Gateways solve access. Datris solves supply.

"Agent control plane" usually means an MCP gateway: authentication, routing, and approvals in front of tools the agent already has. Datris is not a gateway. It is the layer that gets the data in the first place: acquires it, validates it, lands it in the stores you already run, and hands the agent a receipt. Many teams run both.

CapabilityMCP gatewayDatris
Credential brokeringAuth to tools the agent already hasVault-brokered secrets to taps; the agent never holds a key
Routing and approvalsYes — the core jobAgent Policy: per-action allow / approve / refuse
Acquiring data from a sourceNoAI-generated taps for APIs, files, databases, documents
ValidationNoPlain-English rules on every row; quarantine at the door
Landing in your storesNoPostgres, Mongo, Snowflake, Databricks, S3, five vector DBs
Per-row provenanceRequest logRun, script commit, source, as-of, per landed row
RecoveryRetry the callAI error explanation; the agent repairs and reruns
Self-hostedVariesAlways; no managed service

Reach is solved. Coherence is not.

A gateway can hand an agent a thousand tools. What it cannot do is make the data behind those tools arrive validated, landed in one shape, and traceable to its source. That is the job a data team has always done by hand, and it is the job Datris gives the agent a governed way to do.

Databricks and Snowflake now describe their own agent-governance layers as control planes. Those layers govern the intelligence that reads data already inside their lakehouse. Datris is neutral: it loads the lake, it does not live in it. Read Databricks Just Validated the Layer We Bet On and Load the Lake. Don't Live in It.

When you want both

Put the gateway in front of every tool your agents call, including Datris. Let Datris own acquisition, validation, landing, and provenance. The gateway's request log says which agent called what. The Datris receipt says which rows landed, from where, under which commit.