From data access to data-aware authorization
Protocols like OpenSharing give providers a standard way to expose shares, schemas, tables, models, and other assets to external recipients. That is useful, but many collaborations need more than asset-level access.
As a provider, you may want to say: “This recipient, application, or AI agent can use this data — but only for approved purposes, through approved computations, and only when the resulting output satisfies our release rules.”
That is what invocate enables. A provider can authorize an escrow agent to access data, run computation, evaluate contractual constraints, and decide whether a particular request should be approved.
The data user still gets a familiar sharing experience. The provider gets more precise control over what uses are allowed.
Data sharing is becoming more dynamic
AI agents need to query enterprise data on behalf of users. Applications need to compute signals from sensitive datasets. Partners need to evaluate whether data is useful before broader access is granted. Providers need to enforce policies that depend on the actual data, the computation being run, and the result being produced.
Traditional access control asks: “Is this recipient allowed to read this asset?”
invocate asks: “Is this request allowed, given the data, the computation, the requester, the policy, and the output?”
That shift makes more advanced forms of data sharing possible.
Built for teams asking questions like
- Can we let AI agents use our data without giving them broad access?
- Can we authorize requests based on what the computation will reveal?
- Can we share useful outputs instead of raw data?
- Can partners evaluate data, models, or signals without copying sensitive assets?
- Can authorization depend on the actual data, not just user identity or metadata?
- Can we enforce data release preferences across Databricks, Snowflake, APIs, cloud storage, and other systems?
What invocate adds to OpenSharing
1. Programmable authorization for AI agents
AI agents make static access control difficult. An agent may need to inspect data, call tools, combine sources, produce summaries, or answer questions on behalf of a user. But giving an agent broad access to a dataset can create unacceptable leakage, compliance, or business risks.
invocate gives providers a governed interface for agent access. The agent can request computations or answers. The escrow agent evaluates the request, runs the approved computation, checks the result, and releases only what satisfies the provider’s policies. This lets organizations enable AI access to shared data without turning every agent action into a manual approval process.
2. Share computations, not just data assets
OpenSharing makes it possible to expose governed assets. invocate makes it possible to expose governed functions of those assets: answers, aggregates, scores, evaluations, reports, model outputs, or other approved results.
The recipient does not always need raw access to the underlying data. In many cases, they need the result of a computation over that data. For example, instead of giving a partner direct access to a table, a provider may allow the partner to run an approved analysis and receive only the resulting metric, summary, or decision signal.
3. Data-driven authorization decisions
Some authorization decisions cannot be made from metadata alone. Whether a request is safe may depend on the actual rows involved, the distribution of values, the sensitivity of the fields, the number of affected individuals, the relationship between multiple datasets, or the output produced by a computation.
invocate makes authorization data-aware. Because the escrow agent can read the data and run computation under contract, it can evaluate conditions such as:
- Is the result sufficiently aggregated?
- Does the output reveal information about a small group?
- Does the request involve restricted fields?
- Does the computation combine data in a prohibited way?
- Does the answer expose more than the provider intended?
- Does this agent action satisfy the provider’s data release preferences?
This enables a more advanced form of authorization: one that depends not just on identity and role, but on the data and computation themselves.
From request to approved output
- A provider exposes data assets through OpenSharing or another controlled interface.
- invocate is authorized as the escrow agent.
- A data user, application, or AI agent makes a request.
- invocate evaluates the request against the provider’s data release preferences and contract.
- invocate reads the necessary data and runs the approved computation.
- The escrow agent checks whether the result satisfies the release rules.
- The approved output is returned to the data user through a familiar interface.
Important: data remains encrypted end-to-end, including during computation.
Programmable & data-aware auth
Providers can participate in more data collaborations without granting unnecessary raw access. Data users can obtain useful outputs without needing direct access to every underlying asset. AI agents can interact with enterprise data through governed interfaces. And data-sharing protocols can be extended from asset access to programmable, data-aware authorization.
Interested in programmable authorization for shared data?
OpenSharing standardizes how governed data assets are shared. invocate adds the escrow layer that decides what requests, computations, and outputs should be allowed.