Snowflake buys Natoma for AI agent control

Snowflake is acquiring Natoma to bring governed access for AI agents into its platform, enhancing security and control for enterprise applications.

4 min read
Snowflake logo alongside Natoma logo.
Snowflake announces intent to acquire Natoma.· Snowflake
Visual TL;DR
AI Agents RiskDriver
From the article 6 mentionsThe current landscape sees many AI agents operating outside of IT's direct oversight, creating potential risks like data leakage and unauthorized access.
Enterprise Needs ControlDriver
From the articleEnterprises need a way to enable agentic productivity without sacrificing security.
Snowflake Acquires NatomaCore
From the article 4 mentionsSnowflake announced its intent to acquire Natoma, a move designed to bring governed access for AI agents to enterprise environments.
Natoma's PlatformCore
From the article 6 mentionsNatoma's platform functions as a centralized gateway, enforcing identity, policy, and audit trails at the tool-call level.
Governed AccessEffect
enabling secure agent connections to enterprise applications at scale
From the article 4 mentionsThis extends the vision of Governed Agentic Access.
Enhanced SecurityOutcome
providing crucial visibility into agent actions and permissions
From the article 6 mentionsThe ultimate goal is an invisible integration for end-users, where administrators enable enhanced AI capabilities without requiring users to alter their workflows.
AccountabilityOutcome
From the article 2 mentionsThis provides crucial visibility into agent actions, permissions, and authorization, extending accountability to new operational frontiers.

Snowflake announced its intent to acquire Natoma, a move designed to bring governed access for AI agents to enterprise environments. The deal aims to bridge the gap between the promise of autonomous AI agents and the stringent security and control requirements of businesses.

The current landscape sees many AI agents operating outside of IT's direct oversight, creating potential risks like data leakage and unauthorized access. Enterprises need a way to enable agentic productivity without sacrificing security.

Natoma's platform functions as a centralized gateway, enforcing identity, policy, and audit trails at the tool-call level. This provides crucial visibility into agent actions, permissions, and authorization, extending accountability to new operational frontiers.

According to the announcement, integrating Natoma's capabilities will allow Snowflake's Cortex Agents to securely connect with daily enterprise applications at scale. This extends the vision of Governed Agentic Access.

Post-acquisition, Snowflake customers could use a unified interface to manage tasks like summarizing emails, opening support tickets, or updating CRM records, all underpinned by built-in governance and security controls.

The integration is expected to enrich Snowflake data with context from enterprise applications, leading to smarter AI actions. Snowflake positions itself as the foundation for data and action workflows, emphasizing control and security.

Snowflake has already piloted Natoma internally, reporting immediate benefits in summarizing emails and searching across disparate applications without context switching.

The company likens agent identity to providing an intern with a credit card, complete with spending limits and restricted store access. This ensures accountability and boundaries for AI systems that explore various operational paths.

The ultimate goal is an invisible integration for end-users, where administrators enable enhanced AI capabilities without requiring users to alter their workflows. Security shifts from being a barrier to becoming an enabler.

This Snowflake Natoma acquisition follows Snowflake's earlier introduction of AI Guardrails for prompt injection protection, signaling a broader strategy for secure enterprise AI.

The Natoma team's expertise in identity governance, with previous exits to Okta and Google, is seen as a significant asset.

The deal is subject to customary closing conditions.

© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.