# Tech Thursday with SNOK: SAP in energy utilities, Snowflake and UiPath agents - building governed data for AI

> SAP on-premise in energy utilities, Snowflake as the base for RAG and UiPath agents, SNOK MDM for master data. Architecture, SAP licensing and AI governance.

- Source: https://snok.ai/en/news/blog/sap-utilities-snowflake-uipath-agents-snok-mdm/
- Author: Michał Korzeń
- Published: 2026-10-01

---
An energy utility rarely runs on one system. SAP ERP handles finance, controlling, plant maintenance and logistics. Customer billing runs on SAP IS-U or another billing platform. Around them sit a meter data management system, GIS, SCADA, CRM, a customer portal and the interfaces for market data exchange. Each of these systems may hold a separate record of the same customer, metering point and supplier.

On top of that landscape comes the pressure to use AI. Boards ask for customer service assistants, automatic bill explanations and agents that take over exception handling. In our view the first question is a different one: where will the agent get its data, whom will it show that data to, and who is accountable for its decision. This post describes an architecture that answers it: SAP on-premise as the source, Snowflake as a governed data and knowledge platform, SNOK MDM as the master data layer and UiPath as the harness that controls how agents work.

![Architecture: SAP ECC and S/4HANA, billing and other systems feed Snowflake, SNOK MDM returns the golden record, UiPath Maestro runs the agents, and the SAP transaction happens after an employee approves it](https://snok.ai/images/blog/sap-energetyka-snowflake-agenci-uipath-snok-mdm-architektura-en.gif)

*Data flows from SAP and billing into Snowflake, SNOK MDM keeps master data in order, and an agent in UiPath Maestro changes data in SAP only after an employee approves.*

## Why now - CSIRE, smart meters and SAP deadlines

Three developments overlap in Poland right now.

**The Central Energy Market Information System.** CSIRE, the Polish central data hub for the electricity market, has been live since 1 July 2025, and market participants join it in stages. The final onboarding date in the market information operator's schedule is 19 October 2026. For participants connected to CSIRE, supplier switching, metering data and billing data go through standardised exchange with a single central system. Any inconsistency in metering point data leaves the organisation faster than before.

**Smart meters.** According to the Polish Energy Regulatory Office (URE), at the end of 2024 remote-reading meters were installed at 38.26 per cent of more than 19 million metering points. Polish energy law requires at least 80 per cent by the end of 2028. The volume of metering data grows, and so does the number of exceptions to handle before billing.

**SAP deadlines.** Mainstream maintenance for the core applications of SAP Business Suite 7 ends at the end of 2027, with optional extended maintenance available until 2030. The date for a specific industry solution, including SAP IS-U, is worth confirming with SAP. The decision to move to SAP S/4HANA Utilities or to keep the current billing platform is therefore made in the same window in which the first AI projects start.

The conclusion for the architecture: the data layer for AI should work regardless of which billing system remains in the landscape three years from now.

## Two meanings of MDM in energy

In the energy sector, MDM usually stands for meter data management. In this post we mean master data management: who the customer is, which supplier record is the right one, and what a material is called in the warehouse and in the procurement catalogue.

The distinction matters in practice. A meter data management system tells you how much energy flowed through a meter. It does not tell you whether the customer in billing, in CRM and in SAP is the same person or company. A master data layer closes that gap. Without it, every AI agent works with three versions of the same customer.

## Getting data from SAP on-premise into Snowflake

This is the most underestimated part of the project. Choosing how to extract data from SAP is a licensing decision, not only a technical one.

**SAP Business Data Cloud and zero-copy integration.** SAP and Snowflake announced their partnership on 4 November 2025. Since 4 May 2026 Snowflake has offered general availability of its integration with SAP Business Data Cloud: SAP data products are visible in Snowflake without copying, together with their semantic definitions, and Snowflake data can be published back to SAP Business Data Cloud. The offering comes in two variants: SAP Snowflake, sold and supported by SAP, and SAP BDC Connect for Snowflake for existing Snowflake accounts. One important caveat: this covers data available as data products in SAP Business Data Cloud. Data from SAP ECC or SAP IS-U running on-premise has to be brought there first.

**SAP Datasphere replication flows do not support Snowflake as a target.** In the SAP Datasphere documentation for replication flows, Snowflake appears only as a source. An architecture that assumes replication from SAP Datasphere to Snowflake with this mechanism needs a different approach.

**SAP Note 3255746.** In this note SAP clarified that the ODP-RFC interface is intended for data exchange between SAP applications. Vendors of integration tools describe this as a prohibition on using the interface in third-party solutions. The clarification does not cover other methods, such as database-level change data capture, OData or RFC calls outside ODP-RFC, but whether they are permitted depends on your licence agreement with SAP. Before you choose an extraction tool, check which method it uses and confirm it under your agreement.

In practice, we recommend a short review of extraction paths before the first line of code: which data can go through SAP Business Data Cloud, which through change data capture, and which is fine with a daily refresh. The review combines SAP Basis, SAP security and data engineering skills, so we run it as a single project step.

![Three paths from SAP on-premise to Snowflake: SAP Business Data Cloud zero-copy, change data capture, OData or RFC after a licence check, and ODP-RFC in a third-party tool ruled out](https://snok.ai/images/blog/sap-energetyka-snowflake-agenci-uipath-snok-mdm-drogi-danych-en.webp)

*Choosing an SAP extraction path is a licensing decision before it becomes a technical one.*

## Snowflake as a governed data and knowledge base for AI

In this architecture Snowflake plays two roles: data warehouse and knowledge base for language models. Both need order before the first agent appears.

**Numbers through a semantic layer, documents through search.** Vector search, which RAG relies on, works well for documents: tariffs, grid code, terms of service, complaint procedures or contracts. It does not work well for questions about balances, consumption and receivables, because those questions need aggregations and table joins, not text similarity. So we separate the two. Cortex Search, Snowflake's hybrid vector and keyword search, indexes the documents. Numeric data is exposed through semantic views: metrics such as overdue receivables or consumption in a billing period are defined once and calculated deterministically. Cortex Agents combine both sources in a single answer.

**Permissions enforced in one place.** Snowflake Horizon provides classification of personal and confidential data, tags, dynamic masking, row access policies and lineage. Masking and row access policies require Enterprise Edition or higher. The principle we design for: an agent sees exactly what the user it acts for would see. Permissions are enforced by the data platform, not by the prompt. This requires a connection in the user's context, which has to be designed and tested for the chosen authentication method, because connectors also allow application credentials.

**Region and model inference.** Snowflake has no region in Poland. The nearest regions include AWS in Frankfurt and Stockholm and Azure in the Netherlands and Sweden. Leading models in Cortex require cross-region inference, and for organisations created on or after 9 March 2026 the default setting allows requests to be routed to any region. For an energy utility, we recommend deliberately restricting inference to regions in the European Union and recording that decision in the security documentation.

**Protection against prompt injection.** Since May 2026 Cortex AI Guardrails, once enabled by an administrator, protect Cortex agents against prompt injection, including indirect injection hidden in tool results. This matters because customer correspondence and external documents are a natural carrier for such an attack.

We describe how we design data platforms on the [SNOK and Snowflake](https://snok.ai/en/snowflake-snok/) page and in our [Modern Data Stack](https://snok.ai/en/offer/custom-development/modern-data-stack/) offering.

## SNOK MDM - one version of the customer, supplier and material before the agent

Snowflake is a data platform, not a master data management system. It does not decide which of three records for the same customer is the right one, and it does not run the process in which a data owner approves a merge. On Snowflake, a golden record requires additional products or a custom build.

SNOK MDM, our own master data management solution, provides that layer. It works on top of source systems, without replacing ERP or billing:

- **Matching and deduplication** recognise the same entity across many records, for example a customer recorded differently in billing, in CRM and in SAP.
- **A language model proposes merges**, and a data steward approves the decision. Every decision goes into the audit trail.
- **Six domains on one platform**: customers, suppliers, materials, products, financial accounts and employees, and in the industry edition for power, gas and oil utilities also metering points and their links to customers.
- **Connectors for SAP S/4HANA and SAP ECC**, with deployment on-premise, in the client's environment or as a service.

In the energy sector three domains deliver the most. The customer domain, together with metering points from the industry edition, brings order to customer service once CSIRE is fully live. The supplier domain can support supply chain risk assessment where a company is subject to such obligations under the Polish act implementing NIS2. The materials domain connects spare parts in SAP plant maintenance with the procurement catalogue. We publish the SNOK MDM golden record to Snowflake as a data product, so agents and reports use the same approved version.

We discussed when to choose SAP Master Data Governance and when SNOK MDM in [SAP MDG, Reltio or SNOK MDM](https://snok.ai/en/news/blog/sap-mdg-vs-reltio-snok-mdm/). Product details are on the [SNOK MDM](https://snok.ai/en/products/snok-mdm/) page.

## UiPath as the harness for agent work

An agent that picks its own tools, makes its own decisions and executes its own transaction in SAP is a risk nobody in a regulated utility will sign off. What you need is a harness: a layer that defines the agent's process, tools, permissions and the points where an authorised employee approves the decision. In this architecture UiPath plays that role.

**UiPath Maestro orchestrates the process.** UiPath and Snowflake announced their partnership on 30 September 2025. The Snowflake Cortex connector in UiPath Integration Service lets a UiPath Maestro process call a Cortex agent that answers from semantic views and Cortex Search, then pass the result on: to a robot that executes the transaction in SAP, or to a person in Action Center. The alternative is the Snowflake-managed MCP server, registered in UiPath Orchestrator as a remote tool source for conversational agents.

**UiPath AI Trust Layer enforces the rules.** Once policies are configured, it masks personal data before it is sent to the model and restores it after the response, enforces agent policies before deployment and records model calls in an audit log. For a utility that processes data about millions of customers, this is a precondition for production.

**A person approves where the decision has consequences.** A billing correction, a change to metering point data or a reply to a complaint goes through an approval point in Action Center. The agent prepares the justification, and an authorised employee approves it. We described the pattern in more detail in our post on [HITL gates in UiPath Maestro](https://snok.ai/en/news/blog/hitl-gates-uipath-maestro-ai-trust-layer/).

Processes worth starting with:

1. **High bill explanation.** The agent brings together consumption, meter readings and the tariff, drafts a reply, and a customer service employee approves it. UiPath publishes this pattern as a reference agentic use case.
2. **Meter reading exceptions before billing.** A missing reading, an estimated reading or an unusual jump in consumption goes to an agent that proposes a correction or a meter check.
3. **Rejected market data exchange messages.** The agent classifies the reason for rejection, checks the metering point data against the golden record and prepares a correction for approval.

We deliver process automation as a [UiPath Platinum Partner](https://snok.ai/en/uipath-snok/), and describe agent orchestration in our [UiPath Maestro](https://snok.ai/en/offer/ai-automation/uipath-maestro/) offering.

## AI governance - five layers of control

Governance is a set of mechanisms that operate in every layer of the architecture, not a document attached at the end of the project.

1. **Identity.** The agent acts on behalf of a specific user, and that user's identity reaches the data platform. We choose and test the authentication method for exactly this. A technical account with full access is not acceptable.
2. **Data.** Masking, row access policies and classification in Snowflake Horizon, plus the approved golden record in SNOK MDM.
3. **Semantics.** Metrics defined once in semantic views, so the agent does not calculate receivables its own way.
4. **Agent.** Design policies, pre-deployment evaluations and an agent register with permissions in UiPath.
5. **People and the trail.** Approval points for consequential decisions and an audit log covering model calls, data steward decisions and robot transactions.

These layers also support regulatory compliance. The Polish act on the national cybersecurity system implementing NIS2 has applied since 3 April 2026 and covers the energy sector. Obligations for high-risk AI systems under Annex III of the AI Act are set to apply from 2 December 2027, following the changes introduced by the Digital Omnibus package. In the energy sector this mainly concerns AI systems used as safety components in the management and operation of critical infrastructure, including the supply of electricity, not every customer service agent. Classifying a specific use case requires legal analysis, but an architecture with five layers of control makes the documentation easier to prepare. Security of the agents themselves, including testing for prompt injection and data leakage through tools, is covered by our [AI Security](https://snok.ai/en/offer/ai-automation/ai-security/) offering.

## Where to start - three steps

**Step 1. Review data and extraction paths.** A map of systems, master data domains and SAP extraction methods, with a licence compliance assessment. Outcome: the list of data that can go to Snowflake and how to get it there.

**Step 2. Pilot one domain and one agent.** For example, a customer golden record in SNOK MDM, billing data in Snowflake and a bill explanation agent in UiPath Maestro, with an approval point for an employee. A first result on your own data instead of a demo on sample data.

**Step 3. Scale.** More domains, more processes and governance moved into ongoing operations.

## Why SNOK

A project like this combines skills that many organisations split across different vendors: SAP Basis and SAP security, data engineering on Snowflake, master data management, and UiPath automation and agents. SNOK is an SAP partner, a Snowflake Partner and a UiPath Platinum Partner, and SNOK MDM is our own solution. One team can run the whole path: from data in SAP, through the golden record and the data platform, to the agent with an approval point.

If you are planning an AI project at an energy utility, let us start with a review of your data and extraction paths. [Talk to us about an architecture for your SAP landscape](https://snok.ai/en/offer/master-data-management/).

## Sources

- PSE, Energy Market Information Operator - CSIRE launch and rollout schedule (accessed 30.09.2026): https://www.pse.pl/oire/harmonogram-wdrazania-nmwi-poprzez-csire
- URE - report on dynamic price contracts, remote-reading meter data at end of 2024 (accessed 30.09.2026): https://www.ure.gov.pl/download/9/15476/Raportcenydynamiczne.pdf
- Act of 20 May 2021 amending the Polish Energy Law, art. 11t (accessed 30.09.2026): https://orka.sejm.gov.pl/proc9.nsf/ustawy/808_u.htm
- SAP - maintenance strategy for SAP S/4HANA and SAP Business Suite 7 (accessed 30.09.2026): https://support.sap.com/en/release-upgrade-maintenance/maintenance-information/maintenance-strategy/s4hana-business-suite7.html
- SAP News - SAP and Snowflake, 4.11.2025 (accessed 30.09.2026): https://news.sap.com/2025/11/sap-snowflake-data-enterprise-ai-business-data-fabric/
- Snowflake - SAP BDC Zerocopy Connector, general availability, 4.05.2026 (accessed 30.09.2026): https://docs.snowflake.com/en/release-notes/2026/other/2026-05-04-Snowflake-SAP-zerocopy-integration
- SAP Datasphere - sources and targets for replication flows (accessed 30.09.2026): https://github.com/SAP-docs/sap-datasphere
- SAP - API Policy, Frequently Asked Questions, version 1.3, 06.2026, questions 22-23 (accessed 30.09.2026): https://www.sap.com/docs/download/2026/04/e2a0665e-4c7f-0010-bca6-c68f7e60039b.pdf
- Theobald Software - SAP Note 3255746, 23.04.2026 (accessed 30.09.2026): https://theobald-software.com/en/blog/sap-note-3255746
- Snowflake - regions (accessed 30.09.2026): https://docs.snowflake.com/en/user-guide/intro-regions
- Snowflake - cross-region inference in Cortex (accessed 30.09.2026): https://docs.snowflake.com/en/user-guide/snowflake-cortex/cross-region-inference
- Snowflake - Cortex Search (accessed 30.09.2026): https://docs.snowflake.com/en/user-guide/snowflake-cortex/cortex-search/cortex-search-overview
- Snowflake - Cortex AI Guardrails, 14.05.2026 (accessed 30.09.2026): https://docs.snowflake.com/en/release-notes/2026/other/2026-05-14-cortex-ai-guardrails-si-cortex-agents
- UiPath - partnership with Snowflake, 30.09.2025 (accessed 30.09.2026): https://www.uipath.com/newsroom/uipath-partners-with-snowflake-to-unite-agentic-automation-and-snowflake-cortex-ai
- UiPath - Snowflake Cortex connector (accessed 30.09.2026): https://docs.uipath.com/integration-service/automation-cloud/latest/user-guide/uipath-snowflake-cortex
- UiPath - PII masking in AI Trust Layer (accessed 30.09.2026): https://docs.uipath.com/automation-cloud/automation-cloud/latest/admin-guide/pii-masking
- UiPath - High Bill Analysis Agent (accessed 30.09.2026): https://www.uipath.com/resources/agentic-use-cases/high-bill-analysis-agent
- Polish act on the national cybersecurity system, Journal of Laws 2026 item 252 (accessed 30.09.2026): https://isap.sejm.gov.pl/isap.nsf/DocDetails.xsp?id=WDU20260000252
- Regulation (EU) 2026/1744 (Digital Omnibus) (accessed 30.09.2026): https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
