← Back to blog
AiAbout 7 min read

The Enterprise Agent Plumbing Race: Ampersand and Restate Fund the Read-Write Layer

Published Oct 7, 2026
The Enterprise Agent Plumbing Race: Ampersand and Restate Fund the Read-Write Layer

Two funding rounds in early October point at the least glamorous part of enterprise AI, and arguably the most important. Ampersand raised $15 million. Restate raised $20 million. Neither builds a model. Both build the plumbing that lets an agent actually do something inside a system a business already runs.

Ampersand: read and write inside the system of record

Ampersand closed a Series A on 6 October, led by Bessemer Venture Partners, with returning backers Matrix and Flex Capital, plus new names Yelp and Mana Ventures. Total funding now sits at roughly $19.7 to $20.7 million, up from a $4.7 million seed led by Matrix in April 2023. The company was founded in 2022.

The pitch is easy to say and hard to build. Let AI applications work inside the creaky business software companies already depend on. Ampersand builds infrastructure that lets agentic applications perform read and write operations inside systems of record such as Salesforce and NetSuite.

Read is the easy half. Write is where the difficulty lives. An agent that only reads can answer a question. An agent that writes can change a record, and a wrong write in a system of record is a business problem, not a bad answer.

The company's focus is on the customization problem. Enterprise systems are rarely used out of the box. Companies customize them heavily, so one firm's Salesforce setup can look almost nothing like another's. Ampersand positions itself against traditional integration platforms, which tend to offer broader but shallower connections. Deeper integrations that handle per-customer customization are the differentiator the company is selling.

Alongside the funding, Ampersand announced the beta of Andi, an AI integration agent that helps developers with per-customer implementation work. That is the tedious, customer-specific configuration that makes data synchronization actually function in a given environment.

Restate: durable infrastructure for long-running agents

Restate's $20 million Series A, led by Singular, goes toward durable infrastructure for agent workflows. The target is runtime reliability: the unglamorous plumbing that keeps a long-running agent from failing without a trace mid-task.

The problem is specific. An agent that runs for hours, moves between tools, and holds state has many points where it can drop. A network call times out, a service restarts, a step completes but its result never gets recorded. In a demo, you retry by hand. In production, you need the runtime to guarantee that a step either completes or is safely retried, and that the agent's state survives a crash.

That is durable execution, a well-established pattern in distributed systems that is now being applied to agent loops. Restate's bet is that most production agents depend on infrastructure like this, and that almost nobody wants to build it themselves.

Why these rounds belong together

Put the two together and the shape of the gap is clear. One company makes the agent able to touch the systems that hold the business's data. The other makes the agent able to run long enough, and reliably enough, to be trusted with that access.

Both are the kind of work that never makes headlines and that most production agents depend on in the background. The agent platform market got crowded this month with launches from Salesforce, AWS, OpenAI, and NVIDIA, each targeting one problem: making agents safe enough to run a real business function. Ampersand and Restate sit underneath that layer, in the part that determines whether the layer above them works.

The broader governance turn

The agent platform news of October has a common thread: governance is catching up with capability. OpenAI launched Presence, an operational layer for deploying voice and chat agents with structured governance, where a business can define a job scope, limited knowledge access, and approved actions per agent. Classie Supervise launched alongside it, giving enterprises real-time tracking, control, and accounting for agents already in production.

Salesforce and AWS announced Agentforce 360 for AWS, a joint platform whose Atlas Reasoning Engine runs on Anthropic's Claude models through Amazon Bedrock and generates immutable audit trails for every agent decision. CrowdStrike is among the early adopters, citing procurement simplicity alongside security.

The question the market has moved past is whether an agent can do a task. The question now is whether a business can govern that agent once it is running. Ampersand and Restate answer the layer underneath that question, where governance is only possible if the writes are controlled and the runtime is durable.

What to watch

Two things would confirm the thesis. The first is whether enterprises adopt deep per-customer integrations over shallow ones at scale, which is a claim Ampersand is making against established integration platforms.

The second is whether durable execution becomes a default expectation for agent runtimes rather than a feature teams bolt on later. If long-running agents become normal, reliability stops being optional, and the infrastructure that guarantees it stops being a detail. The funding rounds this month suggest investors think both shifts are already underway.

Why "read and write" is not one capability

The phrase "read and write" hides the fact that these are two very different asks, and the difference explains why the integration problem is hard.

A read operation is safe in the sense that its worst outcome is a wrong answer. The agent queries a record, gets data, and either uses it well or badly. No system state changes.

A write operation changes the business. It creates a record, updates a field, triggers a downstream workflow. In a system of record, a write ripples outward through integrations, reports, and processes that were never designed to expect an agent as the author. A write that arrives at the wrong time, carries a stale value, or fires twice becomes a data incident rather than a wrong answer.

That is why Ampersand's focus on per-customer customization is the crux rather than a detail. Two companies running the same software have different field configurations, different validation rules, and different downstream automations. A shallow integration that works against a default schema will break against a customized one, and it will break in a way that is hard to trace, because the failure surfaces in a downstream report rather than at the point of the write.

Why durability is the other half

The write problem and the reliability problem are two faces of the same concern. An agent that touches a system of record has to be trusted to do so correctly and completely, and completeness is exactly what a long-running process struggles with.

Consider an agent that must update a hundred records based on a batch of documents. It will run for a while, use several tools, and hold intermediate state. Partway through, a network call fails or a service restarts. Without durable execution, the run either dies or resumes from a wrong point, and the records end up half-updated. With it, each step is recorded, so the run can resume without repeating a completed write or skipping an incomplete one.

Two clear glass tubes joined end to end by a polished brass fitting with a warm amber liquid flowing through

The two companies are solving the same trust problem from different ends. Ampersand makes sure the agent can reach the systems and respects their shape. Restate makes sure the agent finishes what it starts. An agent that can write but cannot survive an interruption is not usable in production, and an agent that is durable but cannot write is not useful. Both halves are required before the layer above them, the governance and oversight tools, has anything solid to govern.

The pricing signal

A useful way to read the round sizes is as a signal about how the market values the invisible layer. Ampersand's roughly $20 million total and Restate's $20 million Series A are modest next to the capital flowing into model development and agent platforms. That gap suggests the plumbing is expected to be supplied by many small vendors rather than a few large ones, and that the work is valued for reliability rather than for novelty.

For a team building on agents, that suggests a practical posture. Assume the integration and durability layers will come from specialists rather than from the model provider, and design for the ability to swap them. The agent framework that looks permanent today may sit on a runtime that changes, and the systems of record it writes to will outlast all of it.

Related articles