Your agents call tools. Those tools touch data. AI Data Reach tracks the complete round trip — from the user and agent, to the tool and again for the data behind it.
Nested data tables and schemas are applied grants. Arm a role and learn what role is possible — and what comes next.
Tool permissions answer whether an agent may call query. They say nothing about which rows come back. AI Data Reach asks the second question, and asks it on the way through.
Governance that cannot be inspected, overridden, or recovered from is governance nobody trusts in production.
Point it at a warehouse and the hierarchy arrives on a schedule — catalogs, schemas, and tables, refreshed without a hand-maintained inventory.
A grant on a catalog reaches every schema and table inside it, including ones created later. Drop a deny lower down to carve out the exception.
Every decision explains itself in the same sentence the gate used. The screen and the enforcement cannot drift apart, because they call the same function.
Filtered through the resolver, so results never reveal an object the searcher cannot reach — and ranked to surface denies and credential-vending grants first.
Each namespace can run in observe or enforce mode. Turning enforcement off takes platform admin — a tenant cannot switch off its own governance.
Objects whose owner no longer resolves can be claimed by an admin, recorded as break-glass. Nothing is permanently unadministrable.
Snowflake is available today. The rest are in progress — listed here rather than implied, so you can tell which is which.
Point AI Data Reach at a warehouse and see the graph against your own catalog.