Enterprise AI agents & governance

Cohere North 2: a practical control plane for enterprise AI agents

•Make Better Editorial

Cohere’s North 2 adds agent memory, reusable skills, granular access controls, token budgets and private deployment. Here’s the enterprise checklist behind the launch.

Cohere launched North 2 on October 5 as a major upgrade to its enterprise agent platform. The headline features are a redesigned agent harness, cross-session memory, reusable skills and libraries, richer automations, and broader connectors. But the more useful story for teams moving agents into production is the control layer around those capabilities: identity and permissions, autonomy policies, observability, deployment choice, and explicit controls over token consumption.

What changed in North 2

North 2 lets teams build reusable agents and automations that can be shared across an organization. Memory preserves context between sessions; skills package repeatable capabilities; libraries provide shared knowledge and assets; and connectors link the platform to systems including Slack, SharePoint, OneDrive, Outlook, Jira, Linear, Notion and GitHub. Cohere also says the platform is model agnostic, so organizations can use Cohere models or bring other models into the same operating environment.

Why governance is the more important part

Make Better analysis

As agents move from answering questions to taking actions, model quality stops being the only production constraint. A capable agent can still be a bad enterprise system if nobody can bound its permissions, understand what it changed, control its recurring cost, or keep sensitive data in the required environment. North 2 is useful as a concrete example of the control-plane requirements teams should evaluate around any enterprise agent stack—not as proof that one vendor has solved agent governance.

Six controls to require before scaling agents

  1. Identity and access: map every agent to explicit users, groups and permissions instead of giving broad shared credentials.
  2. Autonomy boundaries: define which actions an agent may take independently and which require human approval.
  3. Spend controls: set request or token-rate limits, user quotas and organization-wide caps before usage scales.
  4. Observability: keep logs and monitoring detailed enough to reconstruct what an agent did, which tools it used and where failures occurred.
  5. Memory and data scope: decide what context may persist across sessions, who can access shared knowledge and how sensitive information is separated.
  6. Deployment sovereignty: match cloud, VPC, on-premises or air-gapped deployment to regulatory, security and data-residency requirements.

Where the evidence stops

Important limitation

Cohere’s announcement documents product capabilities, but it does not provide independent comparative evidence that North 2 produces better ROI, lower total cost or more reliable agents than competing platforms. Those outcomes depend on workload design, model choice, infrastructure, permissions and operational discipline. Treat the launch as a feature and architecture signal, then validate economics and reliability on your own workflows.

For a pilot, measure more than task success. Track human interventions, permission failures, token consumption per completed outcome, latency, tool errors and the percentage of runs that can be reconstructed from logs. Those metrics reveal whether an agent is becoming a governable operating system for work or simply a more capable demo.

Bottom line

North 2’s most relevant lesson is that production agents need a control plane around intelligence. Memory and orchestration make agents more capable; permissions, budgets, observability and deployment controls make them deployable. Use that distinction as a checklist when evaluating any enterprise agent platform.

Sources & useful resources