rather than afterthoughts—will earn the trust required for widespread builder adoption.
Through the remainder of 2026, expect continued refinement of these controls, tighter integration with Cortex AI Gateway and organization-level identity features, and growing best-practice patterns for “agent privilege ceilings.” Organizations that implement them early will be able to offer powerful AI coding assistance to every builder while keeping security, compliance, and finance stakeholders confident.
Conclusion
Snowflake CoCo’s enterprise governance controls—per-user quotas, configuration profiles, and Restricted Session Scope—make governed agentic coding practical at scale. By placing clear ceilings on both spend and privilege, they allow organizations to put a data-aware AI coding agent in the hands of every builder without surrendering cost discipline or least-privilege principles.
For security, platform, and AI leaders, the path forward is concrete: adopt quotas to tame spend, define restricted scopes that match real agent tasks, and standardize experiences through profiles. When these controls are in place, “AI for every builder” ceases to be a slogan and becomes an operable, responsible reality inside the AI Data Cloud.
