Cohere North 2 Gives Agents Memory—and Admins Token Caps

|Author: QUASA Editorial Team|5 min read| 3
Cohere North 2 Gives Agents Memory—and Admins Token Caps

In its October 5, 2026 launch announcement, Cohere introduced North 2 with agents that retain context across sessions and North Admin controls for token consumption. The update brings reusable skills, shared libraries, automations and a redesigned system for coordinating multistep tasks into the enterprise platform. Administrators can see usage by user and agent, set request and token-rate tiers, and apply user quotas and organization-wide caps.

Permissions are part of the change. The Register’s report describes access-control lists for libraries and skills, as well as cloud, on-premises and air-gapped deployment options. These controls address different questions: what an agent can carry forward, which shared resources it can reach, how much it can consume and where it runs.

The need for visibility is concrete. In VentureBeat’s reporting, HiddenLayer CTO Jacob Rideout said his team needed to “see and control what the agents were doing” before enabling workflows; the report also says North pricing varies with deployment scale and complexity. A token cap therefore gives an administrator a consumption boundary, while the customer’s total cost depends on the deployment.

North 2’s controls, one boundary at a time

Some North 2 capabilities are described in the product announcement and also covered by independent publications; others are presented mainly as vendor security claims. The distinction matters because a listed control still needs a defined scope and configuration before it governs an agent’s work.

  • Memory — vendor-described and independently reported. Agents keep context across sessions, allowing a later interaction to draw on earlier work. That creates a retained store of context to govern. The public feature description does not state a retention period, a deletion procedure or precise rules for sharing remembered context between users.
  • Skills — vendor-described and independently reported. These are reusable capabilities an agent can call instead of reconstructing the same task logic each time. Teams can share agents and automations across the organization, but reuse and authorization are separate decisions: making a skill available does not, by itself, establish who should be allowed to invoke it.
  • Libraries — vendor-described and independently reported. Libraries hold shared knowledge and assets for agents to use. They can provide a common reference base across teams. An access-control list sets a boundary around who may reach a particular library; the contents and the people granted access still determine what information an agent can draw on.
  • Access control — independently described functionality. Administrators can assign access-control lists to libraries and skills. North Admin also provides roles and permissions, model-use controls and integration with existing identity and access management systems. These are identifiable points of configuration, rather than a blanket assurance about permissions in every connected application or data source.
  • Token budgets — vendor-described and independently reported. North Admin provides token-use visibility down to users and agents. Flow control defines consumption tiers using request and token rates for users and groups; alerts can warn before limits apply, and organization-wide caps constrain aggregate usage. The unit being limited is consumption, so a cap does not amount to a universal fixed-price contract.
  • Deployment location — vendor-described and independently reported. North 2 is offered for cloud, private and on-premises environments, including air-gapped installations. Choosing one of those environments sets an infrastructure boundary. It does not determine the permissions, memory rules or approval requirements configured within that environment.
  • Human oversight — vendor-described. Autonomy policies are presented as a way to restrict agents to authorized actions and seek human oversight for critical decisions or actions. The product description does not prescribe which decisions an organization must classify as critical. That classification governs where a workflow pauses for a person.

Persistent context changes the access question

Memory is useful because an agent can continue work without having every relevant detail supplied again. It also changes the duration of the access question: information available during one interaction may influence a later one. Library and skill permissions govern shared resources, while memory governs context carried between sessions. Treating those as distinct boundaries makes it easier to see why an access-control list for a library cannot answer every question about remembered information.

North 2’s redesigned orchestration system can run multistep work, and its automations can be shared across an organization. Shared execution increases the value of reusable skills, but it also makes the identity behind an action consequential. Roles, model permissions and approval points have to be assigned to the people and agents involved; the platform’s feature list alone does not specify those assignments.

Token limits make usage accountable

North Admin’s granular visibility gives administrators a way to associate consumption with users and agents instead of seeing only an undifferentiated total. Request-rate and token-rate tiers can limit how quickly a user or group consumes capacity. Alerts and an organization-wide cap address a different problem: they expose rising usage and place a ceiling on consumption across the deployment.

That distinction matters for purchasing. Infrastructure requirements, support, customization and usage patterns can affect a North contract, so limiting tokens does not necessarily limit every item on the bill. The documented controls give administrators ownership of model consumption; the agreed price and deployment terms determine how that consumption translates into cost.

Deployment and guardrails set separate boundaries

An air-gapped or on-premises installation addresses where the platform runs and how it connects to outside systems. North Admin’s agent-level guardrails, roles and autonomy policies address behavior within the chosen environment. Private deployment can be an important isolation choice, but its location does not decide which agent may use a skill, which user may open a library or when a person must approve an action.

North 2’s enterprise-security positioning is broader than the individual controls described publicly. The concrete administrative gain is the ability to assign boundaries for shared assets, model access, consumption and deployment. For an organization using persistent memory, the remaining consequential decision is how long that context is kept and how it is removed once it is no longer needed.

Also read:

Share:

Subscribe to our newsletter

Get the latest Web3, AI, and crypto news delivered straight to your inbox.

0