Immuta

Type: company (data access governance / security vendor) Sector: Data access control, security and monitoring software First seen: 2026-06-21 Last updated: 2026-07-10

Created 2026-06-21 from S-2026-06-02-immuta-snowflake-agentic-access (daily vendor-intelligence scan). Single-vendor-source so far — capability claims are Immuta’s own and not independently verified. Updated 2026-07-10 based on S-2026-06-15-immuta-databricks-agentic-access (full capture of the 15 June Databricks announcement previously only flagged in passing: four capabilities GA, including the Comply App for Unity Catalog).

Snapshot

Immuta is a data access governance and security vendor focused on policy-based access control, masking and monitoring across cloud data platforms (Snowflake, Databricks, others). It is relevant to the wiki as the access-control layer for AI: at Snowflake Summit 26 it moved to govern AI-agent data access with least-privilege, on-behalf-of controls — directly relevant to GDPR, DORA and BCBS 239 access expectations for EU/UK FS [S-2026-06-02-immuta-snowflake-agentic-access].

Positions / Claims they advance

  • Launched Immuta Agentic Data Access (powered by Snowflake Cortex AI): enforces access boundaries at the session level and “vends a unique, temporary role scoped to the user the agent is acting on-behalf-of,” so an agent cannot exceed the authorising user’s permissions [S-2026-06-02-immuta-snowflake-agentic-access].
  • Agent Principal Context governs outbound agentic access to data outside Snowflake [S-2026-06-02-immuta-snowflake-agentic-access].
  • The “Comply” app for Snowflake Horizon Catalog offers a natural-language interface for compliance/security teams to interrogate permissions in plain English [S-2026-06-02-immuta-snowflake-agentic-access].
  • Expanded the same model to Databricks (15 June, GA to all Databricks customers): Agentic Data Access for Databricks bounds each agent session to the invoking user’s entitlements at table/row/column/cell level with “a full audit trail maintained inside Unity Catalog” [S-2026-06-15-immuta-databricks-agentic-access].
  • Intent-Driven Access Control: task-scoped permissions via Unity Catalog RBAC/ABAC, auto-expiring when the task ends — framed by Immuta as “ensuring continuous compliance with GDPR … and data sovereignty requirements” [vendor marketing claim — S-2026-06-15-immuta-databricks-agentic-access].
  • The “Comply” App now also covers Databricks Unity Catalog: natural-language compliance auditing over entitlements (“Which AI agents have access to financial tables?”) producing what Immuta calls “instant, audit-ready results” [S-2026-06-15-immuta-databricks-agentic-access].
  • Group-Based Permission Assignment: Group-to-Object ABAC architecture claimed to bypass Databricks’ principal-to-object limits at enterprise scale [S-2026-06-15-immuta-databricks-agentic-access].
  • Argues OAuth-based agent architectures risk “catastrophic privilege escalation” — positioning centralized contextual authorization as the alternative [competitive framing — S-2026-06-15-immuta-databricks-agentic-access].

Relationships

  • partners-with → Collibra — complementary access-control layer alongside Collibra’s catalogue/governance in the same Snowflake agentic stack [inference, based on overlapping Snowflake Summit 26 launches].
  • relates-to → Agentic Data Access Governance — provides the access-enforcement component of this category [S-2026-06-02-immuta-snowflake-agentic-access].
  • partners-with → Databricks — expanded partnership; four Immuta capabilities built on Unity Catalog RBAC/ABAC, GA 15 June 2026 [S-2026-06-15-immuta-databricks-agentic-access].

Tracked changes

  • 2026-06-02 — At Snowflake Summit 26, launched three agentic data-access capabilities on the Snowflake AI Data Cloud (Marketplace) [S-2026-06-02-immuta-snowflake-agentic-access].
  • 2026-06-15 — Expanded Databricks partnership: Agentic Data Access, Intent-Driven Access Control, Comply App for Unity Catalog, Group-Based Permission Assignment — all GA to Databricks customers immediately [S-2026-06-15-immuta-databricks-agentic-access]. (Captured in full 2026-07-10; previously only flagged in the Snowflake source’s notes.)

Open Questions

  • Whether session-scoped role vending generates audit logs suitable as access-control evidence for DORA / GDPR. Partially addressed at claim level: the Databricks release asserts “a full audit trail maintained inside Unity Catalog” [S-2026-06-15-immuta-databricks-agentic-access] — vendor claim, evidence standard not independently verified.
  • No EU/UK FS reference customer named in either release — regulated-FS adoption unconfirmed.

Sources