Intent-driven Governance: Protect Sensitive Data at Scale
| Source: Snowflake Blog
Tags: Snowflake, CoCo, data governance, PII protection, Horizon Catalog, data masking, enterprise AI
Snowflake's Intent-Driven Governance enters public preview, letting organizations describe data protection needs in plain English while its CoCo AI handles column classification, masking policy deployment, and drift monitoring — bridging data governors, domain leads, and platform admins through an explicit human-approval workflow.
Details
Snowflake launched Intent-Driven Governance in public preview, targeting a structural problem in enterprise data compliance: organizations managing thousands of sensitive data objects across internal policies, regional regulations, and industry mandates rarely have a unified workflow to connect the people who need to act on them.\n\nThe feature runs inside Snowflake CoCo, the company's AI assistant. Users describe protection intent in plain English — for example, 'protect PII in our CLINICAL databases' — and CoCo triggers a pipeline that classifies sensitive columns, proposes masking policies, and monitors for policy drift over time. Every enforcement step requires explicit human approval, keeping humans in the loop and preventing fully autonomous changes to production data controls.\n\nThe organizational gap Snowflake is targeting is real: data domain leads understand what makes their data sensitive, data governors define enterprise-wide policy, and platform admins hold the privileges to deploy SQL-level controls. Previously these groups lacked a shared workflow. Intent-Driven Governance creates a collaborative approval chain across all three roles.\n\nSnowflake positions this as the third pillar of its Horizon Catalog platform, alongside interoperability and semantic context. The company specifically calls out AI agent access as a new risk vector — not just human misuse — underscoring why automated, continuous governance tooling is becoming a priority for data platforms in the agentic AI era.