{
  "data": {
    "category": {
      "area": "business",
      "capabilities": [
        "knowledge.search",
        "data.catalogue",
        "data.lineage",
        "work.docs",
        "memory.graph"
      ],
      "description": "Systems that index what a company knows and holds, its documents, chats and tickets or its tables, pipelines and dashboards, so an agent can find the right one with its owner, its lineage and its permissions attached. Compared on what they connect to, whether they keep each source's access controls, what an agent can query and how they're hosted.",
      "json": "https://www.anchorterminal.com/categories/company-knowledge.json",
      "name": "Company knowledge \u0026 data catalogues",
      "slug": "company-knowledge",
      "test": "A fixed set of questions about one test company's documents and data (who owns a table, where a metric comes from, what a policy says), asked through each listing's agent interface as users with different permissions. We check whether answers cite the right source, whether a user ever sees what they shouldn't, and how long a new document takes to become findable.",
      "title": "Company knowledge search and data catalogues for AI agents",
      "toolCount": 13,
      "tools": [
        "glean",
        "openmetadata",
        "onyx",
        "collibra",
        "marmot",
        "dust",
        "atlan",
        "alation",
        "datahub",
        "cohere-north",
        "guru",
        "secoda",
        "overclock"
      ],
      "url": "https://www.anchorterminal.com/categories/company-knowledge"
    },
    "faq": [
      {
        "answer": "Glean has the highest benchmark score of the 13 ranked company knowledge search and data catalogues, 69.8 (B). OpenMetadata is second with 66.6 (B).",
        "question": "What are the highest-rated company knowledge search and data catalogues for AI agents?"
      },
      {
        "answer": "0 of the 13 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.",
        "question": "How many company knowledge search and data catalogues are agent-ready?"
      },
      {
        "answer": "None of the ranked listings here accepts x402 for its main call yet.",
        "question": "Which company knowledge search and data catalogues accept x402 payments?"
      },
      {
        "answer": "By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.",
        "question": "How is this list ranked?"
      }
    ],
    "howToChoose": [
      {
        "label": "Source permissions kept intact",
        "detail": "Check whether each connected source keeps its own access controls, since an agent that surfaces a restricted document through search has leaked it."
      },
      {
        "label": "Answers cite their source",
        "detail": "Confirm that answers cite the document or table they came from, so an agent's claim about a metric can be traced back to its lineage."
      },
      {
        "label": "Owner and lineage per asset",
        "detail": "Check whether ownership and lineage come back with each table or metric, so an agent can say who to ask before it acts."
      },
      {
        "label": "Index lag for new documents",
        "detail": "Measure how long a newly added document takes to become findable, since an agent answering from stale indexes gives wrong answers about current policy."
      }
    ],
    "picks": [
      {
        "also": {
          "name": "OpenMetadata",
          "slug": "openmetadata",
          "why": "B, 66.6/100"
        },
        "name": "Glean",
        "need": "Highest score overall",
        "slug": "glean",
        "why": "B, 69.8/100 on the benchmark"
      },
      {
        "name": "OpenMetadata",
        "need": "Reliability",
        "slug": "openmetadata",
        "why": "84/100 on reliability, against 60 for the overall leader"
      },
      {
        "name": "OpenMetadata",
        "need": "Agent ergonomics",
        "slug": "openmetadata",
        "why": "85/100 on agent ergonomics, against 80 for the overall leader"
      },
      {
        "name": "OpenMetadata",
        "need": "Maintenance \u0026 community",
        "slug": "openmetadata",
        "why": "89/100 on maintenance \u0026 community, against 85 for the overall leader"
      },
      {
        "name": "Collibra",
        "need": "Transparency \u0026 trust",
        "slug": "collibra",
        "why": "82/100 on transparency \u0026 trust, against 80 for the overall leader"
      },
      {
        "name": "Onyx",
        "need": "A hosted MCP endpoint",
        "slug": "onyx",
        "why": "remote MCP server, nothing to install"
      },
      {
        "also": {
          "name": "Onyx",
          "slug": "onyx",
          "why": "self-hosted, MIT licence"
        },
        "name": "OpenMetadata",
        "need": "Self-hosting under an open licence",
        "slug": "openmetadata",
        "why": "self-hosted, Apache-2 licence"
      }
    ],
    "ranked": 13,
    "shortlist": [
      {
        "bestFor": "Agents working inside a company that already runs Glean and need answers from its documents, chats, tickets, code and people with each user's permissions applied.",
        "grade": "B",
        "name": "Glean",
        "position": 1,
        "price": "Paid",
        "score": 69.8,
        "slug": "glean",
        "strengths": [
          "Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs",
          "OAuth with dynamic client registration, or Glean-issued tokens with 19 scopes, user-scoped or global, and optional expiry",
          "Source-system permissions enforced on every search, chat and document read through the MCP server"
        ],
        "url": "https://www.anchorterminal.com/tools/glean",
        "verdict": "Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs. No public price, trial or self-serve signup. Access starts with a demo request.",
        "weaknesses": [
          "No public price, trial or self-serve signup. Access starts with a demo request",
          "Eight incidents on status.glean.com between 10 July and 3 September 2026, seven marked major, most on Chat and the Assistant",
          "No idempotency keys, and no documented confirmation step for MCP tools that write"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Teams running OpenMetadata who want agents to search the catalogue, read lineage and data-quality results, find root causes and create tests or lineage under the user's own permissions.",
        "grade": "B",
        "name": "OpenMetadata",
        "position": 2,
        "price": "Freemium",
        "score": 66.6,
        "slug": "openmetadata",
        "strengths": [
          "MCP built into every instance at /mcp and on by default since 2.0, with nothing extra to install",
          "OAuth 2.0 with PKCE and dynamic client registration through the instance's own SSO or basic auth, 1-hour access tokens and rotating 7-day refresh tokens, plus personal access tokens and bot JWTs",
          "Every tool carries readOnlyHint and destructiveHint, and descriptions say when to choose one tool over another and warn where an answer can be silently wrong"
        ],
        "url": "https://www.anchorterminal.com/tools/openmetadata",
        "verdict": "MCP built into every instance at /mcp and on by default since 2.0, with nothing extra to install. The 16 default tools take about 50,000 characters of definitions, 12,285 of them for search_metadata alone.",
        "weaknesses": [
          "The 16 default tools take about 50,000 characters of definitions, 12,285 of them for search_metadata alone",
          "Three advisories in 2026, a critical template injection and two leaks of bot JWTs to low-privilege users",
          "An open report from 2 October 2026 says get_entity_details returns service connections (host, user, the stored password field) that the REST API masks, and we found no masking step in the MCP read path"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.",
        "grade": "B",
        "name": "Onyx",
        "position": 3,
        "price": "$20 / seat-mo",
        "score": 65,
        "slug": "onyx",
        "strengths": [
          "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card",
          "Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped",
          "Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one"
        ],
        "url": "https://www.anchorterminal.com/tools/onyx",
        "verdict": "MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.",
        "weaknesses": [
          "GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0",
          "Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain",
          "Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "An organisation that already runs Collibra and wants an agent to look up assets, glossary terms, lineage and data quality, or to write assets and classifications under a governed role.",
        "grade": "B",
        "name": "Collibra",
        "position": 4,
        "price": "Paid",
        "score": 64.6,
        "slug": "collibra",
        "strengths": [
          "OpenAPI 3.0 definitions for each REST API, printed on every reference page of developer.collibra.com and served by each instance at `/docs/index.html`",
          "The developer portal publishes `llms.txt`, a Markdown copy of every page and an MCP server for searching the documentation",
          "Every tool in the open-source MCP server declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the 18 data quality tools stay unregistered until a flag is set"
        ],
        "url": "https://www.anchorterminal.com/tools/collibra",
        "verdict": "Each REST API has an OpenAPI 3.0 definition, the developer portal publishes llms.txt and Markdown pages, and every MCP tool carries read-only and destructive annotations. Access needs a sales contract, since no price, trial or self-serve sign-up is published, and no general API rate limit was found in the reviewed documentation.",
        "weaknesses": [
          "No published price, trial or self-serve sign-up. The pricing address returns 404 and the site links a demo request and a product tour",
          "No general request rate limit or `Retry-After` guidance found. Only the OAuth token endpoint has numbers, a pool of 100 tokens refilled at 30 a minute",
          "The Developer Terms of 22 August 2023 forbid publishing benchmarks and calls not driven by bona fide end user requests, except reasonable testing"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Teams that want agents to find which table or topic holds something, who owns it, what feeds it and what a business term means, from a catalogue they host.",
        "grade": "B",
        "name": "Marmot",
        "position": 5,
        "price": "$49 / mo",
        "score": 64.4,
        "slug": "marmot",
        "strengths": [
          "MIT licence, one Go binary on Postgres, with Docker images, a Helm chart and Linux and macOS builds for amd64 and arm64",
          "Nine MCP tools in 6,962 characters of descriptions, each saying when to use it, with limit and offset paging (default 20, max 100)",
          "The three MCP write tools return a preview first, apply only on a second call with `confirm` set to true, and refuse without `assets:manage`"
        ],
        "url": "https://www.anchorterminal.com/tools/marmot",
        "verdict": "MIT licence, one Go binary on Postgres, with Docker images, a Helm chart and Linux and macOS builds for amd64 and arm64. Pre-1.0 (0.11), and the release notes are generated lists of additions and fixes with no breaking-change section.",
        "weaknesses": [
          "Pre-1.0 (0.11), and the release notes are generated lists of additions and fixes with no breaking-change section",
          "The MCP docs page lists 3 tools while v0.11.0 registers 9, and none carries readOnlyHint or destructiveHint",
          "Telemetry is on by default, and the per-channel lookup counts in its daily report aren't on the telemetry page's list"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.",
        "grade": "B",
        "name": "Dust",
        "position": 6,
        "price": "Freemium",
        "score": 62.8,
        "slug": "dust",
        "strengths": [
          "The platform's source is public under the MIT licence at github.com/dust-tt/dust, with commits on the day of the check",
          "Public OpenAPI 3.0 document with 68 operations, plus llms.txt and a Markdown copy of each docs page",
          "Remote MCP server at `https://dust.tt/mcp` and `https://eu.dust.tt/mcp`, with OAuth, dynamic client registration and the signed-in user's own access"
        ],
        "url": "https://www.anchorterminal.com/tools/dust",
        "verdict": "The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.",
        "weaknesses": [
          "Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use",
          "Rate limits are published for document upserts and app runs only, and no Retry-After guidance was found in the docs",
          "The terms link redirects to a Notion site drawn by script, so the service terms, any SLA and the DPA went unread"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "A company already on Atlan that wants agents to find governed tables, owners, lineage, glossary terms and data quality rules, and to run read-only SQL, under the same permissions people have.",
        "grade": "B",
        "name": "Atlan",
        "position": 7,
        "price": "Paid",
        "score": 62.5,
        "slug": "atlan",
        "strengths": [
          "OAuth per user at mcp.atlan.com/mcp, so each call runs with the user's own Atlan personas and policies, and API tokens carrying more than one persona are refused",
          "Write tools return a preview and wait for approval, and the SQL tool refuses anything but SELECT, WITH, SHOW, DESCRIBE and EXPLAIN",
          "Ten coded MCP errors, each with a category and a recovery step, and search paging of 20 by default and 100 at most, or a count alone"
        ],
        "url": "https://www.anchorterminal.com/tools/atlan",
        "verdict": "OAuth per user at mcp.atlan.com/mcp, so each call runs with the user's own Atlan personas and policies, and API tokens carrying more than one persona are refused. Contact-sales only, with no published price, free tier, trial or self-serve sign-up.",
        "weaknesses": [
          "Contact-sales only, with no published price, free tier, trial or self-serve sign-up",
          "39 tools on one endpoint, and the read-only mode that cuts them to 15 is set by Atlan on request",
          "status.atlan.com created its four components on 28 September 2026, none for MCP, and its feed holds one incident"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.",
        "grade": "C",
        "name": "Alation",
        "position": 8,
        "price": "Paid",
        "score": 60.3,
        "slug": "alation",
        "strengths": [
          "OpenAPI 3.0 definitions for each API, shown on every reference page and served by each instance under `/openapi/`",
          "OAuth 2.0 client credentials tied to a system user with one Alation role, with token revocation, secret rotation and offline JWT verification",
          "The AI API answers 429 with `Retry-After` and three `Ai-RateLimit` headers, and the REST 429 body states the seconds to wait"
        ],
        "url": "https://www.anchorterminal.com/tools/alation",
        "verdict": "Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.",
        "weaknesses": [
          "No published price, trial or self-serve sign-up. The pricing address redirects to a sales form",
          "Four incidents between 10 August and 10 September 2026, two of them regional outages longer than an hour",
          "`alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, and a plain `pip install` still resolves to 0.12.0"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Teams already running DataHub who want agents to find tables, trace column lineage, read the SQL people run and see owners and glossary terms before touching data.",
        "grade": "C",
        "name": "DataHub",
        "position": 9,
        "price": "Freemium",
        "score": 59.4,
        "slug": "datahub",
        "strengths": [
          "Apache-2.0 platform and MCP server, run with `uvx mcp-server-datahub@latest` or the acryldata/mcp-server-datahub Docker image against DataHub Core or DataHub Cloud",
          "Write tools stay off until `TOOLS_IS_MUTATION_ENABLED=true`, and all 10 read tools carry readOnlyHint",
          "One filter string on search and lineage (`platform = snowflake AND env = PROD`), paging capped at 50, facet-only searches and an 80,000-token response budget"
        ],
        "url": "https://www.anchorterminal.com/tools/datahub",
        "verdict": "Apache-2.0 platform and MCP server, run with `uvx mcp-server-datahub@latest` or the acryldata/mcp-server-datahub Docker image against DataHub Core or DataHub Cloud. The eight default tools carry about 26,000 characters of descriptions, and search and get_lineage each repeat the same 3,063-character filter grammar.",
        "weaknesses": [
          "The eight default tools carry about 26,000 characters of descriptions, and search and get_lineage each repeat the same 3,063-character filter grammar",
          "Every tool call sends a Mixpanel event by default with the tool name, the client and up to 500 characters of any error message, and no docs page mentions it",
          "The MCP server is pre-1.0 (0.7.1), and CHANGELOG.md stops at 0.5.3 with a breaking HTTP change still under Unreleased"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API.",
        "grade": "C",
        "name": "Cohere North",
        "position": 10,
        "price": "Paid",
        "score": 55.1,
        "slug": "cohere-north",
        "strengths": [
          "Public OpenAPI 3.1 spec for the North API (128 operations) and for Compass search, plus llms.txt and Markdown docs",
          "OAuth 2.0 with PKCE, 16 scopes, refresh tokens and a revoke endpoint, or token exchange from the company's identity provider",
          "Errors carry a stable error_code, an is_retryable flag and retry_after_seconds, and 429 and 503 send Retry-After"
        ],
        "url": "https://www.anchorterminal.com/tools/cohere-north",
        "verdict": "North has a public OpenAPI 3.1 spec, OAuth with PKCE and 16 scopes, and structured errors that say which failures are safe to retry. Access is the main limitation. Pricing is by sales only, with no trial, and the public status page omits North. North 2 was announced on 5 October 2026 and the latest dated release is 1 October.",
        "weaknesses": [
          "No public price, trial or self-serve signup. Access starts with a sales conversation",
          "status.cohere.com has no North or Compass component, and no North SLA was found",
          "Rate limits are set per customer through Flow Control, which is marked Alpha, and no default numbers are published"
        ],
        "where": "local",
        "x402": "no"
      }
    ],
    "updated": "2026-10-09"
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/best/company-knowledge/",
    "json": "https://www.anchorterminal.com/best/company-knowledge/index.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/best/company-knowledge/index.md",
    "slim": "https://www.anchorterminal.com/best/company-knowledge/index.min.md"
  },
  "markdown": "The 10 highest-scoring of 13 company knowledge search and data catalogues on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.\n\n- Ranked: 13 · agent-ready (BB or better): 0 · accept x402: 0 · hosted endpoints: 5\n- Full ranked table: https://www.anchorterminal.com/categories/company-knowledge.md\n- Head-to-head comparisons: https://www.anchorterminal.com/compare/company-knowledge/index.md (63)\n- Methodology: https://www.anchorterminal.com/benchmark/index.md\n\n## The shortlist\n\n| # | Tool | Grade | Score | Best for | Price | Where |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | [Glean](https://www.anchorterminal.com/tools/glean.md) | B | 69.8 | Agents working inside a company that already runs Glean and need answers from its documents, chats, tickets, code and people with each user's permissions applied. | Paid | local |\n| 2 | [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md) | B | 66.6 | Teams running OpenMetadata who want agents to search the catalogue, read lineage and data-quality results, find root causes and create tests or lineage under the user's own permissions. | Freemium | local |\n| 3 | [Onyx](https://www.anchorterminal.com/tools/onyx.md) | B | 65 | Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP. | $20 / seat-mo | hosted |\n| 4 | [Collibra](https://www.anchorterminal.com/tools/collibra.md) | B | 64.6 | An organisation that already runs Collibra and wants an agent to look up assets, glossary terms, lineage and data quality, or to write assets and classifications under a governed role. | Paid | local |\n| 5 | [Marmot](https://www.anchorterminal.com/tools/marmot.md) | B | 64.4 | Teams that want agents to find which table or topic holds something, who owns it, what feeds it and what a business term means, from a catalogue they host. | $49 / mo | local |\n| 6 | [Dust](https://www.anchorterminal.com/tools/dust.md) | B | 62.8 | A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access. | Freemium | hosted |\n| 7 | [Atlan](https://www.anchorterminal.com/tools/atlan.md) | B | 62.5 | A company already on Atlan that wants agents to find governed tables, owners, lineage, glossary terms and data quality rules, and to run read-only SQL, under the same permissions people have. | Paid | hosted |\n| 8 | [Alation](https://www.anchorterminal.com/tools/alation.md) | C | 60.3 | A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role. | Paid | local |\n| 9 | [DataHub](https://www.anchorterminal.com/tools/datahub.md) | C | 59.4 | Teams already running DataHub who want agents to find tables, trace column lineage, read the SQL people run and see owners and glossary terms before touching data. | Freemium | hosted and local |\n| 10 | [Cohere North](https://www.anchorterminal.com/tools/cohere-north.md) | C | 55.1 | Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API. | Paid | local |\n\n## Picks by need\n\n- Highest score overall: [Glean](https://www.anchorterminal.com/tools/glean.md), B, 69.8/100 on the benchmark. Also [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md), B, 66.6/100.\n- Reliability: [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md), 84/100 on reliability, against 60 for the overall leader.\n- Agent ergonomics: [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md), 85/100 on agent ergonomics, against 80 for the overall leader.\n- Maintenance \u0026 community: [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md), 89/100 on maintenance \u0026 community, against 85 for the overall leader.\n- Transparency \u0026 trust: [Collibra](https://www.anchorterminal.com/tools/collibra.md), 82/100 on transparency \u0026 trust, against 80 for the overall leader.\n- A hosted MCP endpoint: [Onyx](https://www.anchorterminal.com/tools/onyx.md), remote MCP server, nothing to install.\n- Self-hosting under an open licence: [OpenMetadata](https://www.anchorterminal.com/tools/openmetadata.md), self-hosted, Apache-2 licence. Also [Onyx](https://www.anchorterminal.com/tools/onyx.md), self-hosted, MIT licence.\n\n## How to choose\n\n- Source permissions kept intact: Check whether each connected source keeps its own access controls, since an agent that surfaces a restricted document through search has leaked it.\n- Answers cite their source: Confirm that answers cite the document or table they came from, so an agent's claim about a metric can be traced back to its lineage.\n- Owner and lineage per asset: Check whether ownership and lineage come back with each table or metric, so an agent can say who to ask before it acts.\n- Index lag for new documents: Measure how long a newly added document takes to become findable, since an agent answering from stale indexes gives wrong answers about current policy.\n\n- How the benchmark tests this category: A fixed set of questions about one test company's documents and data (who owns a table, where a metric comes from, what a policy says), asked through each listing's agent interface as users with different permissions. We check whether answers cite the right source, whether a user ever sees what they shouldn't, and how long a new document takes to become findable.\n\n## Each one in detail\n\n### 1. Glean, B 69.8/100\n\nEnterprise search and AI assistant from Glean Technologies in San Francisco.\n\n- Verdict: Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs. No public price, trial or self-serve signup. Access starts with a demo request.\n- Choose it for: Agents working inside a company that already runs Glean and need answers from its documents, chats, tickets, code and people with each user's permissions applied.\n- Strength: Three public OpenAPI specs (Client, Indexing, Platform) regenerated almost daily, plus llms.txt and Markdown docs\n- Strength: OAuth with dynamic client registration, or Glean-issued tokens with 19 scopes, user-scoped or global, and optional expiry\n- Strength: Source-system permissions enforced on every search, chat and document read through the MCP server\n- Weakness: No public price, trial or self-serve signup. Access starts with a demo request\n- Weakness: Eight incidents on status.glean.com between 10 July and 3 September 2026, seven marked major, most on Chat and the Assistant\n- Weakness: No idempotency keys, and no documented confirmation step for MCP tools that write\n- Price: Paid · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/glean.md\n\n### 2. OpenMetadata, B 66.6/100\n\nOpen-source data catalogue for discovery, lineage, data quality and governance, with connectors to external data systems.\n\n- Verdict: MCP built into every instance at /mcp and on by default since 2.0, with nothing extra to install. The 16 default tools take about 50,000 characters of definitions, 12,285 of them for search_metadata alone.\n- Choose it for: Teams running OpenMetadata who want agents to search the catalogue, read lineage and data-quality results, find root causes and create tests or lineage under the user's own permissions.\n- Strength: MCP built into every instance at /mcp and on by default since 2.0, with nothing extra to install\n- Strength: OAuth 2.0 with PKCE and dynamic client registration through the instance's own SSO or basic auth, 1-hour access tokens and rotating 7-day refresh tokens, plus personal access tokens and bot JWTs\n- Strength: Every tool carries readOnlyHint and destructiveHint, and descriptions say when to choose one tool over another and warn where an answer can be silently wrong\n- Weakness: The 16 default tools take about 50,000 characters of definitions, 12,285 of them for search_metadata alone\n- Weakness: Three advisories in 2026, a critical template injection and two leaks of bot JWTs to low-privilege users\n- Weakness: An open report from 2 October 2026 says get_entity_details returns service connections (host, user, the stored password field) that the REST API masks, and we found no masking step in the MCP read path\n- Price: Freemium · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/openmetadata.md\n\n### 3. Onyx, B 65/100\n\nOpen-source enterprise search and chat platform, formerly Danswer.\n\n- Verdict: MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card. GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0.\n- Choose it for: Teams that want one permission-aware index over Slack, Drive, Confluence, Jira, GitHub and the rest, self-hosted or air-gapped, with agents searching it through MCP.\n- Strength: MIT Community Edition, MCP server included, run by Docker Compose, Helm or Terraform, with a two-week Cloud trial that needs no card\n- Strength: Three read-only MCP tools in 3,360 characters, whose filters return close matches instead of searching unscoped\n- Strength: Personal access tokens limited to `read:search`, with 7, 30 or 365-day expiry, hashed storage and revocation one by one\n- Weakness: GHSA-q62f-rv3h-f822 (critical, CVSS 9.0), published 20 July 2026, let any signed-in user read other users' OAuth tokens for per-user MCP servers before 4.0.0\n- Weakness: Telemetry is on by default and documented as anonymous, while its events carry user IDs and Enterprise builds send the first user's email domain\n- Weakness: Document search has no result limit or paging, and an unparseable `time_cutoff` is dropped with only a server log line\n- Price: $20 / seat-mo · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/onyx.md\n- Against #1: https://www.anchorterminal.com/compare/glean-vs-onyx.md\n\n### 4. Collibra, B 64.6/100\n\nCollibra is a hosted data governance platform with a catalogue, business glossary, lineage and data quality. Agents use REST and GraphQL APIs, a bulk Import API, a hosted MCP server on each cloud instance and an open-source local one.\n\n- Verdict: Each REST API has an OpenAPI 3.0 definition, the developer portal publishes llms.txt and Markdown pages, and every MCP tool carries read-only and destructive annotations. Access needs a sales contract, since no price, trial or self-serve sign-up is published, and no general API rate limit was found in the reviewed documentation.\n- Choose it for: An organisation that already runs Collibra and wants an agent to look up assets, glossary terms, lineage and data quality, or to write assets and classifications under a governed role.\n- Strength: OpenAPI 3.0 definitions for each REST API, printed on every reference page of developer.collibra.com and served by each instance at `/docs/index.html`\n- Strength: The developer portal publishes `llms.txt`, a Markdown copy of every page and an MCP server for searching the documentation\n- Strength: Every tool in the open-source MCP server declares `readOnlyHint`, `destructiveHint` and `idempotentHint`, and the 18 data quality tools stay unregistered until a flag is set\n- Weakness: No published price, trial or self-serve sign-up. The pricing address returns 404 and the site links a demo request and a product tour\n- Weakness: No general request rate limit or `Retry-After` guidance found. Only the OAuth token endpoint has numbers, a pool of 100 tokens refilled at 30 a minute\n- Weakness: The Developer Terms of 22 August 2023 forbid publishing benchmarks and calls not driven by bona fide end user requests, except reasonable testing\n- Price: Paid · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/collibra.md\n- Against #1: https://www.anchorterminal.com/compare/collibra-vs-glean.md\n\n### 5. Marmot, B 64.4/100\n\nOpen-source data catalogue from Marmot Data Ltd in London, MIT licensed and shipped as one Go binary on Postgres.\n\n- Verdict: MIT licence, one Go binary on Postgres, with Docker images, a Helm chart and Linux and macOS builds for amd64 and arm64. Pre-1.0 (0.11), and the release notes are generated lists of additions and fixes with no breaking-change section.\n- Choose it for: Teams that want agents to find which table or topic holds something, who owns it, what feeds it and what a business term means, from a catalogue they host.\n- Strength: MIT licence, one Go binary on Postgres, with Docker images, a Helm chart and Linux and macOS builds for amd64 and arm64\n- Strength: Nine MCP tools in 6,962 characters of descriptions, each saying when to use it, with limit and offset paging (default 20, max 100)\n- Strength: The three MCP write tools return a preview first, apply only on a second call with `confirm` set to true, and refuse without `assets:manage`\n- Weakness: Pre-1.0 (0.11), and the release notes are generated lists of additions and fixes with no breaking-change section\n- Weakness: The MCP docs page lists 3 tools while v0.11.0 registers 9, and none carries readOnlyHint or destructiveHint\n- Weakness: Telemetry is on by default, and the per-channel lookup counts in its daily report aren't on the telemetry page's list\n- Price: $49 / mo · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/marmot.md\n\n### 6. Dust, B 62.8/100\n\nDust is a platform for building AI agents on a company's documents and connected tools, from Permutation Labs in Paris. Outside agents reach it through a REST API, a JavaScript SDK, a CLI and a remote MCP server with OAuth.\n\n- Verdict: The whole platform is MIT on GitHub, with a public OpenAPI document of 68 operations, llms.txt and a remote MCP server that acts with the signed-in user's access. API calls that run agents draw only on a paid workspace credit pool, and the terms of service could not be read.\n- Choose it for: A team that already works in Dust and wants an outside agent to search its spaces, read documents and call its agents with a user's own access.\n- Strength: The platform's source is public under the MIT licence at github.com/dust-tt/dust, with commits on the day of the check\n- Strength: Public OpenAPI 3.0 document with 68 operations, plus llms.txt and a Markdown copy of each docs page\n- Strength: Remote MCP server at `https://dust.tt/mcp` and `https://eu.dust.tt/mcp`, with OAuth, dynamic client registration and the signed-in user's own access\n- Weakness: Programmatic usage has no free credits. It draws only on the workspace credit pool, which Free seats cannot use\n- Weakness: Rate limits are published for document upserts and app runs only, and no Retry-After guidance was found in the docs\n- Weakness: The terms link redirects to a Notion site drawn by script, so the service terms, any SLA and the DPA went unread\n- Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/dust.md\n- Against #1: https://www.anchorterminal.com/compare/dust-vs-glean.md\n\n### 7. Atlan, B 62.5/100\n\nHosted data catalogue and metadata platform for finding and managing enterprise data.\n\n- Verdict: OAuth per user at mcp.atlan.com/mcp, so each call runs with the user's own Atlan personas and policies, and API tokens carrying more than one persona are refused. Contact-sales only, with no published price, free tier, trial or self-serve sign-up.\n- Choose it for: A company already on Atlan that wants agents to find governed tables, owners, lineage, glossary terms and data quality rules, and to run read-only SQL, under the same permissions people have.\n- Strength: OAuth per user at mcp.atlan.com/mcp, so each call runs with the user's own Atlan personas and policies, and API tokens carrying more than one persona are refused\n- Strength: Write tools return a preview and wait for approval, and the SQL tool refuses anything but SELECT, WITH, SHOW, DESCRIBE and EXPLAIN\n- Strength: Ten coded MCP errors, each with a category and a recovery step, and search paging of 20 by default and 100 at most, or a count alone\n- Weakness: Contact-sales only, with no published price, free tier, trial or self-serve sign-up\n- Weakness: 39 tools on one endpoint, and the read-only mode that cuts them to 15 is set by Atlan on request\n- Weakness: status.atlan.com created its four components on 28 September 2026, none for MCP, and its feed holds one incident\n- Price: Paid · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/atlan.md\n- Against #1: https://www.anchorterminal.com/compare/atlan-vs-glean.md\n\n### 8. Alation, C 60.3/100\n\nAlation is a hosted data catalogue for tables, queries, BI reports, lineage and data quality. Agents reach it through REST APIs, a natural-language Aggregated Context API, a Python agent SDK and an MCP server on each cloud instance.\n\n- Verdict: Each API has an OpenAPI 3.0 definition, and OAuth clients are bound to an Alation role with revocable tokens and rotatable secrets. Access needs a sales contract, since no price, trial or self-serve sign-up is published. The agent SDK and local MCP server have stayed at a release candidate since 14 January 2026.\n- Choose it for: A company already on Alation Cloud Service that wants agents to find governed tables, columns, queries, BI reports and lineage, and to run read-only SQL against data products, under an Alation role.\n- Strength: OpenAPI 3.0 definitions for each API, shown on every reference page and served by each instance under `/openapi/`\n- Strength: OAuth 2.0 client credentials tied to a system user with one Alation role, with token revocation, secret rotation and offline JWT verification\n- Strength: The AI API answers 429 with `Retry-After` and three `Ai-RateLimit` headers, and the REST 429 body states the seconds to wait\n- Weakness: No published price, trial or self-serve sign-up. The pricing address redirects to a sales form\n- Weakness: Four incidents between 10 August and 10 September 2026, two of them regional outages longer than an hour\n- Weakness: `alation-ai-agent-sdk` and `alation-ai-agent-mcp` were last published on 14 January 2026 as 1.0.0rc3, and a plain `pip install` still resolves to 0.12.0\n- Price: Paid · Auth: OAuth or key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/alation.md\n- Against #1: https://www.anchorterminal.com/compare/alation-vs-glean.md\n\n### 9. DataHub, C 59.4/100\n\nOpen-source data catalogue and metadata platform from Acryl Data, trading as DataHub.\n\n- Verdict: Apache-2.0 platform and MCP server, run with `uvx mcp-server-datahub@latest` or the acryldata/mcp-server-datahub Docker image against DataHub Core or DataHub Cloud. The eight default tools carry about 26,000 characters of descriptions, and search and get_lineage each repeat the same 3,063-character filter grammar.\n- Choose it for: Teams already running DataHub who want agents to find tables, trace column lineage, read the SQL people run and see owners and glossary terms before touching data.\n- Strength: Apache-2.0 platform and MCP server, run with `uvx mcp-server-datahub@latest` or the acryldata/mcp-server-datahub Docker image against DataHub Core or DataHub Cloud\n- Strength: Write tools stay off until `TOOLS_IS_MUTATION_ENABLED=true`, and all 10 read tools carry readOnlyHint\n- Strength: One filter string on search and lineage (`platform = snowflake AND env = PROD`), paging capped at 50, facet-only searches and an 80,000-token response budget\n- Weakness: The eight default tools carry about 26,000 characters of descriptions, and search and get_lineage each repeat the same 3,063-character filter grammar\n- Weakness: Every tool call sends a Mixpanel event by default with the tool name, the client and up to 500 characters of any error message, and no docs page mentions it\n- Weakness: The MCP server is pre-1.0 (0.7.1), and CHANGELOG.md stops at 0.5.3 with a breaking HTTP change still under Unreleased\n- Price: Freemium · Auth: OAuth or key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/datahub.md\n\n### 10. Cohere North, C 55.1/100\n\nCohere North is an enterprise AI agent and search platform from Cohere in Toronto. It indexes connected work apps into Compass for permission-aware search and chat, with a REST API per instance. North 2 was announced on 5 October 2026.\n\n- Verdict: North has a public OpenAPI 3.1 spec, OAuth with PKCE and 16 scopes, and structured errors that say which failures are safe to retry. Access is the main limitation. Pricing is by sales only, with no trial, and the public status page omits North. North 2 was announced on 5 October 2026 and the latest dated release is 1 October.\n- Choose it for: Regulated companies that want an agent and search platform over their own documents, mail and tickets, run privately or air-gapped and called through a REST or OpenAI-compatible API.\n- Strength: Public OpenAPI 3.1 spec for the North API (128 operations) and for Compass search, plus llms.txt and Markdown docs\n- Strength: OAuth 2.0 with PKCE, 16 scopes, refresh tokens and a revoke endpoint, or token exchange from the company's identity provider\n- Strength: Errors carry a stable error_code, an is_retryable flag and retry_after_seconds, and 429 and 503 send Retry-After\n- Weakness: No public price, trial or self-serve signup. Access starts with a sales conversation\n- Weakness: status.cohere.com has no North or Compass component, and no North SLA was found\n- Weakness: Rate limits are set per customer through Flow Control, which is marked Alpha, and no default numbers are published\n- Price: Paid · Auth: OAuth · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/cohere-north.md\n- Against #1: https://www.anchorterminal.com/compare/cohere-north-vs-glean.md\n\n3 more are ranked in the full table: https://www.anchorterminal.com/categories/company-knowledge.md\n\n## Head to head\n\n- [Glean vs Onyx](https://www.anchorterminal.com/compare/glean-vs-onyx.md)\n- [Collibra vs Glean](https://www.anchorterminal.com/compare/collibra-vs-glean.md)\n- [Collibra vs OpenMetadata](https://www.anchorterminal.com/compare/collibra-vs-openmetadata.md)\n- [Marmot vs OpenMetadata](https://www.anchorterminal.com/compare/marmot-vs-openmetadata.md)\n- [Collibra vs Onyx](https://www.anchorterminal.com/compare/collibra-vs-onyx.md)\n- [Collibra vs Marmot](https://www.anchorterminal.com/compare/collibra-vs-marmot.md)\n\n## Questions\n\n### What are the highest-rated company knowledge search and data catalogues for AI agents?\n\nGlean has the highest benchmark score of the 13 ranked company knowledge search and data catalogues, 69.8 (B). OpenMetadata is second with 66.6 (B).\n\n### How many company knowledge search and data catalogues are agent-ready?\n\n0 of the 13 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.\n\n### Which company knowledge search and data catalogues accept x402 payments?\n\nNone of the ranked listings here accepts x402 for its main call yet.\n\n### How is this list ranked?\n\nBy the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 9 October 2026.\n\n## How this list is made\n\nThe order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Best of",
        "url": "https://www.anchorterminal.com/best/"
      },
      {
        "name": "Company knowledge \u0026 data catalogues",
        "url": ""
      }
    ],
    "description": "Glean (B), OpenMetadata (B) and Onyx (B) lead the 13 ranked company knowledge search and data catalogues. Picks by need, strengths, weaknesses and prices from the Anchor benchmark.",
    "facts": [
      "Glean B",
      "OpenMetadata B",
      "Onyx B"
    ],
    "h1": "Best company knowledge search and data catalogues for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/best-company-knowledge.png",
    "path": "/best/company-knowledge/",
    "published": "",
    "section": "tools",
    "title": "Best company knowledge search and data catalogues for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/best/company-knowledge/"
  },
  "tokens": {
    "markdown": 6200,
    "slim": 1530
  },
  "version": 1
}
