skip to content
The Weighted Average

Enterprise AI & Work

Snowflake Wants the Agent Control Plane

Cortex AI Gateway will govern 100+ MCP servers as one large enterprise can face 160,000 non-human identities.

A woman working on a laptop at a desk in an office
A woman working on a laptop at a desk in an office. Photograph by Christina @ wocintechchat.com M

Snowflake plans to put more than 100 MCP servers behind one policy, identity, audit, routing, and cost layer. The scale explains the timing: at a reported 10:1 non-human-to-human identity ratio, a 16,000-person enterprise already implies 160,000 machine identities before counting every tool those agents touch.

The warehouse is reaching for the authorization decision

Cortex AI Gateway will govern first-party Snowflake agents such as CoWork and CoCo alongside outside systems including Claude Code and Cursor. It centralizes which models, data, applications, MCP servers, and tools each agent may access; records the sequence of actions; attributes consumption to teams and workloads; enforces spending limits; and routes requests across approved models for cost, quality, latency, and availability.

That bundle makes strategic sense. Model choice is becoming fluid, while authorization and data gravity remain sticky. If Snowflake can become the place where an enterprise decides what an agent may touch, the company protects its position even when the model answering a request belongs to Anthropic, OpenAI, Google, or a smaller vendor. The warehouse stops being a passive source and becomes the agent traffic controller.

The product builds on Snowflake’s May acquisition of Natoma, a 27-person startup focused on enterprise MCP governance. Snowflake has moved quickly from acquisition thesis to integrated gateway. The initial partner set spans 1Password, Aembit, Linx Security, Okta, SailPoint, and Saviynt—six vendors supplying identity, task-scoped credentials, policy, and audit connections.

The most useful concept is dual attribution. An agent action should record both the machine identity that performed it and the human who delegated the task. That fixes the semantic failure in a log saying merely that “Michael” transferred money or modified production when an agent actually executed hundreds of steps under Michael’s broad credentials. The gateway pairs that lineage with task-scoped access so a software actor does not inherit every standing permission its user possesses.

The scale arithmetic turns an abstract governance problem into an operating requirement. SailPoint told VentureBeat that a typical Fortune 500 company has around 16,000 employees and at least ten non-human identities per person. Multiplication gives 160,000 machine identities. Add the tools and APIs each identity invokes and the permission graph moves toward seven figures. A directory group called “finance agents” is not an adequate model for row- and column-level data access at that scale.

Cost governance belongs in the same control point. A seemingly simple question can route through a premium reasoning model, trigger searches, and spawn multiple tool calls. Snowflake says the gateway can attribute spend by team, agent, or workload and stop overruns before they occur. That complements the new stateless MCP architecture: the protocol makes tool traffic easier to scale and route, while a gateway decides whether that traffic is allowed and affordable.

The idea extends the archive’s analysis of agent discovery as a platform layer. Discovery tells agents what exists. Governance decides what this agent, for this human, pursuing this task, may invoke now. Enterprises need both, and the second layer is where liability and lock-in accumulate.

Adopt the control model without surrendering the control plane

Who should switch? Organizations already standardizing sensitive data and AI workloads on Snowflake should test Cortex AI Gateway when its public preview opens. They have the shortest path to row-level policy, cost attribution, and third-party agent visibility. Multi-cloud companies whose agents cross Snowflake, Databricks, SaaS systems, and mainframes should evaluate the architecture but resist making Snowflake the only source of policy truth.

The cost is organizational before it is computational. Security teams must inventory agents, assign non-human identities, map each to a human delegator, define task scopes, classify tools and data, and establish budgets. Platform teams must route agent traffic through the gateway and preserve traces across subagents. Application owners must stop handing agents user API keys. Buying a control plane without doing this identity work produces a dashboard over the same old standing privileges.

Availability is another reason not to declare victory. Cortex AI Gateway is scheduled for public preview soon. Several partner integrations are headed to private preview, while Okta’s integration is planned for the fourth quarter of 2026. Snowflake’s Cortex AI product page describes the broader managed agent stack, but buyers should not confuse that coherent platform story with a generally available enforcement fabric. Production adoption should wait for explicit service levels, exportable audit records, failure behavior, and pricing.

The strongest counterpoint is platform capture. A gateway nearest the data can enforce granular policy efficiently, but it can also make every external agent more dependent on Snowflake. Heterogeneous operators should require standards-based identity, portable policy definitions, complete log export, and a bypass path for workloads whose authoritative data lives elsewhere. Otherwise, “open agent interoperability” becomes a funnel into one vendor’s control surface.

What could break the verdict? Agents may evade centralized routing through direct API access; identity integrations may preserve human attribution without reliably preserving task intent; or the gateway may add latency and cost large enough that teams route around it. Snowflake’s own release separates generally available, public-preview, and private-preview controls, underscoring that governance must reflect different autonomy and risk levels: a read-only research bot and a payment agent should not share one blunt policy template.

Evidence that would strengthen the case includes measured reductions in standing credentials, policy violations blocked before execution, spend variance narrowed, and incident investigations reconstructed end to end. Evidence that would weaken it is incomplete coverage—the sanctioned path looks safe while unregistered agents multiply elsewhere.

The reported Nvidia-Hut 8 data-center loop concentrates physical infrastructure. Snowflake is trying to concentrate logical permission. Operators should borrow the model—distinct machine identity, human attribution, task scope, runtime policy, and cost limits—whether or not they buy this implementation. In the agentic enterprise, the decisive product is not another agent. It is the ability to say which agent may act, why, and at what price.

Sources