discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Snowflake buys Natoma to help freeze out rogue agents

Snowflake is buying Natoma to add permission checks and audit controls for AI agents that act inside enterprise apps.

By O'Ryan Johnson·May 28·theregister.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Snowflake plans to fold Natoma into its agentic control plane so AI agents can use tools like Slack, email, calendars, Jira, and Google Drive from governed environments with identity checks, policy enforcement, and audit trails.

Why it matters

This is another sign that enterprise AI is moving from chat to action, which raises the security bar. The story matters because the value of agentic systems now depends on controlling what they can touch, change, and prove they did.

Snowflake is like a big office full of important files and tools. It wants smart computer helpers to do chores, but only the right chores.

Natoma is like a security desk for those helpers. It checks whether a helper is allowed to open a door, send a message, or make a change.

The idea is to let the helpers save time without letting them wander around the office doing things they should not do. That is the big safety part.

Analysis

What Snowflake is buying

Snowflake said it will buy Natoma, a startup that built a gateway for managing AI agent permissions across enterprise applications. The pitch is straightforward: let agents do useful work inside business systems, but keep those actions inside a controlled environment instead of letting them roam freely across tools and data.

Security and control

Natoma sits in front of Model Context Protocol servers, which let agents connect to external software tools. According to the article, the platform checks identity, applies access rules, and records audit information at the level of individual tool calls. That means the system can decide whether a request should go through based on who asked, what permissions they have, and what action the agent is trying to take.

Snowflake’s CEO framed Natoma as part of a broader “agentic control plane,” where agents can send email, summarize Slack conversations, check calendars, or open Jira tickets while still being governed by enterprise security controls. The company says the goal is not just convenience but controlled action with permissions, observability, and policy enforcement built in.

Broader strategy

The deal fits a larger push by Snowflake into AI and infrastructure. The article says this is the company’s sixth acquisition announcement since June 2025, following deals for Crunchy Data, Datometry, Select Star, Observe, and TensorStax. Snowflake also signed a five-year, $6 billion agreement with AWS on the same day, centered on Graviton-powered compute and AI infrastructure.

Financial terms for Natoma were not disclosed. If the transaction closes, Natoma’s 20 employees would join Snowflake.

Key points

  • Snowflake plans to buy Natoma, a startup focused on AI agent permissions and governance.
  • Natoma works as a gateway for MCP servers and checks identity, access, and audit controls for tool calls.
  • Snowflake says the acquisition supports its broader "agentic control plane" strategy for governed AI actions.
  • The deal terms were not disclosed, and Snowflake said Natoma has 20 employees.
  • The announcement came the same day Snowflake signed a five-year, $6 billion AWS agreement.

Originally reported at

theregister.com

Discernion covers the story. Read the full piece at the source.

Tagssecurityai-agentstechbusinessautomation

Author

O'Ryan Johnson

Intelligence analysis by

GPT-5.4 Mini

Published

May 28, 2026

Source

theregister.com

Share

Topics

securityai-agentstechbusinessautomation

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…