Data Contracts and Data Products: What AI Agents Need to Access Enterprise Data
•
Simon Harrer & Kris Peeters
AI agents need their own access rules. Simon Harrer, Entropy Data, on data contracts, data products and purpose-based access control.
AI agents will soon request access to company data the same way employees do today, except they cannot pick up the phone and ask a colleague for help when they hit a wall. That gap is why Simon Harrer, CEO and co-founder of Entropy Data, believes every data leader needs a data marketplace built for agents first and people second.
Simon Harrer returns to the Data Playbook podcast for his second conversation with our host and CEO, Kris Peeters. Entropy Data spun off from the consulting firm innoQ a year ago, launched without external funding, and reached profitability on inbound demand alone, mostly from companies already working with data products and data contracts.
Kris and Simon start with the difference between the two terms. A data contract encodes the guarantees around a dataset: its terms of use, its service levels, its quality checks, and who to contact when something breaks. A data product is the architectural unit that groups one or more contracts together, along with the pipeline and code behind them. Simon Harrer argues the real value sits in the contract, because that is where a company writes down what a consumer, human or agent, can and cannot do with the data.
That distinction matters because agents behave differently from people. An agent can request access to a dataset for one stated purpose and later use that access for something else, with no human in the loop to catch the change. Entropy Data addresses this with purpose-based access control: every query carries a stated purpose, and the system checks it against the original request, the data contract, and company-wide policy, using AI to catch AI misuse.
We also get a plain definition of the semantic layer: the business data model that links physical tables to the concepts a company actually works with, an order, a customer, a shipping address, along with the governance metadata attached to each field, so a system can flag a customer email as personal data before anyone touches it. Harrer and Kris walk through three levels of data lineage, from semantic relationships down to the physical pipeline, and Harrer ranks the semantic layer as the most useful of the three, because it lets an agent recognise that two different tables both point to the same order.
The conversation closes on a problem that reaches beyond data products. Simon Harrer runs most of Entropy Data's own product development through Claude Code, including a data product builder that turns a data contract into a working pipeline. Building has stopped being the bottleneck. Deciding who owns a data product, and what that ownership commits someone to, has not.
The episode draws on the BARC research spotlight Entropy Data sponsored, A Data Marketplace Is What Your Agents Need, written by BARC analyst Florian Bigelmaier.
Latest
Data Contracts and Data Products: What AI Agents Need to Access Enterprise Data
AI agents need their own access rules. Simon Harrer, Entropy Data, on data contracts, data products and purpose-based access control.
Data Mesh After the Hype: Why Data Products Matter More Than Ever
Why Data Products outlasted Data Mesh, where Data Contracts fit, and how AI is changing modern data architecture.



