Cohere North 2 puts agent budgets next to agent permissions. Production needs both
North 2 adds memory, reusable skills and an admin layer with roles, model restrictions, token quotas and spend alerts, deployable down to air-gapped sites. PwC will help deliver it.
Listen to this article · 5 min
AI-generated narration of the full article.

Most agent platforms answer one governance question well: what is this agent allowed to do? Fewer answer the second question with the same seriousness: how much is it allowed to spend doing it? Cohere’s North 2, released on October 5, treats both as admin settings, and that is the right model for anyone running more than a handful of agents.
What Cohere released
North is Cohere’s agent platform. Version 2 adds, according to Cohere’s announcement:
- a redesigned agent harness for multi-step automations;
- Skills that agents can reuse, and shared Libraries of organizational knowledge;
- Memory, so agents keep context across sessions instead of starting cold;
- Applications: decks, dashboards, documents and lightweight apps built from natural language;
- Automations with templates, a visual workflow builder and real-time monitoring.
North stays model-agnostic: Cohere’s models or your own. It can run self-hosted, in a VPC, hybrid, on-premises or air-gapped. Current connectors include SharePoint, OneDrive, Outlook, Exchange, Slack, Jira, Linear, Notion and GitHub. Financial data connectors (PitchBook, Crunchbase, Daloopa, FiscalAI, S&P Global, FactSet) are listed as planned, not available. Cohere cites SOC 2 Type 2, ISO 27001 and ISO 42001; ask for the reports and certificate scope rather than relying on the list.
The admin layer, North Admin, is the part to study. It offers roles and permissions, model selection and usage restrictions by user or group, token spend monitoring and consumption tiers, user quotas and organization-wide caps, real-time activity analytics and alert thresholds before limits trigger.
On the same day, Cohere and PwC announced a global alliance that starts in Canada, pairing North with PwC’s risk, regulatory and transformation teams for search, research, decision support and task automation in private cloud, on-premises and air-gapped settings. No U.S. timing was given.
Two control planes for every agent
- Request from user or schedule
- Authority: role, model, data, tools
- Economics: quota, tier, cap
- Agent runs, memory and tools
- Spend and actions recorded
- Owner reviews alerts and limits
- Before: Authority: role, model, data, tools · Economics: quota, tier, cap
- During and after: Agent runs, memory and tools · Spend and actions recorded · Owner reviews alerts and limits
PlatformAuthority decision
Authority is familiar: roles, data access, tool access, which models a group may use. Economics is newer. A multi-step agent that loops, retries or reads large libraries can spend many times what a chat turn costs. We made this case in our analysis of AI spend guardrails: hard caps suit exploration, while production needs budgets with alerts and a decision about what happens at the limit. North’s alert thresholds before limits are the right primitive; the decision behind them is still yours. When an automation hits its cap at 2 a.m., does it stop, degrade to a cheaper model, or page someone?
Memory needs the rules of a data store
Cohere says agents now keep context across sessions. The announcement does not document where memory lives, how long it is kept, whether it is scoped per user or shared, or how it is deleted. In a self-hosted deployment, much of that is your configuration and your responsibility. As we argued in our guide to agent memory as enterprise data storage, memory is a new copy of business data and needs retention, access control and deletion like any other store. Get those answers from Cohere’s documentation before switching it on for agents that read HR or client files.
The Microsoft 365 question
Many enterprises will point North at SharePoint, OneDrive and Exchange first. The important test is whether an agent acting for a user sees only what that user can see in Microsoft 365, and whether sensitivity labels survive retrieval. The announcement lists the connectors but not their permission model. Check it with a test user who should not see a confidential site, before any production rollout.
What to do now
- Give every production agent a budget owner along with its business owner.
- Set quotas per agent and per group, with alerts before the cap and a written behavior at the cap.
- Restrict models by group, so expensive models are a deliberate choice.
- Document memory scope, retention and deletion before enabling Memory.
- Test connector permission trimming in Microsoft 365 with a restricted user.
- Treat planned connectors as roadmap, not as part of the business case.
The bottom line
North 2 is one more sign that agent platforms are becoming operating systems for fleets of agents. The useful part is not the agent builder; it is the admin layer that puts spending limits next to permissions. Use both, and make sure each has a named person who decides what happens when it trips.