Cohere is going after two common enterprise agent problems with North 2, the new version of its enterprise agent platform. It adds user quotas, rate limits, organization-wide caps and a redesigned agent harness. According to Cohere, North 2 uses memory to keep an agent's context across sessions and gives teams a shared library of knowledge and assets to draw on. It also runs in the cloud, on premises or fully air-gapped.

VB Pulse's agentic orchestration tracker from July found that 21% of enterprises exercise only reactive monitoring of agent spend, with no real-time, programmatic way to stop an agent before a budget-breaking bill arrives. VB Pulse's agentic context layers tracker from July found that 68% of enterprises traced a confidently wrong agent answer to missing or inconsistent business context in the past six months.

Cohere first announced North in January 2025 as a secure workspace positioned to challenge Microsoft Copilot and Google Vertex AI. The new capabilities in North 2 reflect how vendors’ offerings and enterprises’ use of AI have changed over the past 21 months.

North 2 adds memory, controls and reusable agents

The release changes how teams build agents, share them across the organization and control how they run.

Harness. A redesigned orchestration system runs complex multi-step processes on its own, with humans kept in the loop for designated decisions. Users build agents and automations from simple prompts.

Skills and shared agents. Skills are reusable capabilities that agents call, so employees do not rebuild the same logic. Users can also create reusable agents and automations and share them across the organization.

Libraries and memory. Libraries hold shared knowledge and assets that anyone in the organization can draw on. Memory lets agents keep context across sessions instead of starting cold each time. Paul Teyssier, VP, Product AI at Cohere, told VentureBeat that memory lets context persist longer across sub-sessions and agents. He did not provide a figure for how much longer.

Automation. Teyssier said North 2 adds more granular controls over how automations are managed across an organization. He said the change is less about making a process repeatable than about adding enterprise-level controls and reporting as automations scale.

Models. North runs Cohere's models or models a customer already uses.

Admin controls. North Admin sets roles and permissions and controls which models are used where and by whom. Admins monitor activity in real time with detailed analytics and see usage down to the user and agent level, including token spend and limits. Flow control sets consumption tiers by request and token rates for users and groups, and alert thresholds warn teams before limits apply. North Admin integrates with existing identity and access management systems. Teyssier said usage can be broken down by model, user and department and exported into a customer's own analytics systems. 

Security. According to Cohere, guardrails scan prompts and responses for PII and detect prompt injection, while North Admin enforces them at the individual agent level. Autonomy policies limit agents to authorized actions and send critical decisions to a human. The company also cites continual security testing, including red-teaming and third-party vulnerability scanning, plus detailed logs of all changes and tools for monitoring service performance. North holds SOC 2 Type 2, ISO 27001 and ISO 42001 certifications.

In a statement provided by Cohere, Jacob Rideout, CTO of HiddenLayer, said his team's agent workflows pull untrusted data from sources including marketing, engineering and security operations.

"We only turned those workflows on once we could see and control what the agents were doing," Rideout said.

Cohere did not provide performance benchmarks for North 2. Teyssier said application releases are harder to benchmark than models and that Cohere is working on data it can share. 

Where North 2 sits in the market

In the July agentic orchestration survey, 61 of 107 respondents gave a single unambiguous answer to the primary-platform question. Among them, Microsoft led at 41%, followed by Anthropic's Claude platform at 28%, LangChain/LangGraph at 10%, and OpenAI at 7%. The sample is self-selected.

Microsoft, Anthropic and OpenAI have added spend controls of their own. Copilot Studio admins can set monthly consumption limits for each agent. ChatGPT Enterprise admins can set a workspace default, group limits and individual overrides. Claude Enterprise admins can set limits for the organization, groups and individual users. These controls govern usage within each provider's own platform.

Teyssier said North 2's model, harness, search and embedding components are interchangeable, which Cohere positions as a way to reduce lock-in.

Cohere does not publish pricing for North. In a statement provided to VentureBeat, the company said North is priced based on the scale and complexity of a customer's deployment, including infrastructure requirements, usage patterns, support and customization.

What this means for enterprises

In VB's July agentic orchestration survey, only 3% of respondents said none of their deployed agents were genuinely orchestrated workflows. For enterprises, the question is increasingly control and deployment. Security and permissioning limitations were the top risk of provider-controlled orchestration at 37%, followed by vendor lock-in at 23%. Fifty-three percent expect a hybrid control plane by the end of 2026.

Cohere is pitching North 2 on model portability, agent-level security controls and running wherever the data has to stay, from the cloud to on premises to air-gapped sites.