Agentic Data Access Governance

Created: 2026-06-21 Updated: 2026-09-18 Source count: 33

Updated 2026-09-18 based on S-2026-09-18-weekly-briefing (own weekly synthesis) — cross-theme read: the governed-context-via-MCP thread this page tracks (Informatica GA, Fivetran+dbt, Ataccama Ossie, Alation) now sits underneath the week’s agent-control-plane wave on AI Governance Platforms — the control planes register the agents while MCP delivers the context, and neither side closes the gap at the MCP call boundary (what policy, certification status and logging travel with the call). The testable assurance question lives in that seam — see Agent Control-Plane System-of-Record. Per-vendor facts were already integrated by the daily scans (09-10/11/17). [S-2026-09-18-weekly-briefing]

Updated 2026-09-17 based on S-2026-09-16-dbt-summit-2026-announcements and S-2026-09-15-salesforce-aws-dreamforce-informatica-headless (daily DG/DM vendor-intelligence scan) — two additions to the governed-context-for-agents thread. (1) The transformation layer joins the category with evidence primitives rather than a gateway: at dbt Summit (16 Sep) Fivetran + dbt Labs made dbt v2 (pre-run lineage/column validation) and dbt State (per-model lag_tolerance freshness codified “in the infrastructure instead of with whoever, or whichever agent, issues the command”) GA, and introduced dbt Wizard (agent that validates upstream/downstream impact before a change ships; public preview), dbt Charts (dashboards as version-controlled YAML in the same PR/CI as the models; public beta) and Fivetran Context Layer (structured + unstructured context on the open Agents Schema, served via MCP; private beta) — the first entrant recorded here whose pitch is that governance artefacts (lineage, tests, contracts, freshness rules, dashboard definitions) live in code under change control, rather than that policy is enforced at a call gateway [inference — the contrast is this wiki’s]. New company page: Fivetran + dbt Labs. (2) Informatica’s headless MCP context reaches a second substrate: Salesforce states (15 Sep) that Informatica is “expanding the general availability of its MCP servers” — now naming data-quality scores and master-data retrieval alongside catalog discovery/enrichment — from Amazon Bedrock AgentCore and Amazon Quick, after the June Microsoft Foundry GA; per-vendor facts on Informatica. As with every MCP-context claim on this page, neither source states what policy, masking or certification state travels with the call, or whether calls are logged with retention; neither names an EU/UK regulation, regulator or FS customer. Nothing prior superseded. Updated 2026-09-15 based on S-2026-09-03-cyera-oasis-completion and S-2026-07-31-kuppingercole-cyera-oasis-first-take (daily DG/DM vendor-intelligence scan) — adds the first DSPM-side M&A entry to this category: Cyera (adjacent DSPM / AI-security vendor) completed its $1bn acquisition of Oasis Security (non-human identity / agentic access management) on 3 Sep 2026, folding Oasis in as a “Cyera Identity” pillar wired to Cyera’s data-classification layer — i.e. buying the identity half of “should this agent read this record right now?” rather than building it. KuppingerCole’s independent pre-completion take accepts the architecture, questions the price (~5x SailPoint–Entro), and flags buyer-mismatch, substrate and integration risks; its expectation that Oasis would run as an “independent unit” differs from the completion release’s “dedicated identity pillar” wording — surfaced in a new Tensions section. Neither source names an EU/UK regulation, regulator or FS customer. New company page: Cyera.

Updated 2026-09-11 based on S-2026-09-11-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — records the market-level read for the week to 11 Sep: “governed context for agents via MCP plus an open semantic standard” was the dominant DG/DM theme, asserted in the same week by three vendors (Ataccama’s Apache Ossie DQ converter, Qlik’s MCP server in the AWS and Databricks marketplaces, Alation’s IDC positioning on MCP/ODPS) — with none stating what policy enforcement, certification status or logging travels with the call. Also: the pure-play quiet streak recorded on 28 Aug broke (Ataccama, Alation, Qlik, Collibra all moved, four items being late captures); no DG/DM vendor named an EU/UK obligation this week; and privacy/access pure-plays (BigID, OneTrust, Immuta, Privacera, Securiti) plus Informatica, IBM and Atlan were silent in a week whose theme is their claimed territory. Per-vendor facts were already integrated from the daily-scan sources on 2026-09-08/10. Updated 2026-09-10 based on S-2026-09-09-ataccama-apache-ossie-converter and S-2026-09-09-sap-bdc-data-product-governance (daily data-governance vendor-intelligence scan). Two additions: (1) the trust-layer thread moves into the open semantic standard — Ataccama announced (9 Sep) an open-source converter that writes business terms plus a structured DQ block (pass rate, threshold, below-threshold flag, active findings) into Apache Ossie (Incubating) YAML consumed by Snowflake Semantic Views, Databricks metric views and the dbt Semantic Layer, keeping record-level evidence behind its MCP Server; also records that OSI was renamed Apache Ossie on entering the Apache Incubator (mid-2026), so earlier “OSI” references on this page are historical, not contradicted. (2) An ERP-platform, human-workflow instance of documented data-product access: SAP Business Data Cloud wave 2026.19 (deployments stated for 9 Sep) adds a request → steward review → recorded access-agreement lifecycle with configurable additional approvers — captured from search excerpts only, low authority, and not agent-facing. Per-vendor facts live on Ataccama and SAP. Updated 2026-08-14 based on S-2026-08-14-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — records the market-level read for the week: Purview’s three DLP/data-security moves (DLM-Copilot insights GA, cross-SaaS DLP + Defender File Policies retirement 6 Jan 2027, DLP alert auto-resolution) continue consolidating fragmented DLP evidence into a single control plane, with audit representation of auto-resolved/migrated evidence still undocumented [speculative — own market read] (per-vendor facts live on Microsoft Purview); BigID’s 4 Aug authority-layer and sovereignty releases were the only new access-enforcement entrant this week (per-vendor facts already folded in 2026-08-11); and the Alation–PwC Canada E-21 accelerator is this category’s first instance of a Big Four firm packaging a catalogue incumbent’s agentic-governance layer into a named-regulation evidence product — a business-model shift with a direct, if analogical, read-across to BCBS 239/FCA-PRA evidence expectations and to the independent-assurance advisory market itself (per-vendor facts live on Alation). Also records, as landscape rather than category content, Ataccama’s CEO transition (CTO Martin Zahumensky replaces Mike McKee; second C-suite change in five weeks; Bain Capital/Snowflake Ventures backing made explicit) as a supplier-concentration data point for the data-quality/trust layer of this category (per-vendor facts live on Ataccama). Remaining pure-plays (Atlan, OneTrust, Immuta, Monte Carlo) quiet again; Collibra silent a second week post-CLI-EOL; lineage specialists Solidatus/MANTA quiet multiple weeks running. [S-2026-08-14-weekly-vendor-synthesis] Updated 2026-08-12 based on S-2026-07-29-forrester-wave-data-lakehouses (daily vendor-intelligence scan) — the 7 Aug “governance absorbed into the data estate” read gains its first major-analyst corroboration from the platform side: The Forrester Wave: Data Lakehouses, Q3 2026 (Cloudera Leader PR 29 Jul; one search summary dates publication 3 Aug ⚠️ unresolved) evaluated 14 lakehouse vendors and, per retrieved excerpts, prioritises platforms that “embed governance, automated lineage, fine-grained access controls, continuous data quality monitoring, and policy enforcement as core platform capabilities”, framing the lakehouse as “an execution layer for agentic AI” that must supply “trusted, governed, real-time context that AI agents can use to reason, decide, and act”. An analyst now scoring lakehouses on embedded governance is a demand-side signal that platform-native controls are becoming the default route to lineage/DQ evidence, with obvious displacement pressure on the standalone catalogue/governance overlay [inference — the displacement read is this wiki’s; Forrester’s excerpts make no such claim and name no regulation]. ⚠️ Provenance caution: the gated report was not read; Forrester’s blog fetch returned an empty body; Leaders confirmed only via vendor self-announcements (Cloudera, Microsoft/Fabric) — the other 12 placements, including Databricks and Snowflake, are unknown. Rest of today’s scan was negative/duplicate: Alation AIOS (14 Jul), Alation Gartner Peer Insights (21 Jul) and the Microsoft Purview July security-roundup items (30 Jul) re-surfaced but were already ingested (23 Jul, 7 Aug and 11 Aug runs); Collibra 2026.08 release notes still not itemised (standing lead); Ataccama agentic observability (26 Feb), Gartner ADQ MQ (18 Feb), Secoda/Atlassian (Dec 2025), Salesforce/Informatica close (Nov 2025) and ServiceNow/data.world all checked and rejected as outside the 30-day window; no new in-window item from the pure-plays (Atlan, OneTrust, Immuta, Monte Carlo, Soda, Solidatus, dbt Labs) or the privacy cohort.

Updated 2026-08-11 based on S-2026-08-04-bigid-agentic-authority-layer (daily vendor-intelligence scan) — BigID formally entered the access-enforcement layer from the DSPM side: a 4 Aug 2026 (Black Hat-week) launch of Agentic Access Control (agent access scoped to data sensitivity rather than role/credential, adjusted dynamically per task) and Intent-Based Activity Monitoring (continuous behaviour-vs-declared-intent checking with full-chain tracing of what an agent read, moved or acted on), jointly branded an “authority layer”. Differentiator claim vs Immuta’s on-behalf-of session roles and the substrate gateways: sensitivity-based scoping plus intent as the monitored control object rather than entitlement alone [inference — comparative framing is this wiki’s, not BigID’s]. No availability status, customer or third-party validation is given, and no regulation is named — see Key Points. This ends BigID’s quiet spell (tracked since early July); a same-day sovereignty positioning release is recorded on BigID. [S-2026-08-04-bigid-agentic-authority-layer]

Updated 2026-08-07 based on S-2026-08-07-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — records the market-level read that the pure-play quiet streak ended with a company-level repositioning, not a feature release: Alation’s AIOS (14 Jul, re-captured this week with its Gartner Peer Insights Customers’ Choice recognition) completes the arc flagged 24 July — with Collibra 2026.06 and Informatica CDGC July, every major catalogue incumbent now claims the AI-governance evidence layer, and the synthesis’s read is that the passive catalogue is being retired as a market position [speculative — own market read] (per-vendor facts live on Alation); adds Airbyte as a pipeline/data-movement-layer entrant (governed team workspaces + first agent write operations — see Key Points); and records that the Defender for Cloud Apps File Policies retirement (6 Jan 2027, Purview mandated replacement) gives the “vendor lifecycle events are regulatory-evidence events” pattern its second instance in five weeks after the Collibra CLI EOL (per-product facts live on Microsoft Purview). Remaining pure-plays quiet a fifth week; Collibra silent in its first week post-EOL. [S-2026-08-07-weekly-vendor-synthesis]

Updated 2026-08-03 based on S-2026-07-28-snowflake-cortex-ai-gateway (daily data-governance vendor-intelligence scan) — the second major platform substrate moved first-party into this category: Snowflake announced Cortex AI Gateway (28 Jul 2026, public preview “soon”), a centralised control plane for first- and third-party agent access to models, tools, MCP servers and enterprise systems, with an “end-to-end record of agent activity”, cost caps and model routing, plus task-scoped third-party agent access integrations (1Password, Aembit, Linx Security, Okta, SailPoint, Saviynt — pre-preview; Okta Q4 2026). Mirrors Databricks’ June Unity AI Gateway, including the overlapping identity partners [inference]. Both substrates now compete first-party with the partner layer (Immuta, Collibra) they host. Per-vendor facts live on Snowflake. All claims vendor-reported; product pre-preview.

Updated 2026-07-31 based on S-2026-07-31-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — records the market-level read that both major catalogue incumbents now ship an AI use-case/agent inventory natively (Collibra 2026.06: AI Agent asset types + mandatory AIUC-1 assessment; Informatica CDGC July: AI Governance Inventory & Workflows — per-vendor facts live on Collibra and Informatica), moving the EU AI Act evidence layer from pure-play add-on toward standard catalogue capability [speculative — own market read]; adds Neo ($100M a16z/Bessemer stealth exit, 20 July) as a security-led adjacent entrant claiming the agent-inventory/policy-control layer from the SecOps side (single capture — no entity page yet); and records the fourth consecutive quiet week for the pure-plays (Alation, Atlan, OneTrust, Immuta, Monte Carlo; BigID and Ataccama light signals only) — the deliberate H2-launch scan remains due. [S-2026-07-31-weekly-vendor-synthesis] Updated 2026-07-24 based on S-2026-07-24-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — partially resolves the 10 July open question on the catalogue/privacy pure-plays’ quiet spell: for Alation the quiet was pre-launch repositioning — the 14 July AIOS launch moves the company wholesale from catalogue into AI/agent governance (Agentic Compliance, Agentic Data Governance; see Alation and AI Governance Platforms where the per-vendor facts live), while the remaining pure-plays (Atlan, BigID, OneTrust, Immuta, Monte Carlo, Ataccama) were quiet a third consecutive week — a deliberate H2-launch scan is now flagged rather than continued passive watching. No new per-vendor facts added to this page. [S-2026-07-24-weekly-vendor-synthesis] Updated 2026-07-10 (daily vendor-intelligence scan) based on S-2026-06-15-immuta-databricks-agentic-access — full capture of Immuta’s 15 June Databricks announcement (previously only flagged in the Snowflake source’s notes): four capabilities GA on Databricks, extending the access-enforcement layer’s on-behalf-of model to Unity Catalog with a vendor-claimed “full audit trail maintained inside Unity Catalog” and the Comply App’s natural-language, “audit-ready” entitlement reporting. Partially answers (at claim level) this page’s open question on audit-log evidence. The same scan’s deliberate quiet-vendor sweep found no other new items ([S-2026-07-10-vendor-scan-note]). Updated 2026-07-10 based on S-2026-07-10-weekly-briefing (own-writing weekly briefing) — adds the cross-context read that this week’s AI-generated DQ-rule GA in the vendor scan (Collibra, Qlik) has a mirror in Paul’s own delivery: the C-QA MS365 Copilot prompt and the Build Kit’s DQ-1…8 controls apply AI to authoring/grading definitions and rules the same way these platforms apply it to DQ rules, so the same assurance question — is auto-/AI-generated rule and definition logic auditable, traceable and defensible versus steward-authored? — spans both the tools Paul assures and the tools Paul builds (see CLM Glossary Acceleration Squad). No per-vendor facts changed; added as a Key Point and an Open Question. [S-2026-07-10-weekly-briefing] Updated 2026-07-10 based on S-2026-07-10-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — no new per-vendor facts (this week’s Qlik entry was already folded in below); records the market-level read that the agentic-DQ-rule-generation thread has crossed from preview into GA across at least two platforms regulated FIs actually run (Collibra “AI suggested rules” GA July 2026; Qlik DQ agents GA reported 2 July, with Informatica’s IDMC 26 July release pending), making “defensibility and auditability of AI-generated DQ rules vs steward-authored” a nameable assurance test category — the DQ-layer counterpart to the 3 July runtime-logging test category. Also records that the catalogue/privacy pure-plays in this category (Alation, Atlan, BigID, OneTrust, Immuta, Monte Carlo) were quiet this week after a very active June — summer lull vs repositioning undetermined [S-2026-07-10-weekly-vendor-synthesis]. Updated 2026-07-09 based on S-2026-07-02-qlik-data-engineering-ga (daily vendor-intelligence scan): added Qlik as a BI/data-integration-layer entrant — GA (reported 2 Jul 2026 by TechTarget) of data quality agents that generate/edit DQ rules with trust scores, a catalog, governed reusable Data Products, Declarative Pipelines with Coding, and expanded MCP access for authorised agents to Qlik-held data and business logic. Independent analysts (Farmer/TreeHive, Catanzano/Omdia) judge it useful but undifferentiated (“every data platform is shipping something similar”), directly corroborating this page’s market-level read that MCP-governed agentic access is a near-universal claim. Medium authority (independent trade press relaying vendor GA claims). No prior claim changed. Updated 2026-07-03 based on S-2026-07-03-weekly-vendor-synthesis (own-writing weekly vendor synthesis) — no new per-vendor facts (the week’s entrants CData, Ataccama and Komprise were already folded in below); records the market-level read that the DG/DM core-catalogue market was quiet this week (the watchlist scan returned no new item) while the MCP-governed-context pattern kept spreading to adjacent layers (connectivity, data-quality/trust, unstructured storage), and that the week’s vendor momentum sat in the adjacent AI-governance / agentic-runtime-governance space rather than this category [S-2026-07-03-weekly-vendor-synthesis]. Updated 2026-07-01 based on S-2026-06-23-komprise-transparent-file-tables (daily vendor-intelligence scan): added Komprise as an unstructured-data / storage-layer entrant to the category — Transparent File Tables (23 Jun 2026, early access) exposes the unstructured file/object estate to Snowflake/Databricks as Apache Iceberg tables via enriched metadata, claiming “governance based on user access permissions” (entitlement-preserving access). Adjacent vendor (not on the core watchlist); low authority (vendor-relayed via secondary roundup). Reinforces the “governed context/discovery reaching the point of AI consumption” read; adds a new layer (the unstructured estate itself) beneath the catalogue/access/DQ/observability layers already mapped. No prior claim changed. Updated 2026-06-30 based on S-2026-06-23-cdata-connect-ai-governed-mcp and S-2026-06-26-precisely-data-integrity-ai-agents (daily vendor-intelligence scan): added two adjacent-layer entrants to the category — CData (data-connectivity layer: a “governed” MCP server with identity-aware access + audit logging over 350+ sources) and Precisely (data-quality/data-integrity layer: agentic DQ-rule generation in the Data Integrity Suite with a human-oversight claim). Both reinforce the existing “MCP-as-shared-plumbing” and “test the control claim against evidentiary thresholds” reads; neither names an EU/UK regulated-FS reference customer. Low-authority (secondary roundup, vendor marketing). No prior claim changed. Updated 2026-06-26 based on S-2026-06-26-weekly-vendor-synthesis: weekly vendor-synthesis cross-link — no new vendor facts added (the week’s per-vendor moves were already folded in below); records the market-level read that the agentic-data-access pitch is now a near-universal vendor claim and adds the practitioner framing on testing it against evidentiary thresholds. Updated 2026-06-22 based on S-2026-06-04-atlan-gartner-leader-agentic-governance and S-2026-06-16-microsoft-purview-whats-new: added Atlan (metadata-lakehouse entrant; 2026 Gartner D&A Governance Leader) and Microsoft Purview (Microsoft-estate entrant) to the category. Updated 2026-06-26 based on S-2026-06-15-monte-carlo-agent-bricks and S-2026-06-23-nucleus-data-governance-value-matrix: added Monte Carlo (observability-layer entrant — agent observability on Databricks Agent Bricks) and folded in independent analyst corroboration of the category from the Nucleus Research 2026 Data Governance Value Matrix (resolving that source’s previously dangling reference to this topic). Updated 2026-06-26 based on S-2026-06-16-databricks-unity-ai-gateway-summit and S-2026-06-15-informatica-microsoft-foundry-mcp-ga: added Databricks as the lakehouse-native governance entrant in its own right (Unity AI Gateway + Unity Catalog AI-asset governance, plus the first cited — if anonymised — FS agent use case), and recorded Informatica’s MCP context layer reaching GA inside Microsoft Foundry.

TL;DR

“Agentic data access governance” is the emerging vendor category for controlling what autonomous AI agents can read, do and prove when they act on enterprise data. In June 2026 — clustered around Snowflake Summit 26 and the Databricks Data + AI Summit — data-governance and data-access vendors converged on the same pitch: ground AI agents in governed, certified context; enforce least-privilege access for agents; and capture end-to-end traceability of agent decisions. For EU/UK regulated firms this is the tooling layer where BCBS 239 lineage, GDPR access/usage controls and EU AI Act oversight obligations get operationalised — but the claims are vendor marketing and largely unverified in regulated FS.

Key Points

  • Vendors are reframing data governance around agents as data consumers: governance/context must reach the point where an agent queries or acts, “before they act” [S-2026-06-02-collibra-snowflake-ai-command-center].

  • Catalogue/context layer: Collibra pushes certified definitions, ownership, quality signals and policies into Snowflake (Horizon/Cortex) and Databricks (Unity Catalog, Genie, Agent Bricks), and harvests runtime lineage back into an “AI Command Center” for AI lifecycle traceability [S-2026-06-02-collibra-snowflake-ai-command-center][S-2026-06-16-collibra-databricks-governance].

  • Access-enforcement layer: Immuta enforces agent access at the session level, vending a temporary role “scoped to the user the agent is acting on-behalf-of” so an agent cannot exceed that user’s permissions, plus governs outbound agentic access and offers an NL interface to query Horizon permissions [S-2026-06-02-immuta-snowflake-agentic-access].

  • Access-enforcement layer reaches cross-platform parity: Immuta shipped the same model on Databricks (15 June 2026, GA immediately): agent sessions bounded to the invoking user’s entitlements at table/row/column/cell level with a vendor-claimed “full audit trail maintained inside Unity Catalog”; Intent-Driven Access Control (task-scoped, auto-expiring permissions, framed as “continuous compliance with GDPR … and data sovereignty requirements” [vendor marketing]); the Comply App for Unity Catalog (natural-language entitlement auditing — “Which AI agents have access to financial tables?” — producing “instant, audit-ready results” per Immuta); and Group-to-Object ABAC for scale [S-2026-06-15-immuta-databricks-agentic-access].

  • Data-foundation layer: Informatica exposes governed data services to any agent via native MCP, with agents that define DQ rules in natural language and auto-apply business descriptions and sensitivity labels as data flows, unifying data assets and agents in one catalogue [S-2026-06-03-informatica-agentic-data-management].

  • Model Context Protocol (MCP) is becoming the shared plumbing: both Collibra (MCP Server) and Informatica (Agent Fabric Context Catalog published as MCPs) deliver governed context to agents via MCP [S-2026-06-02-collibra-snowflake-ai-command-center][S-2026-06-03-informatica-agentic-data-management].

  • The risk framing is consistent across vendors: an agent acting on “stale definitions, uncertified data, or incomplete lineage is an agent operating outside enterprise controls” [S-2026-06-16-collibra-databricks-governance].

  • Metadata-lakehouse entrant: Atlan — a Leader in the 2026 Gartner MQ for D&A Governance Platforms (MQ dated 6 Jan 2026) — markets, around Snowflake Summit 26 (1–4 June 2026), an AI-governance layer that auto-discovers AI models/agents, classifies them against frameworks and keeps “auditable records of every agent action,” interoperating with Cortex, Genie, Claude and ChatGPT [S-2026-06-04-atlan-gartner-leader-agentic-governance].

  • Microsoft-estate entrant: Microsoft Purview extends governance over the AI surface within Microsoft 365 — June 2026 GA of protections for Copilot Cowork, May 2026 GA for Agent 365, a DSPM preview connector that surfaces Anthropic Claude (Enterprise) interactions, and a DLP control to block untrusted external email as Copilot grounding data — but its reach is largely Microsoft-estate-bound [S-2026-06-16-microsoft-purview-whats-new].

  • Observability-layer entrant: Monte Carlo (a data + AI observability vendor; an Accelerator in the 2026 Nucleus matrix) extended observability up into the agent layer on Databricks Agent Bricks (15 June 2026), claiming a three-layer view (Delta Lake/data tables, Lakeflow pipelines, Agent Bricks agents) with zero-instrumentation trace reading via the existing Databricks connection — adding root-cause tracing of agent failures to the category’s traceability story [S-2026-06-15-monte-carlo-agent-bricks].

  • Lakehouse-native entrant: Databricks itself moved into agent governance at Data + AI Summit 2026 (mid-June 2026), extending Unity Catalog to register, secure and audit AI assets (Databricks-hosted/external models, MCP services, agents, skills) and launching the Unity AI Gateway to govern “runtime interactions between models, agents, MCP services, skills, and enterprise tools,” with ABAC Grant Policies (Beta) and identity/context attributes for access control — making the lakehouse a first-party governance plane, not just a substrate that Collibra/Monte Carlo overlay [S-2026-06-16-databricks-unity-ai-gateway-summit].

  • First cited FS use case (anonymised): Databricks cited a financial-services firm using Unity Catalog to build a mortgage-advisory agent that explains denial reasons while redacting sensitive financial details — the category’s first named-sector (though unnamed-firm) FS deployment; it touches EU AI Act human-oversight/transparency and GDPR data-minimisation, but is vendor-presented and not stated to be EU/UK [S-2026-06-16-databricks-unity-ai-gateway-summit].

  • MCP context layer reaches the Azure build surface: Informatica’s headless IDMC MCP servers became GA inside Microsoft Foundry (~15 June 2026), exposing governed Cloud Data Governance & Catalog, address-verification and provisioning services to Azure-built agents for “traceable context” with “real-time policy enforcement” — extending the MCP-as-shared-plumbing pattern into the Microsoft/Azure agent-development environment [S-2026-06-15-informatica-microsoft-foundry-mcp-ga].

  • Data-quality/trust-layer entrant: Ataccama (a data-quality-led “data trust” vendor; an Expert vendor in the 2026 Nucleus matrix) launched “data products” with a continuous 0–100 Data Trust Index (data quality + ownership + business context) at Snowflake Summit 26 (2 June 2026), delivered to agents via an MCP Server into Snowflake CoCo/Cortex CoWork, and joined the Open Semantic Interchange (OSI) as a Snowflake Agentic Data Sharing launch partner — extending the category’s context layer with an explainable, “fit-for-use” trust signal and reinforcing OSI/MCP as shared plumbing (Collibra also joined OSI) [S-2026-06-02-ataccama-data-products-osi].

  • Trust signals enter the open semantic standard (Sep 2026): OSI was accepted into the Apache Incubator and renamed Apache Ossie (Incubating) in mid-2026 — a YAML/JSON spec for metrics, dimensions, joins and relationships in which AI agents are treated as first-class consumers; it is a specification, not a product [S-2026-09-09-ataccama-apache-ossie-converter]. On 9 September 2026 Ataccama announced it will open-source a converter emitting Ossie-compliant YAML that carries steward-curated business terms (into the ai_context field) and a structured data-quality block — DQ state, pass-rate %, threshold, below-threshold flag, active-finding count — plus an optional plain-language warning in the AI instructions for flagged datasets; the file refreshes on a scheduled job at DQ-run cadence, and check- and record-level evidence is served live from Ataccama’s MCP Server rather than embedded [vendor claim — S-2026-09-09-ataccama-apache-ossie-converter]. This is the first move recorded here to put quality state (not just meaning or policy) into the artefact agents read at query time; whether Snowflake, Databricks or dbt consumers enforce the flag or only pass it through is not stated, and the converter has no release date [S-2026-09-09-ataccama-apache-ossie-converter]. Independent coverage (Techzine) confirms the announcement and notes the Snowflake tie is partly financial (Snowflake Ventures investor) [S-2026-09-09-ataccama-apache-ossie-converter].

  • ERP-platform, human-workflow variant — SAP BDC data-product governance (wave 2026.19, deployments stated for 9 Sep 2026): SAP Business Data Cloud replaces direct permissions and manual sharing for data products with a request-based model in which a Data Steward acting for the Domain Owner approves or rejects against domain policy, decisions are documented, requests become access agreements with a formal lifecycle (including duration), a central Governance area is added to the BDC cockpit, and extra approvers (Legal, Works Council, Budget Responsible) can be required by policy — which SAP frames as a compliance requirement in regulated industries [vendor claim, search-excerpt capture only — S-2026-09-09-sap-bdc-data-product-governance]. It is not agent-facing and names no regulation, but it is the same “who asked, who approved, why, for how long” evidence pattern this category’s access-enforcement vendors pitch to agents — arriving inside the ERP estate [inference — S-2026-09-09-sap-bdc-data-product-governance].

  • Independent analyst corroboration: the Nucleus Research 2026 Data Governance Technology Value Matrix (23 June 2026) frames governance metadata as the “trusted context” layer whose quality “directly influence[s] the accuracy, transparency, and reliability” of AI assistants and autonomous agents — an independent (non-Gartner) read that the vendors in this category are converging on the same agentic-governance thesis; it places Alation, Atlan, Collibra, Oracle and Salesforce (Informatica) as Leaders [S-2026-06-23-nucleus-data-governance-value-matrix].

  • None of the June 2026 releases reviewed named an EU/UK regulated-FS reference customer (Databricks cited an anonymised FS mortgage-advisory use case, but the firm is unnamed and not stated to be EU/UK), and none detailed EU data-residency/sovereignty options for the agentic features (Immuta’s Databricks release invokes “data sovereignty requirements” as marketing framing without specifying configurations [S-2026-06-15-immuta-databricks-agentic-access]) [S-2026-06-16-collibra-databricks-governance][S-2026-06-02-immuta-snowflake-agentic-access][S-2026-06-03-informatica-agentic-data-management][S-2026-06-04-atlan-gartner-leader-agentic-governance][S-2026-06-16-microsoft-purview-whats-new][S-2026-06-15-monte-carlo-agent-bricks][S-2026-06-16-databricks-unity-ai-gateway-summit][S-2026-06-15-informatica-microsoft-foundry-mcp-ga].

  • Cross-context read (own delivery, week to 10 July 2026): the AI-generated-DQ-rule GA in this category has a direct counterpart in Paul’s own CLM glossary tooling — the C-QA MS365 Copilot prompt grades and improves term/definition rows with AI, and the Build Kit encodes DQ-1…8 definition-quality controls — so the “defensibility and auditability of AI-generated vs steward-authored rule/definition logic” test applies symmetrically to the vendor tools Paul assures and the AI-assisted assets Paul builds; a usable engagement framing is to hold both to the same evidence standard (reconstructable logic, human sign-off, source anchoring) [S-2026-07-10-weekly-briefing]. See CLM Glossary Acceleration Squad.

  • Market-level read (week to 10 July 2026): the agentic-DQ-rule-generation thread crossed into general availability — Collibra’s “AI suggested rules” (GA July 2026) and Qlik’s DQ agents (GA reported 2 July 2026) put GenAI-generated data-quality rule logic into production platforms regulated FIs run, with Informatica’s IDMC July release (26 July) pending; the assurance question therefore shifts from “can it?” to whether auto-generated rule logic is defensible, auditable and policy-mapped rather than steward-authored — no vendor specified an audit format for generated rules [S-2026-07-10-weekly-vendor-synthesis].

  • Warehouse-native entrant (second substrate goes first-party): Snowflake announced Cortex AI Gateway (28 Jul 2026; public preview “soon”) — centralised agent access policies, authentication and permissions across models, tools, 100+ MCP servers and enterprise systems; a “centralized, end-to-end record of agent activity”; AI cost attribution with enforced spending limits; routing to enterprise-approved models; built on the May 2026 Natoma (MCP platform) acquisition — plus task-scoped third-party agent access integrations with 1Password, Aembit, Linx Security, Okta, SailPoint and Saviynt (“private preview soon”; Okta Q4 2026). With Databricks’ Unity AI Gateway this makes agent-control planes first-party on both major substrates, overlapping the partner layer (Immuta session roles, Collibra MCP context) that runs on them; named customers (BlackRock, Thomson Reuters) are security-framed, not gateway-specific, and none is an EU/UK-regulated FI [S-2026-07-28-snowflake-cortex-ai-gateway].

  • Market-level read (week to 31 July 2026): the category’s centre of gravity is consolidating into the catalogue incumbents — Collibra’s 2026.06 release wires an assessable AI-agent inventory into the catalogue (AI Agent Version/Tool asset types, AIUC-1 mandatory at Under Review), and Informatica’s July CDGC release adds an AI Governance Inventory & Workflows — so a native AI use-case/agent inventory is now table stakes in both major platforms [vendor release claims, not independently verified]; simultaneously the same control layer is being claimed from the security side (Neo, $100M stealth exit) [inference — one launch], making control-ownership boundaries between security and data/AI-governance tooling an assessment question in DORA ICT-risk scoping [S-2026-07-31-weekly-vendor-synthesis].

  • Market-level read (week to 26 June 2026): “MCP-governed agentic data access” has become a near-universal vendor claim across this category (Collibra, Informatica, Immuta, Atlan, Databricks); in an assurance context the practitioner move is to test it against specific evidentiary thresholds (EU AI Act Art. 12 log retention/immutability, BCBS 239 reconciliation) rather than accept “traceability”/“regulator-ready” framing — none of the releases specified those thresholds [S-2026-06-26-weekly-vendor-synthesis].

  • Connectivity-layer entrant: CData launched Connect AI (~23 June 2026), a governed MCP server exposing 350+ enterprise sources to AI dev environments (Claude Code, Cursor, LangChain) with identity-aware access, audit logging and dynamic schema discovery, plus a free Developer Edition, an open-source DB-API 2.0 Python SDK and a CLI — placing a data-connectivity vendor inside the same MCP-governed agentic-access pattern; the source does not state whether “identity-aware access” enforces on-behalf-of least-privilege scoping (as Immuta’s session roles do) or only authenticates the connection [S-2026-06-23-cdata-connect-ai-governed-mcp].

  • Data-quality/data-integrity entrant: Precisely added Data Quality, Data Enrichment and Location Intelligence agents to its Data Integrity Suite (with its “Gio” assistant) that generate and apply DQ rules and standardise/enrich data “while keeping human oversight and transparency over the rules being created” (~26 June 2026) — extending the agent-era governance story into automated data-quality rule authoring; the “human oversight over the rules” boundary is the testable control for an assurance reviewer [S-2026-06-26-precisely-data-integrity-ai-agents].

  • BI/data-integration-layer entrant: Qlik moved to GA (reported 2 Jul 2026) the data-engineering wave previewed at its April Connect conference: data quality agents that create/edit DQ rules, score datasets with trust scores and detect anomalies; a catalog; governed reusable Data Products; Declarative Pipelines with Coding (approved third-party coding agents in pipeline build); and expanded MCP access letting authorised agents reach data and business logic in Qlik’s environment — extending both the MCP-as-shared-plumbing pattern and the agentic-DQ-rule-generation thread (Informatica, Precisely, Collibra) into the BI/analytics estate; independent analysts call it useful but undifferentiated, with Qlik’s edge the combination in one governed platform, and flag missing agent-observability as the gap [S-2026-07-02-qlik-data-engineering-ga].

  • Unstructured-data / storage-layer entrant: Komprise (an adjacent unstructured-data-management vendor) launched Transparent File Tables (23 June 2026, early access), exposing the distributed file/object estate to Snowflake/Databricks as Apache Iceberg tables via globally-classified, enriched metadata and pointers — without bulk file movement — and claims “data governance based on user access permissions” so lakehouse access inherits existing entitlements; this extends the category downward to the raw unstructured estate (~80% of the data footprint, <1% used in AI per IDC/Komprise) that the catalogue/access/DQ layers otherwise sit above, but the source does not specify whether entitlements enforce at query time or only at file-move time, nor whether the classification is defensible for GDPR/BCBS 239 evidence [S-2026-06-23-komprise-transparent-file-tables].

  • Pipeline/data-movement-layer entrant: Airbyte rolled out updates to its Agentic Data Platform (week ending 31 Jul 2026, reported via Solutions Review roundup) adding team workspaces — segregating users, connectors and agents into governed environments with their own context stores — and first agent write operations (HubSpot connectors) under least-privilege permission scopes; this moves the category from read-only governed context to governed agent action at the pipeline layer, making segregation-of-duties and least-privilege scoping in data movement part of the control surface [S-2026-07-31-solutionsreview-airbyte-roundup]. Not verified against Airbyte’s primary release notes [S-2026-08-07-weekly-vendor-synthesis].

  • DSPM-side access-enforcement entrant: BigID launched Agentic Access Control and Intent-Based Activity Monitoring (4 Aug 2026, Black Hat week) — agent access scoped “based on the sensitivity of the data itself, not just a role or a credential”, adjusted “dynamically as an agent’s task changes”; continuous checking of actual agent behaviour against declared intent, flagging deviations “even when they’re technically within permitted access”; and tracing of “the full chain of what an agent read, moved, or acted on, tied directly to the sensitivity of the data involved”. This adds a fourth access-control model to the category (data-sensitivity + intent, vs Immuta’s on-behalf-of session roles, the substrates’ gateway policies, and CData-style identity-aware connectivity) [inference — taxonomy is this wiki’s]. The release commits to no availability date, names no customer, no analyst and no regulation — the widest claim/evidence gap of any launch recorded on this page [S-2026-08-04-bigid-agentic-authority-layer].

  • DSPM-side M&A — data and identity bought as one control point (3 Sep 2026): Cyera, an adjacent DSPM / AI-security vendor (self-reported $12bn valuation), completed its $1bn acquisition of Oasis Security, a non-human-identity (NHI) / “agentic access management” vendor founded 2022; Oasis will operate as “Cyera Identity”, a pillar “connecting directly to Cyera’s data intelligence layer” so that one platform “determines what every human, machine, and AI agent can see and do”, with permissions “evaluated fresh before every action” [S-2026-09-03-cyera-oasis-completion]. KuppingerCole’s independent analysis (pre-completion) accepts the architecture — agent authorisation needs both the data-sensitivity signal DSPM holds and the credential/ownership signal NHI management holds — while judging the price high (~5x SailPoint’s reported ~$200m for Entro six weeks earlier; shared investors, so “not a clean arm’s-length price discovery event”), discounting Cyera’s “nearly 500%” NHI-growth figure as unmethodologised, and listing buyer mismatch (IAM vs data-security budget holders), a missing secrets/PKI substrate, overlap with Cyera’s existing identity module and integration bandwidth as the risks; its market read is that “NHI management is closing as a separate purchase, not as a discipline” and that mature IGA/PAM shops will keep identity governance in the identity platform rather than a DSPM tool [S-2026-07-31-kuppingercole-cyera-oasis-first-take]. For this category the move is a fourth route to the same control point: substrate gateways (Databricks/Snowflake), on-behalf-of access vendors (Immuta), catalogue incumbents (Collibra/Informatica) and now DSPM-plus-NHI (Cyera; BigID’s August “authority layer” is the build-not-buy analogue) [inference — taxonomy is this wiki’s]. No EU/UK regulation, regulator or FS customer is named by either source; the completion release’s only named customers are Paramount, Chipotle and Valvoline [S-2026-09-03-cyera-oasis-completion].

  • Analyst corroboration from the platform side: The Forrester Wave: Data Lakehouses, Q3 2026 (announced 29 Jul 2026; 14 vendors) evaluates lakehouses on embedded “governance, automated lineage, fine-grained access controls, continuous data quality monitoring, and policy enforcement as core platform capabilities”, framing the lakehouse as “an execution layer for agentic AI” — the first major-analyst scoring seen on this page that treats governance as a native platform capability rather than an overlay category; Cloudera and Microsoft (Fabric) self-announced as Leaders, full quadrant unknown (gated report not read) [S-2026-07-29-forrester-wave-data-lakehouses].

  • Market-level read (week to 14 August 2026): the week’s single new access-governance move was BigID’s (already folded in 2026-08-11); the more consequential development for this category is business-model, not capability — Alation’s partnership with PwC Canada packages the AIOS agentic-governance layer into a named-regulation “compliance accelerator” (OSFI E-21) delivered primarily by PwC, the first time a Big Four firm has wrapped a catalogue incumbent’s runtime-governance claims into a regulator-named evidence product; the synthesis’s read is that this is a template that could port to BCBS 239/FCA-PRA in EU/UK, which would put Big Four-delivered accelerators in direct competition with independent assurance advisory over the same evidence [speculative — own market read]; Microsoft continued consolidating DLP/data-security evidence into Purview (three distinct moves this week: DLM-Copilot insights, cross-SaaS DLP + File Policies retirement, alert auto-resolution); Ataccama’s CEO transition is recorded as a supplier-concentration signal at the data-quality/trust layer, not a capability move [S-2026-08-14-weekly-vendor-synthesis].

  • Market-level read (week to 7 August 2026): the pure-play quiet streak ended by repositioning rather than feature release — Alation’s AIOS makes every major catalogue incumbent a claimed AI-governance evidence platform, and with agent gateways first-party on both substrates (Snowflake, Databricks) plus write-enabled pipeline agents (Airbyte), the synthesis’s read is that agent governance is being absorbed into the data estate itself rather than remaining a pure-play overlay [speculative — own market read]; the Defender for Cloud Apps File Policies retirement (6 Jan 2027) gives the “vendor lifecycle events are regulatory-evidence events” pattern (first instance: Collibra CLI EOL 31 Jul) its second dated instance in five weeks, supporting a standing lifecycle-migration check in assurance reviews [S-2026-08-07-weekly-vendor-synthesis].

  • Market-level read (week to 11 September 2026): three vendors made the same claim in one week — that governance and DQ signals travel with the context agents consume, via MCP and an open semantic specification: Ataccama’s announced Apache Ossie converter (DQ block beside business definitions; MCP Server for drill-down evidence), Qlik’s MCP server distributed through the AWS and Databricks marketplaces, and Alation’s IDC-placement positioning on MCP and the Open Data Product Specification. The synthesis reads this as MCP-plus-open-semantic-spec becoming the standard channel through which catalogue-layer controls are claimed to reach agents [speculative — S-2026-09-11-weekly-vendor-synthesis]. The evidence test it derives: for any estate feeding agents this way, ask what row/column policy, masking and certification status actually travel with the MCP call or semantic file, and whether each call is logged with retention — none of the three vendors states this [S-2026-09-11-weekly-vendor-synthesis]. Contrast with the SAP BDC access-agreement model captured the same week, which is human-workflow governance that does not (as described) cover programmatic or agent consumers [S-2026-09-11-weekly-vendor-synthesis]. The 28 Aug pure-play quiet streak broke this week, but no DG/DM vendor named an EU/UK obligation and the privacy/access pure-plays were absent [S-2026-09-11-weekly-vendor-synthesis].

  • Transformation-layer entrant — governance as code rather than as gateway (16 Sep 2026): Fivetran + dbt Labs positions dbt as “the data infrastructure layer that makes agents trustworthy”: dbt v2 (GA) surfaces “errors, column checks, and lineage before anything runs”; dbt State (GA, paid) codifies freshness per model as a lag_tolerance so that “the guardrails now sit in the infrastructure instead of with whoever, or whichever agent, issues the command”; dbt Wizard (public preview) is a project-grounded agent that checks “upstream and downstream impact, compiling and building the change before anyone sees the diff”; dbt Charts (public beta) defines dashboards as YAML “in the same repo, the same pull request, the same CI as the SQL underneath it”; and dbt context reaches agents through the GA dbt MCP Server, the open-source Agents Schema, GA Anthropic/ChatGPT integrations and the private-beta Fivetran Context Layer (adds unstructured sources) [vendor claims — S-2026-09-16-dbt-summit-2026-announcements]. This is a different control locus from the gateways (Databricks/Snowflake), on-behalf-of access vendors (Immuta), catalogue incumbents and DSPM/NHI entrants already mapped: the claim is that the lineage, tests, contracts, freshness rules and even the executive dashboard are versioned artefacts under change control that both humans and agents read [inference — the taxonomy placement is this wiki’s]. What travels with an MCP/Context Layer call (policy, masking, certification) and whether calls or Wizard validations are logged with retention is not stated; no regulation, regulator or EU/UK FS customer is named (Virgin Media O2 is a UK telco) [S-2026-09-16-dbt-summit-2026-announcements].

  • Catalogue-incumbent context on a second hyperscaler runtime (15 Sep 2026): Salesforce’s Dreamforce AWS story states Informatica “is expanding the general availability of its MCP servers”, with headless capabilities that “now include Informatica platform administration, catalog discovery and enrichment, data-quality scores, and master-data retrieval”, accessible from Amazon Bedrock AgentCore and Amazon Quick (“available now”) — following the June 2026 Microsoft Foundry GA [S-2026-09-15-salesforce-aws-dreamforce-informatica-headless][S-2026-06-15-informatica-microsoft-foundry-mcp-ga]. DQ scores and MDM retrieval are newly named as MCP-exposed; whether they are new servers or re-hosted ones is not determinable, and no enforcement or logging detail is given [S-2026-09-15-salesforce-aws-dreamforce-informatica-headless]. The same story extends Data 360 zero copy across AWS Iceberg/Aurora/RDS/SageMaker Lakehouse with the assertion that governance controls in “either environment” are unchanged, and relays an AWS claim of “ISO 42001 compliance and full audit trails built in” for Bedrock model choice — an uncertificated platform assertion, not something a regulated firm can inherit [S-2026-09-15-salesforce-aws-dreamforce-informatica-headless] [inference on reliance].

Detail

The shape of the category

Three functional layers are emerging, often combined across partnerships. A context/catalogue layer (Collibra, Informatica) supplies the governed meaning — certified definitions, ownership, quality scores, usage policies — that an agent needs to act correctly. An access-enforcement layer (Immuta) constrains what data an agent may actually reach. A data-foundation layer (Informatica) keeps the underlying data quality, master data and lineage trustworthy. The vendors are interoperating rather than each owning the full stack: Collibra and Immuta both plug into the same Snowflake Horizon/Cortex agentic surface, and Collibra also integrates deeply with Databricks Unity Catalog [S-2026-06-02-collibra-snowflake-ai-command-center][S-2026-06-02-immuta-snowflake-agentic-access][S-2026-06-16-collibra-databricks-governance].

On-behalf-of, least-privilege access

The most concrete control is Immuta’s session-level, on-behalf-of role vending: rather than an agent holding broad standing privileges, Immuta issues a unique temporary role scoped to the human the agent is acting for, so the agent inherits exactly that user’s entitlements and no more [S-2026-06-02-immuta-snowflake-agentic-access]. This is the agentic analogue of long-standing least-privilege and data-minimisation principles. As of 15 June 2026 the model spans both major lakehouse/warehouse platforms: on Databricks, Immuta adds task-scoped, auto-expiring permissions (Intent-Driven Access Control) and claims enforcement down to cell level with the audit trail kept inside Unity Catalog — the first release in this category to assert a specific audit-trail location for agent access decisions, though the evidence standard of that trail is vendor-claimed only [S-2026-06-15-immuta-databricks-agentic-access].

Traceability and oversight

Collibra positions its AI Command Center as a “control layer” capturing metadata, runtime lineage and trust signals to give “real-time visibility across the full AI lifecycle, with end-to-end traceability spanning data sources, models, decisions, and outcomes” [S-2026-06-02-collibra-snowflake-ai-command-center][S-2026-06-16-collibra-databricks-governance]. The breadth of that claim is exactly what regulated firms need for AI oversight — but the releases do not map it to specific evidentiary thresholds (e.g. EU AI Act Article 12 logging, or BCBS 239 reconciliation), so the regulatory sufficiency is unestablished [speculative — vendor framing].

Vendor-marketing caveat

All of the above are vendor or vendor-reported claims. They are primary sources but self-interested; capability descriptions, “control”/“trust” language and the implied regulatory fit are marketing positions, not independently verified facts, and no EU/UK FS deployment is cited [S-2026-06-16-collibra-databricks-governance].

Practical Applications

For Paul’s practice this category is most relevant to: Governance Framework Design (where agentic access controls and context-grounding become control objectives in a target operating model); Independent Governance Assurance (testing vendor claims — e.g. whether “on-behalf-of” role vending and runtime lineage actually produce audit-ready evidence); and Regulatory Readiness & Evidence (mapping these tooling capabilities to BCBS 239, GDPR, DORA and EU AI Act control requirements, and flagging the gap between marketing and demonstrable compliance). A neutral, capability-vs-claim framing is the value Paul adds versus vendor narratives [S-2026-06-02-immuta-snowflake-agentic-access][S-2026-06-16-collibra-databricks-governance].

  • relates-to → Snowflake — warehouse-native governance entrant; Cortex AI Gateway + task-scoped third-party agent access [S-2026-07-28-snowflake-cortex-ai-gateway].
  • relates-to → Ataccama — data-quality/“data trust” entrant; Data Trust Index + MCP Server + OSI (now Apache Ossie) converter carrying DQ signals into the semantic layer, context/trust layer [S-2026-06-02-ataccama-data-products-osi][S-2026-09-09-ataccama-apache-ossie-converter].
  • relates-to → SAP — ERP-platform instance of request-based, documented data-product access (SAP Business Data Cloud wave 2026.19); human-workflow governance, not agent-facing [S-2026-09-09-sap-bdc-data-product-governance].
  • relates-to → Collibra — context/catalogue + AI Command Center vendor in this category.
  • relates-to → Immuta — access-enforcement vendor in this category.
  • relates-to → BigID — DSPM-side access-enforcement entrant; Agentic Access Control (data-sensitivity scoping) + Intent-Based Activity Monitoring [S-2026-08-04-bigid-agentic-authority-layer].
  • relates-to → Cyera — DSPM-side M&A entrant; $1bn Oasis Security (non-human identity) acquisition completed 3 Sep 2026, data-classification and agent/machine identity governed as one platform [S-2026-09-03-cyera-oasis-completion][S-2026-07-31-kuppingercole-cyera-oasis-first-take].
  • relates-to → Informatica — data-foundation + MCP context vendor in this category.
  • relates-to → Atlan — metadata-lakehouse catalogue + AI-governance entrant; 2026 Gartner D&A Governance Leader [S-2026-06-04-atlan-gartner-leader-agentic-governance].
  • relates-to → Microsoft Purview — Microsoft-estate governance/posture entrant over Copilot/Agent 365/Claude use [S-2026-06-16-microsoft-purview-whats-new].
  • relates-to → Monte Carlo — observability-layer entrant; agent observability on Databricks Agent Bricks [S-2026-06-15-monte-carlo-agent-bricks].
  • relates-to → Databricks — lakehouse-native governance entrant; Unity AI Gateway + Unity Catalog AI-asset governance [S-2026-06-16-databricks-unity-ai-gateway-summit].
  • relates-to → Precisely — data-quality/data-integrity entrant; agentic DQ-rule generation with a human-oversight claim [S-2026-06-26-precisely-data-integrity-ai-agents].
  • relates-to → Komprise — unstructured-data/storage-layer entrant; Iceberg exposure of the file estate with entitlement-preserving access [S-2026-06-23-komprise-transparent-file-tables].
  • relates-to → Qlik — BI/data-integration-layer entrant; DQ agents + trust scores + governed Data Products + expanded MCP agent access [S-2026-07-02-qlik-data-engineering-ga].
  • relates-to → CData — connectivity-layer entrant; governed MCP server with identity-aware access + audit logging (no dedicated page yet) [S-2026-06-23-cdata-connect-ai-governed-mcp].
  • relates-to → BCBS 239 and Data Lineage — lineage/traceability claims bear directly on BCBS 239 obligations.
  • relates-to → EU AI Act — agent oversight, logging and traceability bear on AI Act requirements.
  • relates-to → AI Governance Maturity Gap — vendors pitch these tools as the response to the governance-lag gap [S-2026-06-03-informatica-agentic-data-management].

Open Questions

  • Do “on-behalf-of” session roles and “runtime lineage” capture produce logs that satisfy DORA, GDPR and EU AI Act (Art. 12) evidentiary requirements? No release specifies retention, immutability or audit format. Partially addressed at claim level: Immuta’s Databricks release asserts “a full audit trail maintained inside Unity Catalog” and “audit-ready” Comply App outputs, but specifies neither retention nor immutability [S-2026-06-15-immuta-databricks-agentic-access].

  • Is any of this deployed in EU/UK regulated FS at production scale? No reference customers named.

  • Are EU data-residency / sovereignty configurations available for these agentic services? Not addressed.

  • Does auto-generated sensitivity labelling (Informatica) reach a standard defensible for GDPR classification without human review?

  • Now that AI-generated DQ rules are GA (Collibra, Qlik), is the generated rule logic defensible and reconstructable as BCBS 239 / FCA-PRA data-quality evidence, or efficiency tooling still requiring steward-authored validation? [S-2026-07-10-weekly-vendor-synthesis]

  • Were the catalogue/privacy pure-plays (Alation, Atlan, BigID, OneTrust, Immuta, Privacera, Securiti, Monte Carlo) quiet in the week to 10 July because of a summer lull or repositioning ahead of H2 launches? A deliberate sweep of this set on 10 July found no new announcements — most recent moves date to May–mid-June — consistent with a lull, but motive undetermined; next catalysts are Informatica’s IDMC release (26 July) and Qlik’s CEO transition (31 July) [S-2026-07-10-weekly-vendor-synthesis][S-2026-07-10-vendor-scan-note]. Partially resolved 2026-07-24: for Alation the quiet was pre-launch repositioning — AIOS launched 14 July; the remaining pure-plays stayed quiet a third consecutive week, motive still undetermined, and a deliberate H2-launch scan is flagged [S-2026-07-24-weekly-vendor-synthesis]. Updated 2026-07-31: a fourth consecutive quiet week for Alation, Atlan, OneTrust, Immuta and Monte Carlo (BigID’s Peer Insights citation and Ataccama’s CPO roadmap event were only light signals); the H2-launch scan is still due [S-2026-07-31-weekly-vendor-synthesis]. Updated 2026-08-07: the quiet-spell question is now resolved for Alation (AIOS company-level repositioning, re-captured this week) but stands a fifth week for Atlan, OneTrust, Immuta, Monte Carlo, Ataccama, BigID, Informatica and the lineage specialists (Solidatus, MANTA); Collibra was additionally silent in its first week after the CLI lineage-harvester EOL, so no migration-outcome signal exists yet [S-2026-08-07-weekly-vendor-synthesis]. Updated 2026-08-11: resolved for BigID — its quiet ended with the 4 Aug Black Hat-week double announcement (agent authority layer + AI sovereignty positioning), consistent with the H2-launch hypothesis; still standing for Atlan, OneTrust, Immuta, Monte Carlo, Ataccama and the lineage specialists [S-2026-08-04-bigid-agentic-authority-layer]. Updated 2026-09-11: resolved for Ataccama (two moves in the week to 11 Sep — Ossie converter, Benelux distributor — following its 4 Aug CEO change) and, in the adjacent catalogue/DQ set, Alation, Qlik and Collibra also moved; still standing for Atlan, OneTrust, Immuta, Privacera, Securiti and the lineage specialists, now joined by Informatica and IBM — a deliberate sweep of this set is flagged again [S-2026-09-11-weekly-vendor-synthesis].

  • If AI-generated DQ rules (vendor) and AI-assisted definition/rule authoring (Paul’s C-QA / DQ-1…8) raise the same defensibility question, what single evidence standard should an assurance review apply to both — and does “human oversight over the rules being created” satisfy it, or is source-anchored, reconstructable rule logic the higher bar? [S-2026-07-10-weekly-briefing]

  • With NHI management “closing as a separate purchase” (SailPoint–Entro, Cyera–Oasis, 1Password–Apono per KuppingerCole), where should an EU/UK FI anchor the agent-identity half of agent-access control — the identity platform (IGA/PAM), the data-security/DSPM platform, or the data substrate’s gateway — and what evidence (credential rotation, orphaned-identity ownership, clean decommissioning) should an assurance review demand regardless of which layer owns it? KuppingerCole expects mature IGA/PAM shops to keep it in the identity platform; no source addresses the FS-specific answer [S-2026-07-31-kuppingercole-cyera-oasis-first-take][S-2026-09-03-cyera-oasis-completion].

Tensions / Contradictions

On how Oasis Security is integrated into Cyera post-acquisition:

  • KuppingerCole [S-2026-07-31-kuppingercole-cyera-oasis-first-take] (medium, pre-completion) stated that “Oasis is expected to run as a separate unit after close”, calling this an “independent-unit hedge” that “defers the unified control plane the deal is premised on” and warning that “‘Independent unit’ and ‘unified platform’ cannot both be true in the first year”.
  • Cyera’s completion release [S-2026-09-03-cyera-oasis-completion] (medium for transaction facts, self-interested) states that “the Oasis platform will operate as Cyera Identity, the dedicated identity pillar within Cyera’s platform, connecting directly to Cyera’s data intelligence layer” — pillar-of-platform wording, with no reference to a separate or independent unit.
  • Where they actually disagree: possibly not at all — a “dedicated pillar” may be the same operating arrangement KuppingerCole described under a different label, or it may signal a tighter integration plan than the LOI implied. Neither source gives an integration timeline or organisational detail that would settle it.
  • Status: unresolved — a testable item for any buyer (ask what “Cyera Identity” ships as, and when).

On the “nearly 500%” NHI-growth statistic:

  • Cyera [S-2026-09-03-cyera-oasis-completion] asserts NHIs in Fortune 500 companies “grew nearly 500% in the last six months alone”.
  • KuppingerCole [S-2026-07-31-kuppingercole-cyera-oasis-first-take] accepts the direction of the trend from its own research but treats the specific rate as “the acquirer’s own figure, offered without published methodology” that it “would not build a business case on”.
  • Where they actually disagree: on evidentiary weight, not direction. Status: unresolved; the wiki carries the figure only as a vendor claim.

Sources