The shift

From data access to data-aware authorization

Protocols like OpenSharing give providers a standard way to expose shares, schemas, tables, models, and other assets to external recipients. That is useful, but many collaborations need more than asset-level access.

As a provider, you may want to say: “This recipient, application, or AI agent can use this data — but only for approved purposes, through approved computations, and only when the resulting output satisfies our release rules.”

That is what invocate enables. A provider can authorize an escrow agent to access data, run computation, evaluate contractual constraints, and decide whether a particular request should be approved.

The data user still gets a familiar sharing experience. The provider gets more precise control over what uses are allowed.

Why this matters

Data sharing is becoming more dynamic

AI agents need to query enterprise data on behalf of users. Applications need to compute signals from sensitive datasets. Partners need to evaluate whether data is useful before broader access is granted. Providers need to enforce policies that depend on the actual data, the computation being run, and the result being produced.

Traditional access control asks: “Is this recipient allowed to read this asset?”

invocate asks: “Is this request allowed, given the data, the computation, the requester, the policy, and the output?”

That shift makes more advanced forms of data sharing possible.

Who it's for

Built for teams asking questions like

  • Can we let AI agents use our data without giving them broad access?
  • Can we authorize requests based on what the computation will reveal?
  • Can we share useful outputs instead of raw data?
  • Can partners evaluate data, models, or signals without copying sensitive assets?
  • Can authorization depend on the actual data, not just user identity or metadata?
  • Can we enforce data release preferences across Databricks, Snowflake, APIs, cloud storage, and other systems?
What invocate adds

What invocate adds to OpenSharing

How it works

From request to approved output

  1. A provider exposes data assets through OpenSharing or another controlled interface.
  2. invocate is authorized as the escrow agent.
  3. A data user, application, or AI agent makes a request.
  4. invocate evaluates the request against the provider’s data release preferences and contract.
  5. invocate reads the necessary data and runs the approved computation.
  6. The escrow agent checks whether the result satisfies the release rules.
  7. The approved output is returned to the data user through a familiar interface.

Important: data remains encrypted end-to-end, including during computation.

The result

Programmable & data-aware auth

Providers can participate in more data collaborations without granting unnecessary raw access. Data users can obtain useful outputs without needing direct access to every underlying asset. AI agents can interact with enterprise data through governed interfaces. And data-sharing protocols can be extended from asset access to programmable, data-aware authorization.

early access

Interested in programmable authorization for shared data?

OpenSharing standardizes how governed data assets are shared. invocate adds the escrow layer that decides what requests, computations, and outputs should be allowed.

Join the Waiting List