Governed AI for Every Builder: Enterprise Controls in Snowflake CoCo

| Source: Snowflake Blog

Tags: Snowflake, CoCo, enterprise AI, AI governance, MCP, cost management

Snowflake CoCo now has per-user AI credit quotas in GA, with three more enterprise controls coming soon: MDM-pushed organization-wide policy, team-level MCP server restrictions, and tool action approval workflows — letting IT teams set guardrails without blocking builders.

Details

Snowflake's CoCo (coding copilot) has expanded beyond cost management into full enterprise governance. Per-user quotas are now generally available across CoCo in Snowsight, CoCo CLI, and CoCo Desktop — administrators set daily and monthly AI credit limits that Snowflake enforces automatically, with resets at cycle boundaries and full usage queryable through SNOWFLAKE.ACCOUNT_USAGE at per-request detail. Three additional controls are coming GA soon. MDM (Mobile Device Management) integration pushes organization-wide policy to every CoCo installation, governing which MCP servers users can connect to, which models are available, and which tool actions require approval before execution. Team-level controls enable per-group restrictions rather than blanket organization-wide limits. At the individual level, administrators can require human-in-the-loop approval workflows before agents take specific actions. For Snowflake customers, these controls address a real deployment friction point: IT and security teams need guardrails before opening CoCo broadly, but overly rigid restrictions defeat the productivity benefit. The governance-as-background-infrastructure framing — builders don't change workflows, guardrails apply automatically — is sound design. This is a vendor-authored blog post, and three of the four features are still "GA soon" rather than available today.