NEW
Agentic Data Access is generally available.Short-lived, task-scoped access for every agent.
Learn more

AI is changing how
every employee gets data.

Immuta is the authorization layer for data access. One set of rules decides every request, in under a second, for every human and every agent. Your people get data faster, and nothing sensitive moves without a reason on the record.

Your AI assistant Claude ChatGPT Genie CoCo Glean + any harness ANALYST · CLINICAL DATA · EU
Show me all patients currently enrolled in oncology trials with the trial name and site
Called tool · immuta-agentic-data-access
4 patients currently enrolled in oncology trials:
patient_name enrollment_status trial_name site_name
REDACTED Enrolled PROT-1004: Oncology Ph II UCLA Medical Center
REDACTED Enrolled PROT-1008: Oncology Ph II Cleveland Clinic

Patient names are masked — you don't have a masking exception for that column. Let me know if you want me to request one.

I need access to patient names, can we start a masking exception
Request filed with the data owner. Purpose attached from your question.
EXCEPTION GRANTED · SCOPED TO ONCOLOGY TRIALS · EXPIRES IN 7 DAYS
Approved by the data owner. Re-running your question with the exception applied:
patient_name enrollment_status trial_name site_name
Amara Osei Enrolled PROT-1004: Oncology Ph II UCLA Medical Center
Tomás Ruiz Enrolled PROT-1008: Oncology Ph II Cleveland Clinic
Ask anything about your data

THE ASSISTANT IS YOURS. IMMUTA IS THE AUTHORIZATION IT CALLS.

Deployed where being wrong is not an option.

Banks, pharmaceutical companies, insurers and government agencies run their data access on Immuta.

People don't look for data anymore. They ask an agent to get it.

TODAY
The person finds the data.
Searches for the data
Works out what it means
Requests access
Waits
Finally asks the question
BECOMES
NEXT
The person just asks.
Asks the question
AI finds the data and resolves the context
Authorization
Gets the answer

And an agent asks differently.
More, faster, and without knowing what is sensitive.

SCALE
1,000s
requests an hour, from one agent
BEFORE AGENTS

A few requests a week, from a person.

A person asked for the one table they needed. An agent asks for every table its task might touch, again and again.

SPEED
<1s
to answer, or the agent gives up
BEFORE AGENTS

Days or weeks, and everyone lived with it.

Waiting was fine when a person was waiting. An agent cannot sit in a review queue for a week.

RISK
Everything
it asks for, sensitive or not
BEFORE AGENTS

Only the data was sensitive, not the question.

An agent does not know which columns hold personal data. It asks for whatever finishes the task, so the question itself is now the risk.

01

You can't code this.

The right answer depends on who is asking, what they want and why. That is millions of combinations, and it has to be worked out again on every single request.

60K actors × 40K data objects × 1.2M columns × 200 intents × 30 jurisdictions
02

You can't staff this.

Thousands of requests an hour, each one waiting on an answer before the work can continue. People should still write the rules and own the exceptions. They cannot be the runtime.

Every answer needed in under a second, or the task fails

So access needs an engine.
One that decides every request, at enterprise scale.

That engine is the Immuta Data Authorization Platform.

A new layer in the enterprise stack. One policy engine that governs every human, every agent and every data system, on every request they make.

SET THE RULES · RESOLVE THE EXCEPTIONS · GIVE AGENTS SCOPED ACCESS · PROVE EVERY DECISION
ACTORS
Humans, agents, sub-agents
AUTHORIZATION LAYER
Policy Enforcement
Author once, enforce everywhere
Request Workflows
Access and exceptions, everywhere
NEWAgentic Data Access
Just-in-time permissioning
NEWAgentic Compliance
Audit, triage, prove compliance
IMMUTA POLICY ENGINE NATIVE INSIDE YOUR DATA LAYER
DECISION
ALLOW
MASK
FILTER
DENY
ESCALATE
NATIVE ACROSS THE ESTATE
WAREHOUSES LAKEHOUSES DATABASES CLOUD STORAGE APIS SAAS

All of data access governance. One platform.

Four modules on one policy engine. Adopt one, add the rest — together they automate the access workflow end to end.

01
01 · AUTHORCORE

Policy Authoring & Enforcement

Write the rule once, in plain language. Immuta compiles it into the real controls inside your data infrastructure.

SCALEOne rule covers every system, instead of one per system.
Policies › Data Policies › Policy Builder
Global Data Policy Builder
Policy name
How should this policy protect the data?
Click here to select an action and begin building your policy
Cancel Stage Policy Activate Policy
Policies › Data Policies › Policy Builder
Global Data Policy Builder
How should this policy protect the data?
Select an action
Mask
Limit usage to purpose(s)
Minimize
Restrict
Policies › Data Policies › Policy Builder
How should this policy protect the data?
Maskcolumns taggedSelect tags ▾usingmasking type ▾
Discovered.PII
Discovered.Person Name
Discovered.Electronic Mail Address
Policies › Data Policies › Policy Builder
How should this policy protect the data?
Maskcolumns taggedDiscovered.PIIusingmasking type ▾
NULL
Hashing
Constant
Regex
Policies › Data Policies › Policy Builder
How should this policy protect the data?
Maskcolumns taggedDiscovered.PIIusingNULLfor everyone ▾
for everyone
for everyone except when user is a member of group
for everyone except when user has attribute
Group Legal
Policies › Data Policies › Policy Builder
Global Data Policy Builder
How should this policy protect the data?
Maskcolumns taggedDiscovered.PIIusingNULLfor everyone exceptwhen user is a member of groupLegal
Enter Rationale for Policy (Optional)
Add
Policies › Data Policies › Policy Builder
Mask PII Columns 1 rule
Where should this policy be applied?
On data sources ▾ with columns tagged Discovered.PII ▾
+ Add Another Circumstance
Cancel Stage Policy Activate Policy
Policies › Data Policies › Policy Builder
Mask PII Columns ● ACTIVE
Maskcolumns taggedDiscovered.PIIusingNULLexceptLegal
Enforced everywhere the data lives EVERY CONNECTED SYSTEM
NO CODE WRITTEN · NOTHING TO MAINTAIN
02
02 · RESOLVECORE

Request Workflows & Exceptions

Policy answers the routine requests on its own. People decide the genuine exceptions, with the reason attached.

SPEEDRoutine access is instant. Exceptions get one fast decision.
Customer Transaction History
Details Columns Members
Search Request masking exception
NameTagsMasking applied
email SensitiveElectronic Mail ⁃ Masked
first_name SensitivePerson Name ⁃ Masked
gender GenderSensitive ⁃ Masked
Request masking exception
Data Product: Customer Transaction History
2 Columns selected Clear all
email "MARKETPLACE_DEMO"."FINANCE"
first_name "MARKETPLACE_DEMO"."FINANCE"
gender "MARKETPLACE_DEMO"."FINANCE"
Submit
Customer Transaction History
Details Columns Members
SuccessMasking exception request submitted
Access Requests
Search Status: Pending
StatusUserTypeRequest
⏱ Pending Ruby Touw Masking exception Multiple columns
⏱ Pending Kyle Lilly Data access Schema Patients
⏱ Pending C. Analyst Data access Customer credit
Masking exception request ⏱ Pending
Data product: Customer Transaction History
⏱ Temporarily approve
Highly sensitive so dropping access to 1 week
Requested 1 Month Approve for 1 Weeks
Submit determination
Customer Transaction History ⏱ Temporarily approved
Details Columns Members
NameTagsMasking applied
email SensitiveElectronic Mail
first_name SensitivePerson Name
gender GenderSensitive
EXPIRES IN 7 DAYS · RECORDED WITH THE REASON
03
03 · GRANTNEW

Agentic Access

Every agent is a first-class identity acting for a named person, scoped to the task in front of it.

SCALEThousands of agents, each scoped without an approval.
AI ASSISTANT
Summarise Q3 trial outcomes
Requesting access to trial data…
IDENTITY RESOLVED
AGENT research-agent #4471
ON BEHALF OF
HUMAN m.okafor@ Clinical analyst
Both are first-class identities. The agent is never anonymous.
SCOPE DERIVED
Maya can access14 sources
This task needs2 sources
Agent is vended2 sources
Never more than the human. Only what this task needs.
CREDENTIAL VENDED
IMMUTA_VENDED_<AGENT>
_<USER>_<UUID>
trials.outcomes trials.patients · masked
TTL 00:14:59
DELEGATION
AGENT research-agent 2 sources
SPAWNS
SUB-AGENT stats-agent 1 source
Still acting for Maya. Delegation can only narrow, never widen.
TASK COMPLETE
TTL 00:00:00REVOKED
The credential is gone. Nothing to clean up, nothing left behind.
Recorded: agent, human, scope, duration
04
04 · PROVENEW

Comply

Every access decision is recorded as it happens, so compliance becomes a question you ask.

SPEEDEvidence reports in seconds, not a six-week hunt.
Samantha Jones ▾
✎ New Chat
⌕ Search Chats
HISTORY
Which agents touch…
What policies grant…
Top reviewers by re…
Access patterns by…
How can I help you today?
Ask me anything about your data and access.
Press Enter to send · Shift + Enter for new line
Which policies grant the most access? Top reviewers by requests approved
Which agents touched sensitive data this week?
Three agents read tagged-sensitive columns:
Research agent · for m.okafor41 reads
Claims copilot · for r.touw28 reads
Finance agent · for k.lilly9 reads
Why are they using it, and how sensitive is it?
AGENTPURPOSESENSITIVITY
Research agentTrial outcomesPHI
Claims copilotClaim triagePII
Finance agentQuarter closeInternal
Flag anything outside its stated purpose
Research agentOUT OF SCOPE
Read finance.ledger_detail — outside its task scope.
Revoke scopeAsk the owner
Scope revoked · recorded
78AGENTS 1.4MDECISIONS 1FLAGGED
Evidence pack readyQ3 · PHI ACCESS

One decision path, whoever is asking.

A person or an agent asks for data. The same four steps run before a single row moves.

WHO IS ASKING
HUMANMaya Okafor
Clinical analyst · Research purpose
SELECT * FROM trials.patients
AGENTResearch agent
On behalf of Maya Okafor · Task #4471
Summarise Q3 trial outcomes
Immuta decidesEVERY REQUEST · SUB-SECOND
01
Identify who is asking
Resolve the identity, and if it is an agent, the named person it is acting for.
02
Walk the review flow
The request runs down a decision tree your team authored: request type, data tags, group, purpose and answers on the form.
03
Land on an outcome
Approve automatically and time-bound it, deny automatically, or route to the one reviewer who should decide.
04
Write the record
Who asked, for whom, and the exact branch the request took to get there.
YOUR DATA
CONTROLS APPLIED IN PLACE
WarehousesLakehousesDatabasesCloud storageAPIsSaaS
ROWS RETURNED
patient_id8841 patient_name•••••••• outcomeremission

Step 04 is not the end of the path.

The record it writes is what the next request is decided against.

Every decision teaches the next one.

Most governance programs get slower as they scale. This one gets faster.

1st

The first request of its kind takes a person.

100th

The hundredth takes a rule someone already wrote.

1,000th

The thousandth takes nothing at all.

Your reviewers stop answering the same question and start setting the standard.

Access request
A person or an agent asks
Determination
Policy decides, or a person
Enforced natively
Applied where the data lives
Evidence recorded
The decision and its reason
GOVERNANCE MEMORY
Every determination, and why it was made
OVER TIME, THE SHARE OF REQUESTS NEEDING A PERSON APPROACHES ZERO

The hardest estates in the world run their access on Immuta.

Regulated, global, and under real scrutiny. Same engine underneath all of them.

JPMorgan consolidated access controls for 150,000 global users in a single policy layer.

General Motors automated 10M+ access grants, cutting provisioning from 5 days to 2 minutes.

Roche centralized control across 50 siloed teams with Immuta policies.

Booking standardized 40,000 Snowflake and S3 tables with Immuta policies.

Aviva reduced time to Snowflake data from 30 days to 2 days.

Stellantis reduced 18,588 legacy permissions to 6 Immuta policies.

Eli Lilly shares trial data for research in minutes, without exposing patients.

AstraZeneca governs research data across therapeutic areas with one policy set.

Merck protects 7M queries a month on regulated data.

MiniMed governs device and patient data for clinical use, with sensitive fields masked by default.

The proof is in production. At the companies least able to get it wrong.

10M+
access grants

Automated, cutting provisioning from five days to two minutes.
GENERAL MOTORS
18,588
→ 6 policies

Legacy permissions collapsed into six Immuta policies.
STELLANTIS
30
→ 2 days

Time to get an analyst working in Snowflake.
ROCHE
150,000
global users

Access controls consolidated into a single policy layer.
J.P. MORGAN
7M
queries a month

Protected on regulated data.
MERCK
50
siloed teams

Brought under one set of controls, without slowing research down.
ROCHE
CERTIFICATIONS AND FRAMEWORKS
SOC 2 TYPE II

Audited annually for security, availability and confidentiality.

ISO 27001

Certified information security management system.

FEDRAMP MODERATE

Authorized for use by US federal agencies.

HIPAA

Supports covered entities and their business associates.

GDPR

Processing and transfer controls aligned to EU requirements.

PCI DSS

Controls for environments handling cardholder data.

Start where your access model is breaking.

One working session with your AI, data and security leaders to pick the first deployment point.
The same policy engine carries the other three.