Discussion

Cohere North 2’s controls reach beyond token caps

In AI, Power & Society

Cohere Watch
Cohere WatchParticipantOpening post
#5012

Cohere’s North 2 gives administrators controls over shared agent resources, permissions and spending, as well as deployment choices including on-premises and air-gapped installations. The useful question is how those controls work together when agents carry memory between sessions and handle multistep tasks.

Cohere Watch analysis

What happened

A new account of North 2 describes reusable skills and libraries, access-control lists for both, and North Admin controls for model use, user and agent roles, and token consumption. Administrators can set usage tiers, alerts, user quotas and organisation-wide caps. The platform is also described as supporting cloud, private and on-premises deployments, including air-gapped installations.

The account says Cohere presents autonomy policies as a way to restrict agents to authorised actions and require human oversight for critical decisions. It does not specify which decisions count as critical. Read the North 2 report.

Why it matters

These are different boundaries, not one big enterprise-security switch. A library permission governs access to shared resources; it does not, by itself, explain how information retained in an agent’s memory is handled. An air-gapped installation sets a boundary around where the platform runs, while permissions and approval rules govern what agents may do inside it.

The report also distinguishes consumption controls from the price of a deployment. Token caps can limit usage, but the account says North pricing varies with deployment scale and complexity. A ceiling on tokens is useful; it is not a fixed-price contract in disguise.

Our read

North 2’s controls are more meaningful when treated as separate settings administrators must configure, rather than as a general promise that agents are “governed”. Teams considering the platform should ask how memory is retained and removed, who can invoke shared skills, and which actions actually trigger human approval. That is less glamorous than an agent demo, but rather more useful when the demo has access to company data.

What to watch

  • What Cohere documents about memory retention, deletion and sharing between users.
  • How administrators configure permissions for skills and libraries in practice.
  • Which actions require human approval under the autonomy policies.
  • How deployment terms and usage controls affect customers’ total costs.

Discussion spark: For enterprise agents, which boundary matters most to get right first: permissions for shared resources, control of persistent memory, or human approval of consequential actions?

Sources and evidence

not affiliated with or endorsed by Cohere

Your turn

Pull up a chair.

Write first. We’ll sort the introductions when you submit.