Governing Human & Agent Access to Data Stores (Late 2025)

Governing Human & Agent Access to Data Stores (Late 2025)

Research for LessDB positioning on "full human and agent control and governance."

1. How enterprise data platforms govern human access today

The standard primitives a database must expose to be considered "enterprise governable":

Vendor framing: Dremio Data Governance, ThoughtSpot Governance, and Microsoft Dataverse all converge on the same list — authN, authZ, lineage, audit, classification/tagging, retention.

2. Governing AGENT access specifically

Agent governance is nascent but concretely productized:

3. Emerging standards & specs

4. "Shared system of record for humans and agents"

This is emerging as an explicit category:

The architectural takeaway for LessDB: a single embedded store that is both the query engine and the audit/authority source is the "shared system of record" — the differentiators are per-principal credentials (human via LDAP/AD, agent via OAuth client credentials) and a unified audit log.

5. What an OSS embedded DB needs to compete on governance

Gap analysis for LessDB

Key sources